在 Intune(公共预览版)中配置 eSIM 手机网络配置文件Configure eSIM cellular profiles in Intune (public preview)

eSIM 是一种嵌入式 SIM 芯片,可让你通过支持 eSIM 的设备(如 Surface LTE Pro)上的手机网络数据连接连接到 Internet。eSIM is an embedded SIM chip, and lets you connect to the Internet over a cellular data connection on an eSIM-capable device, such as the Surface LTE Pro. 如果使用 eSIM 卡,则无需从移动运营商处获取 SIM 卡。With an eSIM, you don't need to get a SIM card from your mobile operator. 如需跨国旅行,还可在不同移动运营商和数据套餐之间进行切换,并始终保持连接状态。As a global traveler, you can also switch between mobile operators and data plans to always stay connected.

例如,你有一个用于工作的手机网络流量套餐,还有另外一个私人使用的流量套餐,但由另一个移动运营商提供。For example, you have a cellular data plan for work, and another data plan with a different mobile operator for personal use. 当你在旅行时,可以通过查找在该区域提供流量套餐的移动运营商来获取 Internet 访问权限。When traveling, you can get Internet access by finding mobile operators with data plans in that area.

此功能适用于:This feature applies to:

  • Windows 10 及更高版本Windows 10 and newer

在 Intune 中,可以导入移动运营商提供的一次性使用的激活码。In Intune, you can import one time use activation codes provided by your mobile operator. 要在 eSIM 模块上配置手机网络流量套餐,请将这些激活码部署到支持 eSIM 的设备。To configure cellular data plans on the eSIM module, deploy those activation codes to your eSIM-capable devices. 当 Intune 安装激活码时,eSIM 硬件模块会使用激活码中的数据联系移动运营商。When Intune installs the activation code, the eSIM hardware module uses the data in the activation code to contact the mobile operator. 完成后,eSIM 配置文件将下载到设备上,并配置为激活手机网络。Once complete, the eSIM profile is downloaded on the device, and configured for cellular activation.

要使用 Intune 将 eSIM 部署到设备,需要以下条件:To deploy eSIM to your devices using Intune, the following are needed:

  • 支持 eSIM 的设备,例如,Surface LTE:请参阅设备是否支持 eSIMeSIM capable devices, such as the Surface LTE: See if your device supports eSIM. 或者,请参阅一些已知支持 eSIM 的设备的列表(在本文中)。Or, see a list of some of the known eSIM capable devices (in this article).
  • 已注册并且由 Intune 托管 MDM 的 Windows 10 Fall Creators Update PC(1709 或更高版本)Windows 10 Fall creators update PC (1709 or later) that is enrolled and MDM managed by Intune
  • 移动运营商提供的激活码。Activation codes provided by your mobile operator. 这些一次性使用的激活码被添加到 Intune,并部署到支持 eSIM 的设备。These one time-use activation codes are added to Intune, and deployed to your eSIM capable devices. 请联系移动运营商获取 eSIM 激活码。Contact your mobile operator to acquire eSIM activation codes.

将 eSIM 部署到设备 - 概述Deploy eSIM to devices - overview

要将 eSIM 部署到设备,管理员需完成以下任务:To deploy eSIM to devices, an Administrator completes the following tasks:

  1. 导入移动运营商提供的激活码Import activation codes provided by your mobile operator
  2. 创建 Azure Active Directory (Azure AD) 设备组,将支持 eSIM 的设备包含在内Create an Azure Active Directory (Azure AD) device group that includes your eSIM capable devices
  3. 将 Azure AD 组分配给已导入的订阅池Assign the Azure AD group to your imported subscription pool
  4. 监视部署Monitor the deployment

本文将指导你完成这些步骤。This article guides you through these steps.

支持 eSIM 的设备eSIM capable devices

如果不确定设备是否支持 eSIM,请联系你的设备制造商。If you’re unsure if your devices support eSIM, then contact your device manufacturer. 在 Windows 设备上,可以确认是否支持 eSIM。On Windows devices, you can confirm eSIM supportability. 有关详细信息,请参阅使用 eSIM 在 Windows 10 电脑上建立手机网络数据连接For more information, see Use an eSIM to get a cellular data connection on your Windows 10 PC.

步骤 1:添加手机网络激活代码Step 1: Add cellular activation codes

移动运营商在以逗号分隔的文件 (csv) 中提供手机网络激活码。Cellular activation codes are provided by your mobile operator in a comma-separated file (csv). 如果有此文件,请使用以下步骤将其添加到 Intune:When you have this file, add it to Intune using the following steps:

  1. 登录到 Microsoft 终结点管理器管理中心Sign in to the Microsoft Endpoint Manager admin center.
  2. 选择“设备” > “eSIM 移动电话配置文件” > “添加”。Select Devices > eSIM cellular profiles > Add.
  3. 选择具有激活码的 CSV 文件。Select the CSV file that has your activation codes.
  4. 选择“确定”,保存所做更改。Select OK to save your changes.

CSV 文件要求CSV file requirements

使用具有激活码的 csv 文件时,请确保你或你的移动运营商遵循以下要求:When working with the csv file with the activation codes, be sure you or your mobile operator follows the requirements:

  • 该文件必须采用 csv 格式 (filename.csv)。The file must be in csv format (filename.csv).
  • 文件结构必须严格遵循格式要求。The file structure must adhere to a strict format. 否则,会导入失败。Otherwise, the import fail. Intune 在导入时检查文件,并且如果发现错误则会失败。Intune checks the file on import, and fails if errors are found.
  • 激活码为一次性使用。Activation codes are used one time. 建议不要导入先前导入过的激活码,因为在部署到相同或不同的设备时可能会导致问题。It's not recommended to import activation codes that you previously imported, as it may cause problems when you deploy to the same or different device.
  • 每个文件应特定于单个移动运营商,并且所有激活码应特定于同一计费套餐。Each file should be specific to a single mobile operator, and all activation codes specific to the same billing plan. Intune 将激活码随机分配给目标设备。Intune randomly distributes the activation codes to targeted devices. 无法保证哪个设备会获得特定的激活码。There isn't any guarantee which device gets a specific activation code.
  • 一个 csv 文件中最多可以导入 1000 个激活码。A maximum of 1000 activation codes can be imported in one csv file.

CSV 文件示例CSV file example

  1. csv 的第一行和第一个单元格是移动运营商 eSIM 激活服务的 URL,称为 SM-DP +(订阅管理器数据准备服务器)。The first row and first cell of the csv is the URL of the mobile operator eSIM activation service, which is called SM-DP+ (Subscription Manager Data Preparation server). URL 应为完全限定的域名 (FQDN),不带任何逗号。The URL should be a fully qualified domain name (FQDN) without any commas.

  2. 第二行和所有后续行都是包含两个值的唯一一次性使用的激活码:The second and all later rows are unique one-time use activation codes that include two values:

    1. 第一列是唯一的 ICCID(SIM 芯片的标识符)First column is the unique ICCID (the identifier of the SIM chip)

    2. 第二列是匹配的 ID,只用逗号分隔它们(末尾没有逗号)。Second column is the Matching ID with only a comma separating them (no comma at the end). 请参阅以下示例:See the following example:

      移动运营商激活码示例 csv 文件。

  3. csv 文件名将成为 Endpoint Manager 管理中心中的手机网络订阅池名称。The csv file name becomes the cellular subscription pool name in the Endpoint Manager admin center. 在上图中,文件名为 UnlimitedDataSkynet.csvIn the previous image, the file name is UnlimitedDataSkynet.csv. 因此,Intune 将订阅池命名为 UnlimitedDataSkynet.csvSo, Intune names the subscription pool UnlimitedDataSkynet.csv:

    手机网络订阅池被命名为激活码示例 csv 文件名。

步骤 2:创建 Azure AD 设备组Step 2: Create an Azure AD device group

创建包含支持 eSIM 的设备的设备组。Create a Device group that includes the eSIM capable devices. 添加组列出了相关步骤。Add groups lists the steps.

备注

  • 仅针对设备,不针对用户。Only devices are targeted, users aren't targeted.
  • 我们建议创建包含 eSIM 设备的静态 Azure AD 设备组。We recommend creating a static Azure AD device group that includes your eSIM devices. 使用组即确认仅针对 eSIM 设备。Using a group confirms you target only eSIM devices.

步骤 3:将 eSIM 激活代码分配给设备Step 3: Assign eSIM activation codes to devices

将配置文件分配给包含 eSIM 设备的 Azure AD 组。Assign the profile to the Azure AD group that includes your eSIM devices.

  1. 登录到 Microsoft 终结点管理器管理中心Sign in to the Microsoft Endpoint Manager admin center.

  2. 选择“设备” > “eSIM 移动电话配置文件”。Select Devices > eSIM cellular profiles.

  3. 在配置文件列表中,选择要分配的 eSIM 手机网络订阅池,然后选择“分配”。In the list of profiles, select the eSIM cellular subscription pool you want to assign, and then select Assignments.

  4. 选择“包括”组或“排除”组,然后选择组 。Choose to Include groups or Exclude groups, and then select the groups.

    在 Microsoft Intune 中包含要分配配置文件的设备组。

  5. 选择组时,会选择 Azure AD 组。When you select your groups, you're choosing an Azure AD group. 要选择多个组,请使用 Ctrl 键,然后选择组。To select multiple groups, use the Ctrl key, and select the groups.

  6. 完成后,“保存”更改。When done, Save your changes.

eSIM 激活码为一次性使用。eSIM activation codes are used once. Intune 在设备上安装激活码后,eSIM 模块会联系移动运营商以下载手机网络配置文件。After Intune installs an activation code on a device, the eSIM module contacts the mobile operator to download the cellular profile. 该联系人会完成将设备注册到移动运营商网络。This contact finishes registering the device with mobile operator network.

步骤 4:监视部署Step 4: Monitor deployment

查看部署状态Review the deployment status

分配配置文件后,可以监视订阅池的部署状态。After you assign the profile, you can monitor the deployment status of a subscription pool.

  1. 登录到 Microsoft 终结点管理器管理中心Sign in to the Microsoft Endpoint Manager admin center.
  2. 选择“设备” > “eSIM 移动电话配置文件”。Select Devices > eSIM cellular profiles. 随即会列出所有现有的 eSIM 手机网络订阅池。All of your existing eSIM cellular subscription pools are listed.
  3. 选择订阅,然后查看“部署状态”。Select a subscription, and review the Deployment Status.

检查配置文件状态Check the profile status

创建设备配置文件后,Intune 会提供图形图表。After you create your device profile, Intune provides graphical charts. 这些图表显示配置文件的状态,例如成功分配给设备,或配置文件是否显示冲突。These charts display the status of a profile, such as it being successfully assigned to devices, or if the profile shows a conflict.

  1. 选择“设备” > “eSIM 手机网络配置文件”> 选择现有订阅。Select Devices > eSIM cellular profiles > Select an existing subscription.

  2. 在“概述”选项卡中,顶部图形图表显示分配给特定 eSIM 手机网络订阅池部署的设备数。In the Overview tab, the top graphical chart shows the number of devices assigned to the specific eSIM cellular subscription pool deployment.

    它还显示分配了相同设备配置文件的其他平台的设备数量。It also shows the number of devices for other platforms that are assigned the same device profile.

    Intune 显示针对设备的激活码的发送和安装状态。Intune shows the delivery and installation status for the activation code targeted to devices.

    • 设备未同步:创建 eSIM 部署策略后,目标设备未联系 IntuneDevice not synced: The targeted device hasn't contacted Intune since the eSIM deployment policy was created
    • 激活挂起:Intune 在设备上主动安装激活代码时的临时状态Activation pending: A transient state when Intune is actively installing the activation code on the device
    • 活动:激活代码安装成功Active: Activation code installation successful
    • 激活失败:激活代码安装失败 - 请参阅故障排除指南。Activation fail: Activation code installation failed – see troubleshooting guide.

查看设备状态详情View the detailed device status

可以监视和查看可在“设备状态”中查看的设备详细列表。**You can monitor and view a detailed list of devices you can view in Device Status.**

  1. 选择“设备” > “eSIM 手机网络配置文件”> 选择现有订阅。Select Devices > eSIM cellular profiles > Select an existing subscription.

  2. 选择“设备状态”。Select Device Status. Intune 会显示有关设备的其他详细信息:Intune shows additional details about the device:

    • 设备名:目标设备的名称Device Name: Name of the device that is targeted
    • 用户:注册设备的用户User: User of the enrolled device
    • ICCID:移动运营商在设备上安装的激活代码内提供的唯一代码ICCID: Unique code provided by the mobile operate within the activation code installed on the device
    • 激活状态:设备上激活代码的 Intune 发送和安装状态Activation Status: Intune delivery and installation status of the activation code on the device
    • 手机状态:由移动运营商提供的状态。Cellular status: State provided by the mobile operator. 跟进移动运营商进行故障排除。Follow up with mobile operator to troubleshoot.
    • 上次签入时间:设备上次与 Intune 通信的日期Last Check-In: Date the device last communicated with Intune

监视实际设备上的 eSIM 配置文件详细信息Monitor eSIM profile details on the actual device

  1. 在设备上,打开“设置”>转到“网络和 Internet” 。On your device, open Settings > go to Network & Internet.

  2. 选择“手机网络” > “管理 eSIM 配置文件” Select Cellular > Manage eSIM profiles

  3. 此时会列出 eSIM 配置文件:The eSIM profiles are listed:

    在设备设置中查看 eSIM 配置文件。

从设备中删除 eSIM 配置文件Remove the eSIM profile from device

从 Azure AD 组中删除设备时,也会删除 eSIM 配置文件。When you remove the device from the Azure AD group, the eSIM profile is also removed. 请务必:Be sure to:

  1. 确认使用的是 eSIM 设备 Azure AD 组。Confirm you're using the eSIM devices Azure AD group.
  2. 转到 Azure AD 组,然后从组中删除该设备。Go to the Azure AD group, and remove the device from the group.
  3. 当删除的设备联系 Intune 时,系统会评估更新的策略,并删除 eSIM 配置文件。When the removed device contacts Intune, the updated policy is evaluated, and the eSIM profile removed.

当用户停用或取消注册设备时,或者在设备上运行重置设备远程操作时,也会删除 eSIM 配置文件。The eSIM profile is also removed when the device is retired or unenrolled by the user, or when the reset device remote action runs on the device.

备注

删除配置文件可能无法停止计费。Removing the profile may not stop billing. 请联系移动运营商,检查设备的计费状态。Contact your mobile operator to check the billing status for your device.

最佳做法和疑难解答Best practices & troubleshooting

  • 确保 csv 文件格式正确。Be sure your csv file is properly formatted. 确认该文件不包含重复代码、多个移动运营商或不同的流量套餐。Confirm the file doesn't include duplicate codes, doesn't include multiple mobile operators, or doesn't include different data plans. 请记住,每个文件对于移动运营商和手机网络流量套餐必须是唯一的。Remember, each file must be unique to a mobile operator and cellular data plan.
  • 创建仅包含目标 eSIM 设备的静态设备 Azure AD 组。Create a static device Azure AD group that only includes the eSIM devices that are targeted.
  • 如果部署状态存在问题,请检查以下内容:If there's an issue with the deployment status, check the following:
    • 文件格式不正确:请参阅步骤 1:添加手机网络激活代码(在本文中),了解如何正确设置文件格式。File format not proper: See Step 1: Add cellular activation codes (in this article) on how to properly format your file.
    • 手机网络激活失败,请联系移动运营商:激活代码可能未在其网络中激活。Cellular activation failure, contact mobile operator: The activation code may not be activated within their network. 或者,配置文件下载和手机网络激活失败。Or, the profile download and cellular activation failed.

后续步骤Next steps

配置设备配置文件Configure device profiles