Jump to content

Recommended Posts

Posted

Hi all,

 

We're planning on deploying laptops to staff in the near future. What do you guys recommend? Do we keep them as domain joined devices or not?

 

Also what policies do you have for laptop usage and how do you handle insurance, breakages and repeat breakage offenders.

 

So far my plan is...

 

deploy non-domain joined laptops with BitLocker and a local group policy set, using Forticlient (we have fortinet firewall) to provide web filtering, AV and Vulnerability scanning. Use either inTune or something you suggest for MDM.

 

How do you guys allow access in to your network? VPN or RemoteApps or something else? If something else; can you perhaps point me in the direction of a good guide/tutorial.

 

I look forward to hearing your ideas and would like to thank you for taking the time to read this! :)

Posted

Ours are all domain joined, Bitlockered with the Documents folder (only) set to synch with their home folder when in school. Primary/Junior schools so they haven't asked for remote access.

 

Usage Policies? If only...

Posted
I would defo recommend domain joined. We still have some 'legacy' laptops which are standalone and changes to shares / filtering / printers etc become a pain. GPO's are much easier to manage them with.
Posted
I can't see a reason not to have them domain joined?

 

Only one I can see is speed. Though would always recommend domain joined for ease of managabilty and security.

Posted
Definitely domain joined. They can log in "offline" at home with auo sync to the hard disk encrypted with bitlocker. But when in the building the laptop will get the same benefits as any other computer on the network in terms of package deployment, group policy, updates, printer mappings, AV protection etc.
Posted

Domain Joined with AzureAD join (on by default if you have AD AzureAD Connect)]

Bitlocker

 

OneDrive for Business for Documents.

 

On Desktops (if you have any remaining) migrate their Documentes to OneDrive in the autumn once Selective Sync goes GA.

 

Set them to either go direct to MS for updates, or open up your WSUS server to the internet.

Same for Anti-Malware updates.

 

Setup up DirectAccess for remote access.

 

Disable boot menus unless the supervisor password has been provided.

Set the SSD to be the first and only boot device.

 

Do not give them admin.

 

If it wasn't for printing, SIMS and quirks with our 802.1x setup we could probably move to AzureAD joined only with InTune for app deployment / management.

  • Thanks 1
Posted

Thanks for your reply! Do you have any more info please on Selective Sync (first i've heard of it). Also do you have a copy of your policies or can you tell me what your agreement is when it comes to breakages and lost laptops.

 

Thanks

Posted

Domain joined here. Offline files (encrypted) . Remote access is allowed selectively over VPN via Fortigate.

 

Had to educate some teachers as they had a couple of synch problems due to the way they were working. Apart from that absolutely fine.

 

We used to use LEA for Internet so just created a couple of scripts imaginatively named "At Work" and "At Home" to toggle the Use Proxy setting.

 

Since moving away from LEA no need for this.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...