- Introduction to Windows Intune
- Mobile Device Management Features
- Windows Intune Licensing and Supported Architectures
- The Windows Intune Connector and Subscription
The Windows Intune Connector and Subscription
Until this point, there have been references to a connector within Configuration Manager to integrate with Windows Intune, without fully explaining what this is. The Windows Intune connector is a ConfigMgr site system role that uses Secure Sockets Layer (SSL) port 443 to communicate to the Windows Intune cloud service. A Windows Intune subscription is created within ConfigMgr to define the mobile platforms ConfigMgr supports and the Microsoft Online Services cloud tenant to which to connect.
The subscription allows the organization to specify the mobile device configuration settings for the Windows Intune service. It is defined before the Intune connector is installed and contains the following items:
- Windows Intune Organizational ID: This is the actual Windows Intune service the organization must license (separately) and Azure AD namespace that defines the service in the format of *.onmicrosoft.com. The ConfigMgr administrator needs the service available to configure the remainder of the Intune subscription.
- Setting the Management Authority: This defines the way the organization manages mobile devices, either using ConfigMgr or Intune cloud-only. An organization can only choose a single authority method.
- ConfigMgr User Collection: This collection defines the users within the organization that can enroll mobile devices.
- Company Portal Information: Details on the color scheme and general information listed in the company portals.
- Primary Site Code: The ConfigMgr site code into which the Intune connector site system role is installed.
- Mobile Device Platforms Provisioning: Defines which mobile platforms users can enroll into the environment along with configurations necessary to support each mobile device.
After the subscription has been configured, the Windows Intune connector site system role is installed, and the connection to Intune is complete. On a set schedule, the connector site system role pushes device settings and deploys applications to the Windows Intune service, enables new users to be able to enroll their mobile devices, and pulls new data about existing managed mobile devices and stores it within the database.
Chapter 7 includes detailed information on installing and using the connector.