snagrat Posted January 18, 2020 Posted January 18, 2020 Yeah, that's a quite nice part of intune an about the only thing that that doesn't make me think MS hate us lot. Click a couple of buttons and you've got an up to date office on your machines. That said, I still use MDT as none of the machines have drivers built into windows so a pure autopilot doesn't work, so at one stage I remove it from intune and added it as the first part of a 2 stage image and figured I may as well save the time of a 300MB office download every time. On reflection that was possibly a mistake as credit due, intune does pull down and install the apps pretty quickly. Autopilot is more for new devices, which would have the drivers on the shipped image.
mavhc Posted January 18, 2020 Posted January 18, 2020 Yeah, that's a quite nice part of intune an about the only thing that that doesn't make me think MS hate us lot. Click a couple of buttons and you've got an up to date office on your machines. They don't hate you if they can get you to pay monthly per computer for something that used to be built in to deploy something they also own and charge for.
free780 Posted January 19, 2020 Posted January 19, 2020 The new device based activation should work as long as you can get the registry entries applied. I don't think MS hate us. They are primarily interested in 1:1 and increasing the year on yest cost for licensing.
chaplic Posted January 19, 2020 Posted January 19, 2020 The new device based activation should work as long as you can get the registry entries applied. I don't think MS hate us. They are primarily interested in 1:1 and increasing the year on yest cost for licensing. I must have missed some device based change then - any pointers please share. my comment about MS hating us wasn't directed at them wanting to make a few bucks - aren't we all? I own an small IT co, so would certainly be doing the same as them if I could. It just that system admins seem to be an afterthought with this sexy new tech when you start to trouble shoot it, and the amount of legwork needed to achieve basic config is extraordinary. For example, just making something persistent so it'll reapply when a user makes a change is an exercise in hackery. The policy approach to applying arbitrary registry keys is terrifying.
free780 Posted January 20, 2020 Posted January 20, 2020 https://docs.microsoft.com/en-us/deployoffice/device-based-licensing I get the impression microsoft think the users will join the device to the wifi (802.1x so 1:1) and then log in with their UPN rather than SamAccountName and magically Office will download and install. Bitlocker will encrypt and all will be well. I noticed simple things likes a different home page in edge for different user groups wasn't reliable. Policy seems to only get refrshed every hour not when a user logs in.
TwistedHelixis Posted January 20, 2020 Posted January 20, 2020 (edited) Manage Windows 10 devices through the G Suite Admin console - https://gsuiteupdates.googleblog.com/2020/01/windows-10-gsuite-admin-single-sign-on-sso.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+GoogleAppsUpdates+%28G+Suite+Updates+Blog%29 With these new controls G Suite admins can: Enable their organization to use existing G Suite account credentials to login to Windows 10 devices, and easily access apps and services with SSO Protect user accounts with anti-phishing, anti-hijacking, and suspicious login detection technologies Ensure that all Windows 10 devices used to access G Suite are updated, secure, and within compliance Perform admin actions, such as wiping a device and pushing device configuration updates, to Windows 10 devices from the cloud without specific network requirements Edited January 20, 2020 by TwistedHelixis 2
mavhc Posted January 20, 2020 Posted January 20, 2020 Manage Windows 10 devices through the G Suite Admin console - https://gsuiteupdates.googleblog.com/2020/01/windows-10-gsuite-admin-single-sign-on-sso.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+GoogleAppsUpdates+%28G+Suite+Updates+Blog%29 With these new controls G Suite admins can: Enable their organization to use existing G Suite account credentials to login to Windows 10 devices, and easily access apps and services with SSO Protect user accounts with anti-phishing, anti-hijacking, and suspicious login detection technologies Ensure that all Windows 10 devices used to access G Suite are updated, secure, and within compliance Perform admin actions, such as wiping a device and pushing device configuration updates, to Windows 10 devices from the cloud without specific network requirements Paid version only though
chaplic Posted January 20, 2020 Posted January 20, 2020 https://docs.microsoft.com/en-us/deployoffice/device-based-licensing I get the impression microsoft think the users will join the device to the wifi (802.1x so 1:1) and then log in with their UPN rather than SamAccountName and magically Office will download and install. Bitlocker will encrypt and all will be well. I noticed simple things likes a different home page in edge for different user groups wasn't reliable. Policy seems to only get refrshed every hour not when a user logs in. Ta.. But I realised I have been there already, checked it out and discounted it (old age must be kicking ine). We are are small school thus don't qualify for EES, instead have OVS-ES. Gotta love licensing.
snagrat Posted January 20, 2020 Posted January 20, 2020 Not sure why you need DBA. Regardless of licensing agreement the users should be able to have a ProPlus license. Then Office just auto activated when they are logged in via their AAD account. This is how we use it. We are 1:1 pretty much but still works if we roam between devices. The policy sync is rubbish but not too bad if you can specify devices to be for certain year groups etc where the policy is the same regardless who logs on. It’s only when you want different settings where you need to wait.
jmak Posted January 20, 2020 Posted January 20, 2020 Not sure why you need DBA. Regardless of licensing agreement the users should be able to have a ProPlus license. Then Office just auto activated when they are logged in via their AAD account. This is how we use it. We are 1:1 pretty much but still works if we roam between devices. The policy sync is rubbish but not too bad if you can specify devices to be for certain year groups etc where the policy is the same regardless who logs on. It’s only when you want different settings where you need to wait.Cos you only get five activations per user.
snagrat Posted January 20, 2020 Posted January 20, 2020 Cos you only get five activations per user. Use Shared Computer Activation then. It’s even a tick box in Intune when you deploy Office.
chaplic Posted January 21, 2020 Posted January 21, 2020 Use Shared Computer Activation then. It’s even a tick box in Intune when you deploy Office. It's a primary school, circa 100 pupils and 30 laptops, they don't want per pupil accounts. So a single generic account and Shared Computer Activation is no use
FN-GM Posted January 21, 2020 Posted January 21, 2020 So a single generic account and Shared Computer Activation is no use How does that work for prevent? If you share an account the web logs can be traced back to a single user.
free780 Posted January 21, 2020 Posted January 21, 2020 Not to mention shared storage space for work. Also safeguarding and accountability of students.
chaplic Posted January 21, 2020 Posted January 21, 2020 How does that work for prevent? If you share an account the web logs can be traced back to a single user. 0 We are looking at primary pupils with limited, supervised access. How does a six year old remember and type in a complex password (I don't mean that to be snarky, genuine question as to how other do, and also a plea for explicit details and regulations calling out this requirement?)
mavhc Posted January 21, 2020 Posted January 21, 2020 There's never any technical specifications for this kind of thing. Generally QR code badges, or teachers with a list of passwords.
sigma Posted January 21, 2020 Posted January 21, 2020 I generally don’t enforce passwords for KS1 until the teachers ask for them, but do have individual accounts for them. School size is irrelevant. I have supported schools where the teacher has a card for each child with their user name and password for KS1 which they dish out at the beginning of lessons. All the KS2 pupils in all the primaries I support cope with passwords. I insist on memorable rather than strong passwords as they can’t get a reset when I’m not there. If they can’t think of a password, I offer https://www.dinopass.com/ and they usually settle on something quite quickly.
localzuk Posted January 21, 2020 Posted January 21, 2020 The guidance is the Keeping Children Safe in Education stuff, and the requirement for "appropriate filtering and monitoring". If you don't have individual users, I'd say the issue is - how do you attribute actions back to the users that did it? So, a child goes to a extremist website, your filter and monitoring software logs it, but you don't find out about it until after. You've got nothing to go on to find out who did it. 2
PotNoodleTech Posted January 22, 2020 Posted January 22, 2020 I mean - even setting up users for each pupil with a blank password is very preferable compared to everyone in the school sharing one account. I personally think pupils should be taught about passwords in the early years - it is a skill they are going to need for the rest of their life! 3
mavhc Posted January 22, 2020 Posted January 22, 2020 You're not holding onto hope that passwords will be got rid of? We have security keys and phones and oauth and sqrl and fido now
msi_school Posted January 22, 2020 Posted January 22, 2020 I mean - even setting up users for each pupil with a blank password is very preferable compared to everyone in the school sharing one account. I personally think pupils should be taught about passwords in the early years - it is a skill they are going to need for the rest of their life! I fully agree with @AButters. I have found that it is important to train the teachers as much as the pupils about using individual accounts, and at some point someone is going to have to bite the bullet and teach passwords. Is it not better to do this in the low key stages where we are teaching all the other building blocks and where failure is less critical. When I worked in a prep school we used the same username for the whole school career initial, surname, year of entry which was printed in each pupil's diary or on a card for EYFS. The password policy changed by key stage, EYFS on simple pass word for the whole group usually the group name ie PP1S, KS1 an eight letter simple password in the pupil diary such as bigboots, KS2 similar password but not written down and KS3 a Dinopass password such as jollynose49. at each stage the teachers knew the passwords and the pupils could not change them. This did cause problems especially with a family with a greek surname so we had to shorten it from Papadopoulos to Papa after a great deal of negotiation with the parents and with teachers mainly unhappy with the system changing from one account for the whole student body resolved in some way by keeping password lists in the class rooms and finally by the Head telling them to sit down.
p858snake Posted January 22, 2020 Posted January 22, 2020 Local primary teaches the younger grades password, I think I was supporting a grade 2 or 3 class (around 8/9 yr old maybe) teaching them how to login, they all had business card sized cards with their username and simple password (cat, dog etc from memory), and teaching them how to do Ctrl Alt Del (Bunny Ears iirc)
mavhc Posted January 22, 2020 Posted January 22, 2020 Do people still enforcing needing to press ctrl-alt-del to login?
thimon Posted January 22, 2020 Posted January 22, 2020 Do people still enforcing needing to press ctrl-alt-del to login? Never have with Windows 10. Goes straight to logon screen from boot up.
p858snake Posted January 23, 2020 Posted January 23, 2020 Do people still enforcing needing to press ctrl-alt-del to login? This would have been Win Seven from memory, on a state wide system where local admins didn't get a choice.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now