Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Windows 11 for Enterprise Administrators - Second Edition

You're reading from  Windows 11 for Enterprise Administrators - Second Edition

Product type Book
Published in Oct 2023
Publisher Packt
ISBN-13 9781804618592
Pages 286 pages
Edition 2nd Edition
Languages
Authors (5):
Manuel Singer Manuel Singer
Profile icon Manuel Singer
Jeff Stokes Jeff Stokes
Profile icon Jeff Stokes
Steve Miles Steve Miles
Profile icon Steve Miles
Thomas Lee Thomas Lee
Profile icon Thomas Lee
Richard Diver Richard Diver
Profile icon Richard Diver
View More author details

Table of Contents (13) Chapters

Preface 1. Chapter 1: Windows 11 – Installation and Upgrading 2. Chapter 2: Introduction to PowerShell 3. Chapter 3: Configuration and Customization 4. Chapter 4: User Account Administration 5. Chapter 5: Tools to Manage Windows 11 6. Chapter 6: Device Management 7. Chapter 7: Accessing Enterprise Data in BYOD and CYOD Scenarios 8. Chapter 8: Windows 11 Security 9. Chapter 9: Advanced Configurations 10. Chapter 10: Windows 11 21H2 and 22H2 Changes (versus Windows 10) 11. Index 12. Other Books You May Enjoy

Accessing Enterprise Data in BYOD and CYOD Scenarios

This chapter discusses accessing enterprise data in End User Computing (EUC) device scenarios. The main objective of this chapter is to provide information and guidance on accessing corporate data on personally owned Windows 11 devices. To achieve that, the chapter will take us through EUC device models, key considerations, device choice options, ownership, and management responsibilities.

Note that securing EUC devices will be covered in Chapter 8, Windows 11 Security.

In this chapter, the following topics will be covered:

  • What are the EUC device models?
  • Protection and governance options
  • Storage sync options
  • Alternative EUC delivery options

What are the EUC device models?

In 2019/2020, the COVID-19 global pandemic changed so much about what we do and how we do it forever. We had our approach to Bring Your Own Device (BYOD) and Choose Your Own Device (CYOD) redefined.

Historically, IT catered only to a minority of an organization’s workforce that operated outside of the company offices; now, in 2023, we are adjusting to a new normal of a hybrid workforce in most cases.

These changes have been reflected in our attitudes to EUC solutions, and how technology must adapt and evolve to meet an organization’s productivity demands for its users.

The following sections will first introduce the concepts of the BYOD and CYOD EUC solutions; we will then look at key considerations such as device choice, ownership, and management responsibility, and compare the options.

The bring your own device model

In this section, we will introduce the concept of the BYOD EUC model. BYOD is an EUC solution approach in...

Protection and governance options

Multiple options are available to provide the appropriate security and governance controls for BYOD scenarios. With the shift in security approaches from perimeter networks to end user devices, a defense-in-depth and layered approach should be taken; you can then identify which combination of options is required for your specific business requirements, technical capabilities, and end user scenarios.

The following topics will be covered in this section, specifically those related to BYOD and CYOD scenarios:

  • Identity and access management
  • Information protection
  • Device configuration
  • Application management:
    • Provisioning packages
    • Mobile application management

Identity and access management

In a scenario where a corporate-owned device (COD) is on the company network being Active Directory (AD) joined, then identity and access management (IAM) is generally controlled by AD and Group Policy. A device may even be Azure AD joined...

Storage sync options

In this section, we will look at the available storage sync options of OneDrive for Business and Work Folders.

OneDrive for Business

This solution is a core part of the Microsoft 365 platform and provides a cloud storage and sharing solution. There are several options available to ensure that data is protected – for example, allowing users only to synchronize their OneDrive folders on authorized devices. If the device is not domain joined or compliant (for example, enrolled with Intune MDM), then the user will only be able to gain access to the content via a browser. Controls can also be set to control the ability for the user to share their content from OneDrive to internal or external third parties.

It is also possible to govern access based on device specifics, such as restricting access based on the IP address and support for modern authentication. If the MAM section is grayed out, then settings are being controlled by Microsoft Intune instead...

Alternative EUC delivery options

With the pandemic of 2020, we entered a new era of the hybrid workplace, and with it, the endpoint computing strategy is transforming at an ever-increasing rate of innovation.

Now more than ever, work is no longer somewhere we go as such; the PC, wherever that may be, is now the office.

Windows 365 Cloud PC and Azure Virtual Desktop

Traditionally, companies have implemented EUC solutions such as Remote Desktop Service (RDS)/Virtual Desktop Infrastructure (VDI) to provide users access to company apps and data. The last couple of years have seen innovation in this area.

Microsoft launched Azure Virtual Desktop (AVD), previously called Windows Virtual Desktop (WVD), a Microsoft desktop and app virtualization service that can utilize multi-session Windows 10 and Windows 11 images for desktops.

Layered on top of this desktop virtualization service hosted in Microsoft Azure, Microsoft provides Windows 365, also referred to as Cloud PC; it provides...

Summary

In this chapter, we covered the BYOD and CYOD scenarios, key considerations for deciding which types of devices can be used by your users, and the risks and benefits of each option. Whether you enforce MDM to manage external devices or opt for a MAM-only option, there are plenty of choices for providing access and governance to resources. We also looked at alternative EUC solutions and storage sync options.

In the next chapter, we will explore the new hardware and software-based security options available in Windows 11.

lock icon The rest of the chapter is locked
You have been reading a chapter from
Windows 11 for Enterprise Administrators - Second Edition
Published in: Oct 2023 Publisher: Packt ISBN-13: 9781804618592
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}