Back

Enterprise Mobility Suite Overview with Brad Anderson

As more apps and data move to cloud traditional perimeter security has become irrelevant and ineffectiveWith widespread EMM consolidation compani...

4 min read
Published on Mar 24, 2016
Enterprise Mobility Suite Overview with Brad Anderson

As more apps and data move to cloud, traditional perimeter security has become irrelevant and ineffective.

With widespread EMM consolidation, companies are no longer looking for disparate identity, device management, app management and data management solutions. They need a comprehensive solution that enables mobile productivity.

EMS is a born-in-the-cloud solution that integrates with on-premises capabilities. So it serves as an extension from what you’re already using, enables you to capitalize on gaps between products and equip users to do more. Learn more about getting EMS deployed in your organization.

The concept of security in the Microsoft-hosted cloud may be difficult to grapple for some, especially when it comes to protecting all the aspects of users and company data on the go. That’s why Microsoft exec Brad Anderson recently released a video that breaks down the EMS capabilities (42 minute video).

Here are 3 distinguishing characteristics of EMS that make it the most comprehensive cloud security platform:

1. Verifying Identity With Azure Active Directory

Identity is the most important part of an enterprise mobility management platform and architecture. While the cloud has increased productivity, more entry points and interactions mean 1 threat could compromise an entire organization.

2.  Azure Active Directory is the identity store and security springboard for all corporate apps, devices, etc. Once users have proven who they are, they can access apps like Office 365 and have everything delivered to them to be productive. Microsoft has worked with thousands of partners (including 2,500 SaaS apps) to ensure they also integrate with AD.

To prevent against malicious access, you can enable multi-factor authentication (verification via email or text) through Microsoft EMS. Windows 10 takes this one step further through camera authentication, which eliminates the need for passwords and unauthorized logins altogether.

3.  Managing Corporate Apps, Not Devices

Microsoft EMS focuses on managing corporate apps, not the devices themselves, so users can work securely from the apps and devices they prefer while retaining control over their personal data. Microsoft’s Advanced Threat Analytics and telemetry capabilities sift through data to point you to suspicious activity. Here are just a few technologies at work:

  • Cloud App Discovery brings apps under management so you can drill into specific apps to see user activity, how much data is transferred, etc. Other management capabilities include auto provisioning and access revoking, single sign-on, etc.
  • Azure Machine Learning identifies who is using apps, when they’re being used and from where and delivers custom reports.
  • Anomalous Sign-in Reports tell you when people are attempting to sign in from hidden IP addresses, from multiple accounts or from two different locations within a short period of time.
  • Microsoft’s Digital Crimes Unit constantly looks at the dark part of web to find user credentials for sale and compromised user accounts.

Distinguishing Between Corporate and Personal Data

How can data loss prevention (DLP) be applied to corporate documents but not personal ones?

Microsoft has baked the concept of multi-use (employees use devices for both work and personal use) into its security platform. For example, built-in intelligence identifies what is corporate or personal data and restricts users from sharing corporate information via a personal email or copying and pasting it.

By protecting the apps, not the device itself, you’re able to apply policy to corporate apps without taking over device.

Here are a few ways EMS promotes smart data loss prevention when managing data transfer across partners and employees:

Tech Tips built into Office: By identifying sensitive data such as credit card numbers, EMS provides pops-up Tech Tips to help users make smarter decisions when handling sensitive data.

  • Access embedded into documents: Files inherently understand who can open it and what rights particular users have.
  • Integration with Azure RMS: When users share a document, it actually contains names of users who can access it and the rights they have. Users can share information and track how the data is being used — who is accessing documents, attempts to open from unauthorized users, etc. — all by time and location.
  • Easy open/send for RMS-protected documents: In the past, it wasn’t possible to read, edit and send RMS-protect documents with devices. Now, EMS makes it simple to read, create and edit these files.

The core belief behind EMS is that data should be self-protecting and inherently understand who can open it and what rights those users have.

If you have any questions about the Enterprise Mobility Suite or want to learn how it can protect your corporate assets in the cloud, contact an Agile IT rep today!

This post has matured and its content may no longer be relevant beyond historical reference. To see the most current information on a given topic, click on the associated category or tag.

Related Posts

MSP vs. In-House Support for CUI Data Management

MSP vs. In-House Support for CUI Data Management

Compare MSP vs. in-house support for CUI data management. Explore cost, expertise, compliance readiness, and which approach best protects sensitive government data.

Sep 18, 2025
8 min read
How to Plan an Effective Backup Strategy for Microsoft 365

How to Plan an Effective Backup Strategy for Microsoft 365

Learn how to plan and implement a backup strategy for Microsoft 365 that protects critical data in Exchange, SharePoint, Teams, and OneDrive against loss, ransomware, and compliance risks.

Sep 17, 2025
6 min read
GCC High Licensing and Validation Challenges

Common Challenges in GCC High Licensing and Validation

Uncover common challenges in Microsoft GCC High licensing and validation, including eligibility issues, documentation gaps, and partner approval hurdles.

Sep 16, 2025
7 min read
Microsoft GCC High Validation Steps Explained

Navigating the Microsoft GCC High Validation Steps

Explore the step-by-step process for Microsoft GCC High validation, including eligibility, documentation, and how to secure access for CMMC and DFARS compliance.

Sep 15, 2025
7 min read
GCC High Licensing Requirements for Small Businesses

GCC High Licensing Requirements for Small Businesses

Learn the licensing requirements for small businesses seeking Microsoft 365 GCC High, including minimum user counts, eligibility, and steps for purchasing secure cloud licenses.

Sep 12, 2025
7 min read
GCC vs. GCC High: CMMC Ain’t Just Some Box to Check

GCC vs. GCC High: CMMC Ain’t Just Some Box to Check

Think GCC is “close enough” for CMMC Level 2? Think again. We break down GCC vs. GCC High and why compliance isn’t just a licensing checkbox.

Sep 12, 2025
6 min read

Ready to Secure and Defend Your Data
So Your Business Can Thrive?

Fill out the form to see how we can protect your data and help your business grow.

Loading...
Secure. Defend. Thrive.

Let's start a conversation

Discover more about Agile IT's range of services by reaching out.

Don’t want to wait for us to get back to you?

Schedule a Free Consultation

Location

Agile IT Headquarters
4660 La Jolla Village Drive #100
San Diego, CA 92122