Deployingandmanagingapplicationsacrossplatformsisdifficult.AppsToday’schallengesUsersexpecttobeabletoworkinanylocationandhaveaccesstoalltheirworkresources.UsersDataUsersneedtobeproductivewhilemaintainingcomplianceandreducingrisk.Theexplosionofdevicesiserodingthestandards-basedapproachtocorporateIT.DevicesUsersPeople-centricITEnableyourendusersAllowuserstoworkonthedevicesoftheirchoiceandprovideconsistentaccesstocorporateresources.UnifyyourenvironmentDeliveraunifiedapplicationanddevicemanagementon-premisesandinthecloud.ProtectyourdataHelpprotectcorporateinformationandmanagerisk.Management.Access.Protection.DataDevicesAppsAccessandInformationProtectionProtectyourdataCentralizecorporateinformationforcomplianceanddataprotectionPolicy-basedaccesscontroltoapplicationsanddataEmpowerusersSimplifiedregistrationandenrollmentforBYOdevicesAutomaticallyconnecttointernalresourceswhenneededAccesstocompanyresourcesisconsistentacrossdevices√UnifyyourenvironmentCommonidentitytoaccessresourceson-premisesandinthecloudChallengesSolutionsUserswanttousethedeviceoftheirchoiceandhaveaccesstoboththeirpersonalandwork-relatedapplications,data,andresources.Userswantaneasywaytobeabletoaccesstheircorporateapplicationsfromanywhere.ITdepartmentswanttoempoweruserstoworkthisway,buttheyalsoneedtocontrolaccesstosensitiveinformationandremainincompliancewithregulatorypolicies.Userscanregistertheirdevices,whichmakesthemknowntoIT,whocanthenusedeviceauthenticationaspartofprovidingaccesstocorporateresources.Userscanenrolltheirdevices,whichprovidesthemwiththecompanyportalforconsistentaccesstoapplicationsanddata,andtomanagetheirdevices.ITcanpublishaccesstocorporateresourceswithconditionalaccessbasedontheuser’sidentity,thedevicetheyareusing,andtheirlocation.EmpowerusersEnablingITtoempowerusersITcanpublishaccesstoresourceswiththeWebApplicationProxybasedondeviceawarenessandtheusersidentityITcanprovideseamlesscorporateaccesswithDirectAccessandautomaticVPNconnections.Userscanworkfromanywhereontheirdevicewithaccesstotheircorporateresources.Userscanregisterdevicesforsinglesign-onandaccesstocorporatedatawithWorkplaceJoinUserscanenrolldevicesforaccesstotheCompanyPortalforeasyaccesstocorporateapplicationsITcanpublishDesktopVirtualization(VDI)foraccesstocentralizedresourcesActiveDirectoryWebAppsWebApplicationProxyRemoteAccessRDSGatewayVDISessionhostFilesLOBAppsRegisteringandEnrollingDevicesITcanpublishaccesstocorporateresourceswiththeWebApplicationProxybasedondeviceawarenessandtheusersidentity.Multi-factorauthenticationcanbeusedthroughWindowsAzureActiveAuthentication.UserscanregisterBYOdevicesforsinglesign-onandaccesstocorporatedatawithWorkplaceJoin.Aspartofthis,acertificateisinstalledonthedeviceUserscanenrolldeviceswhichconfigurethedeviceformanagementwithWindowsIntune.TheusercanthenusetheCompanyPortalforeasyaccesstocorporateapplicationsAspartoftheregistrationprocess,anewdeviceobjectiscreatedinActiveDirectory,establishingalinkbetweentheuserandtheirdeviceDatafromWindowsIntuneissyncwithConfigurationManagerwhichprovidesunifiedmanagementacrossbothon-premisesandinthecloudActiveAuthenticationActiveDirectoryWebApplicationProxyADFSDemoWorkplaceJoinPublishaccesstoresourceswiththeWebApplicationProxyUserscanaccesscorporateapplicationsanddatawherevertheyareITcanusetheWebApplicationProxytoauthenticateusersanddeviceswithmulti-factorauthenticationUseconditionalaccessforgranularcontroloverhowandwheretheapplicationcanbeaccessedActiveDirectoryprovidesthecentralrepositoryofuseridentityaswellasthedeviceregistrationinformationOthercloudbasedappsandidentitystoresMobileServicesActiveDirectoryDeveloperscanleverageWindowsAzureMobileServicestointegrateandenhancetheirappsActiveDirectoryReverseproxypassthroughe.g.NTLM&BasicbasedappsPublishedapplicationsRestfulOAuthappsOfficeFormsBasedAccessClaims&KerberoswebappsADIntegratedADFSWebApplicationProxyDevicesApps&DataDemoWebApplicationProxy17网