DavidOverton.com
This site is my way to share my views and general business and IT information with you about Microsoft, IT solutions for ISVs, technologists and businesses, large and small.  
When does Windows Intune make sense for a company as the only management solution or hybrid

Windows_intune_logoI’ve been asked this question several times, so I thought I would share my thoughts.  I don’t regularly work with the Windows Intune team at Microsoft as this is not my role, so this is purely my opinion, not in any way endorsed by Microsoft.

To start off with, I think Windows Intune makes sense for a company whenever they are considering a cloud based Management strategy.  Windows Intune also has the benefit of providing you with Windows and Microsoft anti-Malware software for your computers, so it is a way to get up to date, stay secure and manage the computers.  Having said all of this, there are times when Windows Intune makes perfect sense.

Smaller organisations have a range of choices to deliver systems management from Microsoft, which they need to pair with security and desktop software updates to deliver a solution the same as Windows Intune.  There are also all the options available to larger organisations, but the options tailored for SMEs are functionally rich at a lower price point. These include the SBS 2011 Essentials and SBS 2011 Standard / Premium Products as well as Windows 7 itself.  From a comparison point of view, this is how they simply stack up:

SBS 2011 Essentials

SBS 2011 Standard

Windows Intune

Windows Server 2008 R2

Yes

Yes

No, but could be irrelevant (Yes in Azure)

Active Directory

Yes

Yes

No

WSUS

No

Yes

Yes

Group Policy

No

Yes

Yes (some)

Management tools

Simple monitoring

Yes

Yes

Exchange 2010

No

Yes

No (Yes in Office 365)

SharePoint Foundation

Optional, but not pre-built

Yes

No (Yes in Office 365)

Premium Add-on Services

Optional

Optional

No (Yes in Azure)

User / PC limit

25

75

Unlimited
Windows 7 (and later versions) No No Yes
Anti-malware No (non-centralised for 1-9 PCs) No (non-centralised for 1-9 PCs) Yes
Remote shared screen assistance No No Yes
Payment Model Up front Up front Subscription

Windows Intune gives you the ability to run your infrastructure on-premise or in the cloud.  This could include Office 365 or Azure if desired.  There are basically two options available:

All in the cloud

Intune and Office 365 Infrastructure

In this scenario, you do not use on-premise management or service delivery and can combine Windows Intune with Office 365 to provide a complete set of cloud services.  This solution works particularly well in these scenarios:

  • When you do not want to buy hardware and software up front, giving you scalability options and limited commitment
  • When you do not have a centralised location for server technology
  • When you do not have a complex IT environment to manage

Part and part (hybrid model)

Intune, Office 365 and On Prem with SBS

The part and part or hybrid model is about choices.  There are many reasons why you may desire to manage your estate from an on-premise solution.  You have more control and can implement more customisation, however you also need skills in maintaining the management (and Office server) environment too.  However some users may fall outside the standard remit you control, for example, connectivity to the office or ownership of the computer.  Windows Intune can help here by enabling a greater level of control due to cloud connectivity being required.  For example, if your employees want to bring in to the office their home computers / tablets / netbooks, but you want to ensure a level of security and management, Windows Intune is fantastic for this as it provides them with the latest version of Windows, anti-malware and a great set of management policies for you to ensure they are safe and secure.

Of course, no matter what solution you use, you need skilled people to manage the PC infrastructure.  If you don’t have the staff, then Microsoft partners are the best bet.  Given my experience with SBSC partners over the years, if you are a SME, use a SBSC partner to help you.  They will charge for their services, but it will be money well spent!

There is more about this in the soon to be released book.

 

ttfn

David

Technorati Tags:

Posted Sat, Oct 1 2011 11:41 AM by David Overton

Comments

David Overton's Blog wrote How does a SBS partner win / lose with Windows Intune–discuss
on Mon, Oct 31 2011 11:31 PM

Hi, I don’t run my own business offering support to customers, but I thought I would put out a suggestion

Charles Hoffman wrote re: When does Windows Intune make sense for a company as the only management solution or hybrid
on Thu, Dec 1 2011 9:04 PM

For customers that don't have AD and are using InTune, is there a way to do single sign on with CRM On-premise?

David Overton wrote re: When does Windows Intune make sense for a company as the only management solution or hybrid
on Thu, Dec 1 2011 10:01 PM

Charles,

Windows Intune does not provide an alternative to AD today - I don't know if it will, so this is not a pre-announcement.

Which CRM package are you looking at?

Thanks

David

Charles Hoffman wrote re: When does Windows Intune make sense for a company as the only management solution or hybrid
on Fri, Dec 2 2011 10:39 PM

This would be for MS Dynamics on-premise (not the online version).  The question is a client has no PDC, so no AD, what solution is there to keep it all cloud based for InTune, etc. and Dynamics is off in a data center.  So sounds like there is no way to not have an AD sitting somewhere...  Bummer.

David Overton wrote re: When does Windows Intune make sense for a company as the only management solution or hybrid
on Sun, Dec 4 2011 10:28 PM

Charles, Windows Intune is a management solution, but does not offer, today (no, this is not a forward announcement), the ability to offer AD federation capabilities.

For Windows Intune the customer does not need to manage identity as the Windows Intune client install includes a certificate that is unique to your subscription for the service, so the user never needs to sign in.

If that was not what you were after, let me know.

David

Add a Comment

(required)
(optional)
(required)
Remember Me?

(c)David Overton 2006-23