Jump to content

Recommended Posts

Posted

Hi Edu colleagues;)

 

We are managing about 400 windows 10 laptops (which are in a Hybrid Azure AD Joined) with Intune, and users can install company software via Company Portal which works fine.

Users are logged on the device with the their domain credentials and are normal users on the device, so they cannot install applications for example.

 

But we are getting more and more questions about this. users want to install other applications which they used for lessons, and not always we can add it to the company portal.

Also users want to connect their wacom(or other brands) tablets and other peripherals, which they can't install in this situation.

 

My question is how are you dealing with this?

I heard they make users local admin on they device, but is that recommended? I can't oversee they drawbacks.

 

Any help or tips wold be welcome

Posted

This is a conversation I'm sure that everyone on these forums has had at one point or another.

 

First of all, I would say that you need to speak to someone in the management team of your school and explain to them what the situation is, what the problems are, what's caused them and what the various solutions to the problems are and what the advantages and drawbacks to those solutions are. You need to get support from them and you need to be able to point your staff at policies and directives from your management team when they complain about not being able to do whatever it is they want.

 

In regards to giving people local admin access, that should be an absolute last resort for when there is no other way to get a piece of software to work. Giving someone local admin access allows them to install whatever they want on a computer which means (going by my experience anyway) that the laptops end up with all manner of unlicensed or outright pirated crap on them, browser toolbars, spyware and god knows what else. You also end up getting the blame when the user inevitably breaks it.

 

It's been a while since I looked at deploying software from Intune but why can't you deploy the software that they're asking for from it? If I remember correctly, you can bundle both EXE and MSI installers and deploy them from Intune?

Posted

thanks. we as IT don't want local admins, but them main problem is installing peripherals like usb drawing boards. As they arent local admin they also can't install drivers.

 

Any iedeas on this?

Posted
Worst case scenario you can remote into their machine (on of off site) and install the drivers for them. I wouldn't even say giving them local admin access is a worst case scenario, it's just not an option, creates way too many risks. We use LAPS so each local admin credential on all devices is different, then use Windows Quick Assist to remote into their devices (when the device is off site), or get them to pop into the IT Support office when they're onsite and we install the software for them. Luckily all staff seem happy with this setup, no complaints, at least to us :)
Posted
Worst case scenario you can remote into their machine (on of off site) and install the drivers for them. I wouldn't even say giving them local admin access is a worst case scenario, it's just not an option, creates way too many risks

In my opinion,i don't support this,it will cause a lot of trouble.

Posted

I've not given users 'admin' since Windows 2000.

 

However increasingly Microsoft and Apple are changing the kernel, management and security tools that make local admin less than it used to be. If you are runing 1:1 devices primarily mananaged through and MDM, and most /all of your services are cloud based, and you have modern security tools deployed... it is time to reconsider and re-evalute the no local admin for users mantra. If its still a 'no', you should review things again in a year's time.

 

We have not pivoted yet, but I know there will come a time.

 

For now, like thimon we use LAPS and Quick Assist. Sometime we use our management platoform temporarily grant admin to the local user using one of the methods in this article: https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin

Posted
In my opinion,i don't support this,it will cause a lot of trouble.

What trouble exactly? We've been doing this with staff since working from home was put in place. No issues.

Posted
We've had an issue where WFH users don't have admin rights and our don't work as they are off the network and the local admin user doesn't work (a mistake i made in setup!), managed to push out a local admin user via Intune and then can remote on and use that!
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...