Jump to content

Recommended Posts

Posted

We have been advised...recommended...to use Intune to manage a new issue of staff laptops...to deploy apps, limit access to usb...etc etc.

 

Anyone been down this route? Will it work? Will be need SCCM as well?

Posted

We are running a small scale trial looking at exactly what you are, staff laptops that can be taken away from site. You don't need to use SCCM, we are building the devices and installing the main apps with MDT. Apps can only be deployed as MSIs, problematic if they need MSTs. It's not bad and there are gaps, you could say unexcusable for MS, but they are being filled. The security options are nice.

 

Powershell will be important.

 

Biggest thing you have to do is remember it is not GPO. You will not be able to lock down every little thing.

 

HTH and give a yell if you have any specific questions

Posted

Intune is a good MDM but going by the last time I looked at it, its ability to manage desktop machines is pretty limited.

 

It’s very user centric. It can be used to manage apps and settings on phones, tablets etc and you can use it to deploy modern apps from the MS Store on W8/8.1/10 devices but I don’t think it can do traditional application deployment.

 

It can be integrated into SCCM but it’s not a requirement.

 

Frankly, I’d use SCCM or whatever system you’re using to manage desktops with at the moment over it to manage domain joined laptops.

  • Thanks 1
Posted (edited)
you can use it to deploy modern apps from the MS Store on W8/8.1/10 devices but I don’t think it can do traditional application deployment.

You *could* using the silverlight interface but that's being retired for the Azure one soonish although I think it needed the client which is now not recommended on Windows 10 Fall update if I recall.

 

EDIT: This: https://www.anoopcnair.com/intune-azure-end-end-msi-lob-app-deployment-video-guide/ appears to show how to deploy an MSI but it needs to be targetting at machines only I believe.

Edited by ZeroHour
Posted
You can run powershell scripts but they have to targeted at users. They only run once. In theory you could download aexe from http/s and install via powershell. Microsoft have pitched intune at 1:1 devices primarily and with the idea the user logs in, settings and apps get installed. Rather than IT doing lots of hand holding, per user registry settings etc.
Posted (edited)

We just got licensed for InTune (mainly for iPads now we've outgrown Meraki's free plan) and so far I'm quite impressed with the iOS side of it. Am now looking at deploying out to all our computers and changing our Windows 10 management over to what Microsoft call "modern management".

 

We're using SCCM at the moment but it's huge overkill for a primary - the only hurdle right now is application deployment. I don't want to install apps during imaging with MDT unless they're fully managed ala Applications in SCCM.

 

There's plenty of InTune documentation for shared devices if you look on the Microsoft website, it's geared at schools in particular. I think given time and planning it could complement my long term goal to minimise onsite servers :)

Edited by Blue_Cookeh

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...