just_david Posted August 11, 2017 Posted August 11, 2017 Just had a query come in and i'm damned if i can think of a current solution. But is there such a thing as an MDM for windows laptops? I'm thinking a single web portal for managing laptops that often leave site, or might never be on site. Is there a simple one step solution like zuludesk or meraki for windows 10?
fathead Posted August 11, 2017 Posted August 11, 2017 Yes, pretty sure Meraki has a Win 10 agent https://meraki.cisco.com/blog/2016/08/in-the-know-about-windows-10-and-sm/
sparkeh Posted August 12, 2017 Posted August 12, 2017 ..Isn't it called Active Directory and GPO The OP asked about laptops that are rarely or never on site. AD and GPO won't help there. MS are pushing InTune for this and there's other MDMs that could be used as stated above. 2
sparkeh Posted August 12, 2017 Posted August 12, 2017 Active directory and Direct access? Doesn't satisfy the 'never on site' requirement. With an MDM you can configure and manage the device without it ever coming on site. I can't see how you can do that with AD + DA but please correct me if I am wrong?
just_david Posted August 12, 2017 Author Posted August 12, 2017 Yeah, i'm referring to cases where laptops may never come on site, other than when broken. I think you could do it with ad using azure, but thats probably a whole load to exppensive for the environments i'm thinking of. Just how much control do I get with the likes of meraki? Given the nature they wouldn't need to be locked down like a site machine would. The control only needs to be as simple as monitoring use and managing security. anything extra would be a bonus.
LytchettNM Posted August 12, 2017 Posted August 12, 2017 Using direct access will give the network management over external computers (fully integrated into window 8 onward, windows 7 requires some extra work to the client) that are not on the direct LAN, this is done using IPV6 so some old business application that are IPV4 only will not work, but for these app's you can setup terminal services and share your older IPV4 only apps as a remote app.
Guest kiest90 Posted August 12, 2017 Posted August 12, 2017 Would the initial configuration be performed on site?
sparkeh Posted August 12, 2017 Posted August 12, 2017 For DA you would need the device on site to add to AD and pick up the DA GPOs. Using an MDM this is not necessary
LytchettNM Posted August 12, 2017 Posted August 12, 2017 (edited) Yes you setup the server that you are going to run DA on and its wizard will add a GPO to your domain, you then add the computers we want to have remote access to this group. Gpupdate the laptop and you all done, when the remote computer has internet access outside of your LAN it will create a tunnel via IPV6 without need for the user to do anything and push any policy's you have assigned to that work station. The admin just need to bear in mind that pushing say a new package will work but take much much longer than on LAN. Edited August 12, 2017 by Techforyou
just_david Posted August 15, 2017 Author Posted August 15, 2017 Thanks guys those are some great starting points.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now