
Explain the Ivanti epmm enterprise design, featuring a two-firewall dmz with core and sentry, and enable apps at work, active sync, and fcm/apns connectivity.
Log in to the Ivanti support site to download core and sentry software, review n-1 version guidance, and prepare your lab with core-sentry connectivity and certificates.
Announce a lab modification in section four, shifting the certificate revocation list hosting from the IIS server to external DNS to allow roaming devices to access the CRL.
Explore configuring a lab network for Ivanti EPMM by placing core and sentry in a DMZ behind a firewall, using destination NAT and external DNS to publish addresses.
Install and configure Ivanti EPMM core and sentry in a vanilla setup, including VM creation, CentOS/Oracle Linux OS, DNS and siklab local domain, interface, NTP, and admin portal access.
Explore certificate generation and management for Ivanti MobileIron, including creating a root CA and wildcard SAN certificate via CSR, satisfying iOS SAN requirements, and uploading to core and system manager.
Upload the wildcard and CA certificates to the core and Sentry, configure certificate enrollment, and enable mutual authentication to secure device enrollment and core trust.
Explore configurations, policies, certificates, and labels to automate cross-platform device provisioning, policy prioritization, and dynamic labeling during iOS registration and VPN access.
Explore Android enterprise framework, four deployment modes, and single device enrollment with Ivanti EPMM, including managed Google Play, work profile separation, and certificate setup for secure Android enrollment.
Explore ActiveSync integration by provisioning a dedicated sentry for ActiveSync, configuring Exchange settings for iOS, Windows, and Android, and validating TLS certificates and DNS records.
Create a common exchange config for iOS and Windows, apply it via the native mail clients, and configure server address, domain, SSL, and basic authentication.
Establish a high-availability cluster by configuring a primary active core and a passive secondary, monitor heartbeats on ports 443 and 8443, and perform manual sync for failover.
Explore troubleshooting and maintenance for Ivanti EPMM, examining audit logs, MDM activity, certificate management, LDAP sync, and ActiveSync/app tunnel status for proactive health checks.
Upgrade the Ivanti endpoint manager core to 12.1 by verifying release notes and compatibility, preparing backups, and following a controlled high-availability upgrade sequence for core and sentry.
Ivanti Endpoint Manager Mobile (Ivanti EPMM) - formerly MobileIron is a mobile device management(MDM) product; also referred to as mobility management or Unified Endpoint Management (UEM) software; makes IT administrators' life easier by streamlining the provisioning of mobile devices, their services and apps.
The product provides IT administrators with the upper hand to securely control and manage mobile devices lifecycle from registration till retiring the device from Ivanti EPMM management.
The product also enables the mobile users to securely access corporate data, email, and mobile apps through their controlled mobile devices
2011 witnessed the launch of the mobile management industry where many vendors led the industry including MobileIron at that time before Ivanti acquired it in late 2020
Ivanti EPMM (MobileIron) enables IT administrators to perform the following tasks:
Connect to backend services such as LDAP and leverage LDAP users for use in Ivanti EPMM.
Register both company- and employee-owned devices to be managed by Ivanti EPMM.
Configure and push to devices policies and settings such as VPN settings and security policies.
Distribute, install, and manage applications.
Leverage existing platform-specific mobile device management protocols, such as iOS MDM.
Configure and push certificates to devices.
In this course you will learn the following:
- Core (a.k.a UEM) and Sentry roles
- Core and Sentry Interfaces
- Ivanti EPMM Enterprise Design (Architecture & Connectivity Requirements)
- Core and Sentry Installation
- Certificate generation
- Upload Certificates and Connect Sentry with Core
- Configurations, Policies, and Labels
- How to prepare your iPhone mobile for registration
- iPhone registration
- iOS VPN configuration
- Android Enterprise
- Android registration
- Windows registration
- Sentry ActiveSync
- ActiveSync Integration
- Exchange configuration – iOS and Windows
- Exchange configuration – Android
- Administration
- High Availability
- Troubleshooting & Maintenance
- Core Upgrade
Please note that Ivanti EPMM image download/license requires ACTIVE SUPPORT entitlement or to be an active partner with IVANTI