Jump to content

Recommended Posts

Posted

Can someone help walk me thru modern management of Windows 10 from when I first receive a laptop from the vendor to giving the laptop to the teacher or students.

I am trying to piece together the workflow.

 

How can I customize the OS? Do I still imaging it with a thin image or only apply provisioning packages created by WCD to customize the OS?

 

Do I manually run provisioning package on each computer, so touching every single computer?

 

To add the computer to the Azure AD, are the options bulk enrollment or Autopilot? Which method is better or what is the scenario to consider each method?

 

What settings and policies are set by provisioning package and which are managed by policies in Intune?

 

Thanks in advance.

Posted

First, my unhelpful but first thought response: Ha ha ha ha, good luck.

 

Next my thoughtful response: Ohh good question, I'm interested in responses to this too.

 

Now my considered response: Modern Management seems to have come out of a Microsoft brain storming session where they got confused if they were designing something of creating a vision statement. We have found lots of talk about it, migration paths to it, but no real meat on what it is and how to do actual tasks. Even a Fast Track session we have had has been a bit airy fairy.

 

What we have found so far. Forget everything you know and currently do to manage devices. This is Microsoft's power to the users, light admin touch management. Their use case is you get a newly ordered device shipped direct to a user, they turn it on, sign in and away they go, with some basics being pushed down from the corporate cloud. We have subverted it slightly in our tests by creating an enrollment user and setting up devices with that. Also bare in mind that a lot of the things possible in SCCM are not possible in Modern Management. Yet. Maybe. This is why they have cohabitation, with sliders to say how much control you want SCCM to have or InTune.

 

So to answer your questions:

 

- How can I customize the OS? Do I still imaging it with a thin image or only apply provisioning packages created by WCD to customize the OS?

You don't, is Microsoft's answer. They are expecting you to not even have your hands on it. We have found no bare metal install method at all within Modern Management. In our testing we have created a bog standard Win10 image to wipe a machine and that is as much as you can do, as far as we can tell. Our research indicates that to use Modern Management a user has to sign in at the very beginning of the OOBE setup, as well as the machine be registered in your InTune.

 

- Do I manually run provisioning package on each computer, so touching every single computer?

Again, you don't. Microsoft are aiming for you not touching anything, maybe not even having access to the device. We are going the route that we will always be the central hub so we will probably wipe any computer we get in to get rid of pre-installed guff. Currently we have been signing in with an enrollment user, as this prevents issues from the first user being a local admin, but come the day we have to prep 50, 75, 100 devices, I will not wanting to be doing that.

 

- To add the computer to the Azure AD, are the options bulk enrollment or Autopilot? Which method is better or what is the scenario to consider each method?

As far as I am aware Autopilot is the only method, but there is a bulk enrollment option available, you just have to get the details from the hardware. Again, if your supplier does not do this for you, Heaven help us as it will be a mammoth task.

 

- What settings and policies are set by provisioning package and which are managed by policies in Intune?

Everything comes from InTune, again because of this idea that you may potentially not even see the device.

 

So, as far as we can make out, the flow would be something like this:

 

* Order devices

* Supplier Autopilots them on to your InTune

* Devices arrive

* Two options, either dump the new devices straight on the user or unbox and wipe.

* User logs in.

* OOBE process checks against the cloud to see if device has been registered

* Device recognised as in your organisation

* Organisation settings and details dumped down

* User carries on their day.

 

No please do not rely on any of my answers as gospel, this is just what we can work out. There are still a lot of questions, of which I think a lot of them either can't be answered or the answer is just no. Such as "Why does the first user become a local admin and can I turn that off?". Also remember that Applications are expected to either come from the Business Store or an MSI only.

 

Things seem to be changing very slowly and we are still discussing if cohabitation is the way to go until InTune is more fully featured, or if we just embrace the change and go with it. It is a massive change in IT Management process, ideas and historical processes, but that is the way we seem to be going. There are a lot of articles on WindowsNoob, but we have only just found them so not sure how good they are.

 

Hope that is more helpful than my first response but currently it really feels like the blind leading the blind on Modern Management.

  • 3 weeks later...
Posted

Thanks for your insight into Modern Management. It was very helpful.

 

I have since talked to a Microsoft rep and your info is pretty spot on.

 

Here are some notes to help me understand after talking to the MS rep.

 

Workflow:

Buy computer from vendor -> upload AutoPilot info to Intune (either get info from vendor or run PowerShell script to gather info) -> user logs in using Azure account -> machine is managed by Intune MDM -> computer grabs policies from Intune

 

There is no need to reimage a computer if the computers are at least v1703 or later which is the requirement for Autopilot. If an older computer doesn't meet this requirement, then the computer will need to be reimaged using a Windows 10 ISO (no need to create a base image) using MDT or bootable USB. Don't use SCCM as it adds the SCCM client to computer which is not desirable.

 

No need to use provisioning package from WCD tool. Intune takes care of "everything".

 

I think the hard part for me is that I am coming from SCCM world, so I am comparing the process and performance to a traditional Windows computer.

I see the inability to add non-MSI applications or customize the OS as a negative, but the selling point with Intune is faster sign-in (yet to be tested and confirm), more secure since the computers are getting updates from Microsoft and not need to rely on administrator managing the updates on SCCM (I have never really seen Software Updates work in SCCM), less management, etc.

Instead of comparing this workstation not a traditional Windows computer, this needs to be compared to a Chromebook.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...