colacao82 Posted July 7, 2017 Posted July 7, 2017 Hi all, We're planning on deploying laptops to staff in the near future. What do you guys recommend? Do we keep them as domain joined devices or not? Also what policies do you have for laptop usage and how do you handle insurance, breakages and repeat breakage offenders. So far my plan is... deploy non-domain joined laptops with BitLocker and a local group policy set, using Forticlient (we have fortinet firewall) to provide web filtering, AV and Vulnerability scanning. Use either inTune or something you suggest for MDM. How do you guys allow access in to your network? VPN or RemoteApps or something else? If something else; can you perhaps point me in the direction of a good guide/tutorial. I look forward to hearing your ideas and would like to thank you for taking the time to read this!
LeMarchand Posted July 7, 2017 Posted July 7, 2017 Ours are all domain joined, Bitlockered with the Documents folder (only) set to synch with their home folder when in school. Primary/Junior schools so they haven't asked for remote access. Usage Policies? If only...
XiJ Posted July 7, 2017 Posted July 7, 2017 I would defo recommend domain joined. We still have some 'legacy' laptops which are standalone and changes to shares / filtering / printers etc become a pain. GPO's are much easier to manage them with.
RobD Posted July 7, 2017 Posted July 7, 2017 I'd go with domain joined with workfolders and direct access.
DJ-1701 Posted July 7, 2017 Posted July 7, 2017 I can't see a reason not to have them domain joined? Only one I can see is speed. Though would always recommend domain joined for ease of managabilty and security.
ReverentCreature Posted July 7, 2017 Posted July 7, 2017 Definitely domain joined. They can log in "offline" at home with auo sync to the hard disk encrypted with bitlocker. But when in the building the laptop will get the same benefits as any other computer on the network in terms of package deployment, group policy, updates, printer mappings, AV protection etc.
psydii Posted July 7, 2017 Posted July 7, 2017 Domain Joined with AzureAD join (on by default if you have AD AzureAD Connect)] Bitlocker OneDrive for Business for Documents. On Desktops (if you have any remaining) migrate their Documentes to OneDrive in the autumn once Selective Sync goes GA. Set them to either go direct to MS for updates, or open up your WSUS server to the internet. Same for Anti-Malware updates. Setup up DirectAccess for remote access. Disable boot menus unless the supervisor password has been provided. Set the SSD to be the first and only boot device. Do not give them admin. If it wasn't for printing, SIMS and quirks with our 802.1x setup we could probably move to AzureAD joined only with InTune for app deployment / management. 1
colacao82 Posted July 12, 2017 Author Posted July 12, 2017 Thanks for your reply! Do you have any more info please on Selective Sync (first i've heard of it). Also do you have a copy of your policies or can you tell me what your agreement is when it comes to breakages and lost laptops. Thanks
tinca492 Posted July 12, 2017 Posted July 12, 2017 Domain joined here. Offline files (encrypted) . Remote access is allowed selectively over VPN via Fortigate. Had to educate some teachers as they had a couple of synch problems due to the way they were working. Apart from that absolutely fine. We used to use LEA for Internet so just created a couple of scripts imaginatively named "At Work" and "At Home" to toggle the Use Proxy setting. Since moving away from LEA no need for this.
TwistedHelixis Posted July 12, 2017 Posted July 12, 2017 All my primary schools have domain joined laptops and remote access from home, connecting to the remote access server (built in to windows server) is very simple.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now