About Ed Hands

 I have been working in the IT field for over twenty years.  

In addition to spending time with my beautiful wife and two lovely daughters,  I enjoy practicing the guitar, Tae Kwon Do, reading, and grilling out  I am always trying to plan the perfect road-trip with my family.  Hopefully there will be coffee.

The purpose of this blog is to journal my experience in the IT field and hopefully provide a useful guide to those doing likewise.  And to journal my random musings on technology, computers, or whatever else strikes my fancy.  Adult ADD FTW!!!!  Ohhh...look...something shiny....


Follow me!
Technology Blogs
technology blogs
Web Directory
OnToplist is optimized by SEO
Add blog to our directory.
ping web site via FeedShark
Shameless Self-Promotion



$100 (1) 2010 (1) 2011 (1) Active Directory (2) activecho (1) AD (1) air-watch (1) Android (7) Anger (1) App (1) app catalog (3) Apple (11) Apple iPad (3) Apps (3) AVI (2) bad science (1) Barracuda (1) Barracuda Networks (1) batch file (2) Beatles (1) best commercial (1) Blogger (1) Blogs (1) Boardwalk Empire (1) cancer (1) Cannot Get Mail (1) CDW (4) certprincipalname (1) cessation (1) Chantix (1) Christ (2) Cisco (1) Cisco VPN (2) climate (1) CNET (1) coffee (1) collaboration (1) comcastbusiness.net (2) distribution group (1) DOS (2) dropbox (1) DVD (1) EMC (1) Enlightenment (1) Evernote (3) Exchange (2) Exchange 2010 (4) Fallout 3 (1) family (1) FlexClone (1) Flipboard (1) Funny (1) GAL (1) Galaxy (1) Galaxy Tab (4) global warminig (1) God (1) GoodPlayer (1) Google (3) Google Toolbar (1) Gorilla Glass (1) GPO (2) Graditude (1) hacker (1) HDMI (1) horror (2) hotels (1) HP (4) humor (1) idiots (1) IE8 (1) IE9 (1) iftt.com (1) Internet Explorer (1) ios (1) iPad (5) iPhone (7) Jamie Foxx (1) Japanese (1) kuerig (1) Lefthand (1) magic (1) Mail list (1) MDM (1) Media Streaming (2) Meditation (4) Michael Richards (1) Microsoft (1) Middle East (1) MKV (2) MobilEcho (2) Movies (3) Murdoch (1) NBC (1) NetApp (5) Netflix (2) Network (3) Nook (1) NPR (1) OAB (1) Office (2) Only connect to proxy servers that have this principal name in their certificate (1) outlook (1) Outlook 2010 (1) Outlook Anywhere (1) OWA (1) Photos (1) quit (1) quit smoking (1) racist (1) rant (1) Rants (2) Resolutions (1) Resturants (3) Road Trip (1) Samsung (3) Saturday Night Live (1) science (1) Screen Shot (1) Seattle (2) security (1) Shattered (1) Shortcuts (1) smoking (1) SMP-N100 (1) SnapDrive (1) SNL (2) software (1) Sony (1) spam (2) spam filter (3) Spirituality (1) Squarespace (1) starbucks (1) Streaming (2) Super Bowl (1) Superbowl 2011 (1) Superbowl XLV (1) System Restore (1) Task (1) Teaching (1) Television (1) The Daily (1) top commercial (1) top ten (1) Touchpad (4) Training (1) Travel (2) Users (2) Verizon (1) verizon.net (1) VMWare (2) vsphere (1) WD TV (2) wd tv live (1) WDTVLIVEPLUS (2) web (1) webOS (3) Western Digital (2) Windows 7 (5) Windows Server (3) Wisconsin Dells (1) worst commercial (1) WPA (1) WPA2 (1) XBox 360 (1) XML (1) ZDNet (1) Zen (13) zombie (1)
« The Frustation of the trailing space... | Main | God has an interesting sense of humor sometimes... »

MDM Solution: Air-Watch and mobilEcho implementation

Over the past few months I have been working on a system to unify the management of our mobile devices and allow a BYOD policy at the same time. Currently we do not allow Androids in our business because of the security risk associated with them. But there is a lot of drive from our employees to go to them, as well as some good business reasons to do so as well. These reasons include the wide selection of carriers and the relative low cost of both the phones and the tablets. This makes the Android a very attractive platform. The security and fragmentation of the platform, however, have made it kind of hard to make a jump to the Android OS company-wide.

And being a small IT department of two people managing 300+ users, I didn't want to manage another device or server to accomplish these goals.

So with that in mind, I began looking for a MDM solution that would meet the following criteria:

The solution should

1) Manage multiple platforms including iOS, Android, Windows Mobile, and even Blackberry.

2) Be easy to use. I don't want to go through six weeks of training just to figure out how to use it.

3) Allow apps to be rolled out en masse.

4) Allow enforcement of security policies.

5) Allow selective wipe of company data from personal phones.

6) Roll out company settings for mail, VPN, WiFi, etc.

I chose four different solutions to evaluate. (Well, technically five, but since the Apple Configurator won’t magange Androids, Blackberries and Windows phones, it was DOA.)

The first was MobileIron. I was enthralled by MobileIron, but that soon waned when I discovered that MobileIron was on "on-premises" box that would need to be configured and maintained. But I was still tempted. MobileIron definitely has the security nailed down. I liked how it could handle rouge apps and the management seemed very smooth and tuned.

Next I looked at Meraki. Meraki was just bought by Cisco and honestly that's the reason I took a look at them. And oddly, it was also the thing that drove me away from them. Right now, the price is free. Yup, free. However, while they state they have no intentions of changing that, I have seen things like this change dramatically shortly after the little fish is eaten by the big fish. This would force me to either reevaluate the MDM solution and possibly re-implement another MDM solution at some point in the future. Worse yet, they could discontinue it all together and leave me in the lurch. It is a fine solution, and spreads far beyond just mobile devices to include PCs and Macs, but I need to minimize disruptions to the employees and this uncertainty didn't leave me with a warm fuzzy feeling.

The next two on my list were Air-watch and MaaS360, both at the recommendation of my CDW rep. After asking some folks I know at other companies and at the recommendation of some folks over at the IT Admin Forum at LinkedIn, I decided to try Air-watch first.

After they went through a short tutorial and got the initial test server configured, there were some minor issues but nothing huge. It did seem, at the beginning, that the profiles that Air-watch pushed out were hit or miss in regards to their implementation and their effectiveness. But after a while the basics were covered and everything was working fine. I was ready to broaden the test and implement an EIS (Enterprise Integration server) server internally and start rolling it out to some test users. Now I know, dear reader, that this flies in the face of my requirement of not having another server to manage, but please understand that this is merely a piece of software that runs on an existing server and has an agent that synchs Active directory information with the off-site Air-watch server. It also allows the Air-watch Secure Content Locker to map internal WebDAV shares, network shares, and Sharepoint Shares. This was going to be, for my company, the true selling point and power of Air-Watch.

Or so I thought. Initially everything worked fine. But then I started adding more shares and the problems began. Without getting into to gory of details, the shares that I had way exceed the normal capacity of Air-watch. And truthfully, even I was surprised by the quantity of documents we had and were trying to share. It turns out that in our main folder structure there were over 2,500,000 documents. It seems that currently (and I am speculating here because it is where AW stopped indexing the documents) that AW is limited to about 184,000 files. Which is probably fine for 99% of the users, but we needed either a) something that would get all of them, b) change the way the data is retained and structured or c) limit what we put in the SCL.

Before I continue, however, I want to take a moment to mention the customer support at Air-watch. From the sales rep to the tech support, they are one of the most dedicated group of folks I have ever seen in the industry. I could be cynical and say it was just because I was testing the software that they were so dedicated, but honestly the numbers just don't support such cynicism. We simply don't have a large enough user base for that to be true. So I feel they were doing it out of the commitment to the product and the customer. A number of times I had called it quits on AW because I didn't think it was going to be a good fit, but they worked with me and held my hand until I realized that it was a good fit and had a place in my organization. And more than that, they were going to help me make this MDM solution a success come hell or high-water. You don't find that often enough in IT companies.

Because of their dedication to product and customer, I never even made it to testing MaaS360.

So with the MDM solution secure, except for the ability to get network documents on the mobile devices, I decided to see if there as a piece of software dedicated to just that: putting data in network shares on mobile devices.

So after some investigation, I found MobileEcho by GroupLogic. Like AW, it also places a a few small files on the server (which I placed on the same server with the AW EIS software) and runs two services: one to index the files in the locations you want to share on the mobile device and the other to manage some extended permissions, handle wiping data, sending out enrolment notices, etc. All the management for the software, other than the indexing portion, is done through a simple but effective web interface.

Out of all the installations I have done and software I have implemented, I would have to say that this one of the simplest and easy to configure software packages I have ever seen. I had it up and running in about ten minutes. And the speed is incredible. Navigating the network shares on the mobile device is literally faster than doing it on the computer. I don't make this statement lightly: this software is amazing. The reaction from my test users were as follows:


"Buy it."

"Holy S*%$"

"How can I get this on my PC?"

The only caveat to it, and this is really a matter of choice, is that we are not going to open it up on the firewall. So my end users will need to access it via VPN. That means there is an additional step or two they will need to do to get access to their data which they would not have needed to do using the AW SCL. But in the end, that's okay because the tradeoff is speed is well worth those couple of extra steps.

I am now working on getting a firm count on mobile devices and users and working out pricing. I think these two products are going to benefit my company enormously and increase our competitive edge in our market.

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (1)

References allow you to track sources for this article, as well as articles that were written in response to this article.
  • Response
    MDM Solution: Air-Watch and mobilEcho implementation - Journal - /ReBoot.com

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>