Jump to content

Recommended Posts

Posted
Yeah, that's a quite nice part of intune an about the only thing that that doesn't make me think MS hate us lot. Click a couple of buttons and you've got an up to date office on your machines.

 

That said, I still use MDT as none of the machines have drivers built into windows so a pure autopilot doesn't work, so at one stage I remove it from intune and added it as the first part of a 2 stage image and figured I may as well save the time of a 300MB office download every time. On reflection that was possibly a mistake as credit due, intune does pull down and install the apps pretty quickly.

 

Autopilot is more for new devices, which would have the drivers on the shipped image.

Posted
Yeah, that's a quite nice part of intune an about the only thing that that doesn't make me think MS hate us lot. Click a couple of buttons and you've got an up to date office on your machines.

 

 

They don't hate you if they can get you to pay monthly per computer for something that used to be built in to deploy something they also own and charge for.

Posted
The new device based activation should work as long as you can get the registry entries applied. I don't think MS hate us. They are primarily interested in 1:1 and increasing the year on yest cost for licensing.
Posted
The new device based activation should work as long as you can get the registry entries applied. I don't think MS hate us. They are primarily interested in 1:1 and increasing the year on yest cost for licensing.

 

 

I must have missed some device based change then - any pointers please share.

 

my comment about MS hating us wasn't directed at them wanting to make a few bucks - aren't we all? I own an small IT co, so would certainly be doing the same as them if I could.

 

It just that system admins seem to be an afterthought with this sexy new tech when you start to trouble shoot it, and the amount of legwork needed to achieve basic config is extraordinary. For example, just making something persistent so it'll reapply when a user makes a change is an exercise in hackery. The policy approach to applying arbitrary registry keys is terrifying.

Posted

https://docs.microsoft.com/en-us/deployoffice/device-based-licensing

 

I get the impression microsoft think the users will join the device to the wifi (802.1x so 1:1) and then log in with their UPN rather than SamAccountName and magically Office will download and install. Bitlocker will encrypt and all will be well. I noticed simple things likes a different home page in edge for different user groups wasn't reliable. Policy seems to only get refrshed every hour not when a user logs in.

Posted (edited)

Manage Windows 10 devices through the G Suite Admin console - https://gsuiteupdates.googleblog.com/2020/01/windows-10-gsuite-admin-single-sign-on-sso.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+GoogleAppsUpdates+%28G+Suite+Updates+Blog%29

 

With these new controls G Suite admins can:

Enable their organization to use existing G Suite account credentials to login to Windows 10 devices, and easily access apps and services with SSO

Protect user accounts with anti-phishing, anti-hijacking, and suspicious login detection technologies

Ensure that all Windows 10 devices used to access G Suite are updated, secure, and within compliance

Perform admin actions, such as wiping a device and pushing device configuration updates, to Windows 10 devices from the cloud without specific network requirements

Edited by TwistedHelixis
  • Thanks 2
Posted
Manage Windows 10 devices through the G Suite Admin console - https://gsuiteupdates.googleblog.com/2020/01/windows-10-gsuite-admin-single-sign-on-sso.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+GoogleAppsUpdates+%28G+Suite+Updates+Blog%29

 

With these new controls G Suite admins can:

Enable their organization to use existing G Suite account credentials to login to Windows 10 devices, and easily access apps and services with SSO

Protect user accounts with anti-phishing, anti-hijacking, and suspicious login detection technologies

Ensure that all Windows 10 devices used to access G Suite are updated, secure, and within compliance

Perform admin actions, such as wiping a device and pushing device configuration updates, to Windows 10 devices from the cloud without specific network requirements

 

Paid version only though

Posted
https://docs.microsoft.com/en-us/deployoffice/device-based-licensing

 

I get the impression microsoft think the users will join the device to the wifi (802.1x so 1:1) and then log in with their UPN rather than SamAccountName and magically Office will download and install. Bitlocker will encrypt and all will be well. I noticed simple things likes a different home page in edge for different user groups wasn't reliable. Policy seems to only get refrshed every hour not when a user logs in.

 

Ta.. But I realised I have been there already, checked it out and discounted it (old age must be kicking ine). We are are small school thus don't qualify for EES, instead have OVS-ES. Gotta love licensing.

Posted

Not sure why you need DBA.

 

Regardless of licensing agreement the users should be able to have a ProPlus license. Then Office just auto activated when they are logged in via their AAD account.

 

This is how we use it. We are 1:1 pretty much but still works if we roam between devices.

 

The policy sync is rubbish but not too bad if you can specify devices to be for certain year groups etc where the policy is the same regardless who logs on. It’s only when you want different settings where you need to wait.

Posted
Not sure why you need DBA.

 

Regardless of licensing agreement the users should be able to have a ProPlus license. Then Office just auto activated when they are logged in via their AAD account.

 

This is how we use it. We are 1:1 pretty much but still works if we roam between devices.

 

The policy sync is rubbish but not too bad if you can specify devices to be for certain year groups etc where the policy is the same regardless who logs on. It’s only when you want different settings where you need to wait.

Cos you only get five activations per user.
Posted
Use Shared Computer Activation then. It’s even a tick box in Intune when you deploy Office.

 

 

It's a primary school, circa 100 pupils and 30 laptops, they don't want per pupil accounts. So a single generic account and Shared Computer Activation is no use

Posted
So a single generic account and Shared Computer Activation is no use

 

How does that work for prevent? If you share an account the web logs can be traced back to a single user.

Posted
How does that work for prevent? If you share an account the web logs can be traced back to a single user.

0

We are looking at primary pupils with limited, supervised access. How does a six year old remember and type in a complex password (I don't mean that to be snarky, genuine question as to how other do, and also a plea for explicit details and regulations calling out this requirement?)

Posted
I generally don’t enforce passwords for KS1 until the teachers ask for them, but do have individual accounts for them. School size is irrelevant. I have supported schools where the teacher has a card for each child with their user name and password for KS1 which they dish out at the beginning of lessons. All the KS2 pupils in all the primaries I support cope with passwords. I insist on memorable rather than strong passwords as they can’t get a reset when I’m not there. If they can’t think of a password, I offer https://www.dinopass.com/ and they usually settle on something quite quickly.
Posted
The guidance is the Keeping Children Safe in Education stuff, and the requirement for "appropriate filtering and monitoring". If you don't have individual users, I'd say the issue is - how do you attribute actions back to the users that did it? So, a child goes to a extremist website, your filter and monitoring software logs it, but you don't find out about it until after. You've got nothing to go on to find out who did it.
  • Thanks 2
Posted

I mean - even setting up users for each pupil with a blank password is very preferable compared to everyone in the school sharing one account.

 

I personally think pupils should be taught about passwords in the early years - it is a skill they are going to need for the rest of their life!

  • Thanks 3
Posted
I mean - even setting up users for each pupil with a blank password is very preferable compared to everyone in the school sharing one account.

 

I personally think pupils should be taught about passwords in the early years - it is a skill they are going to need for the rest of their life!

 

I fully agree with @AButters. I have found that it is important to train the teachers as much as the pupils about using individual accounts, and at some point someone is going to have to bite the bullet and teach passwords. Is it not better to do this in the low key stages where we are teaching all the other building blocks and where failure is less critical.

 

When I worked in a prep school we used the same username for the whole school career initial, surname, year of entry which was printed in each pupil's diary or on a card for EYFS. The password policy changed by key stage, EYFS on simple pass word for the whole group usually the group name ie PP1S, KS1 an eight letter simple password in the pupil diary such as bigboots, KS2 similar password but not written down and KS3 a Dinopass password such as jollynose49. at each stage the teachers knew the passwords and the pupils could not change them.

 

This did cause problems especially with a family with a greek surname so we had to shorten it from Papadopoulos to Papa after a great deal of negotiation with the parents and with teachers mainly unhappy with the system changing from one account for the whole student body resolved in some way by keeping password lists in the class rooms and finally by the Head telling them to sit down.

Posted
Local primary teaches the younger grades password, I think I was supporting a grade 2 or 3 class (around 8/9 yr old maybe) teaching them how to login, they all had business card sized cards with their username and simple password (cat, dog etc from memory), and teaching them how to do Ctrl Alt Del (Bunny Ears iirc)
Posted
Do people still enforcing needing to press ctrl-alt-del to login?

 

This would have been Win Seven from memory, on a state wide system where local admins didn't get a choice.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...