Jump to content

Recommended Posts

Posted

Hi.

Looking at the future of Win10 in our environment, looks like it will be with us a while.

I've gone down the on-prem LTSC 2019 route here as we don't buy bulk Windows laptops at all really, and the odd ones we have are kept on site for projector trolleys. All data is held on site, apart from users starting to use Google Classroom more since COVID-19.

 

For remote working, we just provide Chromebooks to staff for remote working with our Citrix system in Kiosk mode with no local data stored between sessions.

We also haven't purchased any new PCs in bulk, since 2016 (Intel NUCs) and they are all shared devices in classroom labs with mandatory profiles, onsite WSUS and GPO managing everything. Right now we have a stable and working system.

 

Has anyone moved over to Intune to manage school devices, (which seems to renaming to endpoint admin).

 

I have been researching Autopilot, and Intune for education. Intune seems to lack some of of the fine tune control that we have with GPO ATM.

 

I had to build a Windows laptop yesterday and it took up most of my morning due to a specific application that the Chromebook wouldn't work with (Adobe Connect).

Just feeling that this process could be streamlined by Azure Hybrid Domain join and Intune. It's only a basic setup really: office 2016 with Mak key, bitlocker enabled OS Drive, Citrix workspace app and a local user account.

 

Comments/thoughts!

Posted

Yes the future is intune, but its not really ready yet in my opinion.

 

That doesn't mean it cant be used though, just that it is still very early in the product lifecycle.

Posted
We are using it with devices that go off site, so random laptops, tablets and mobile phones. Not sure I am ready to dive in fully and have it run the whole estate. As Supportman says, it is good, but not all there plus it uses a different philosophy so you have to change mindset.
Posted

I guess I'm not so trusting of so many "cloud providers" as some of you and I also like to keep as much possible on prem and stick with the tried and tested methods.

 

My setup is similar to an extent, but rather than rolling out inTune, I've stuck with what I know to be reliable and can support properly. That being on site GPO, getting that to work offsite isn't too difficult, there's DirectAccess and Always On VPN.

 

(In simple terms) User takes their surface home, fires it up, connects to Wi-Fi at the login screen, types their domain credentials in, everything logs in like you're on the network. GPOs still work, remote support, internal resources all work just fine.

 

Yes there's some extra setup to do, remote access server, ISATAP for IT staff computers, some extra GPOs to apply and things to consider like captive portals and caching of profiles for when network connectivity isn't possible.

 

But it works for us, I'm happy with it, teachers are happy, GPOs all work (even when new ones are applied).. Why would I change that?

Posted
Why would I change that?

 

If it works for you then fantastic.

 

My thought process is for business continuity/disaster recovery and for simplicity. If the site burns down or we have a power failure, using inTune I can send key staff to work from home or another location and they have access to everything and notice nothing different. Also when staff go to conferences there are often weird and wonderful Wifi and network setups so without having to add technologies in-between I can better guarantee a smooth experience.

It also streamlines support. With AutoPilot I can turn a laptop on and it gets our details and settings. Potentially I could ship a new laptop direct from the manufacturer to a member of staff, they click a few buttons and they are up and running. Laptop is playing up? Set it to factory reset from the console and it will revert, setup and be ready for them, no need to even come to you.

 

If MS and the manufacturers could just get image deployment like Apple have, I would be a very happy bunny.

 

It would be the same as reasons for moving to O365 and other online services. We have been slowly moving over and when all this looked like kicking off at the beginning of the year staff came to us to ask how we would proceed and the only thing we had to show them was how to use Teams effectively and how to access their phones from offsite. Staff were used to OneDrive, shared documents in SharePoint, OWA for email and key people were used to collaborating on documents so led the others with them. I would stick my neck out and say that at one point when the school was in lockdown, we were more efficient than when we were al in school.

 

I guess for me it is seeing how I can improve our provision for staff and make things easier, rather than getting to a point where I look at our IT estate and say "I am done, this is it".

Posted (edited)

I'm playing with Intune at the moment in a lab, is is a bit different but in there it has the same basic layout of Group Policies i.e. administrative templates for Users/Computers (although I cannot get them to work as of yet, lol). I've got a Windows 10 VM that I have connected to Azure AD and a Business Premium Microsoft 365 package with one Intune license.

 

I've been using GPOs for quite a while, near 15 years (although current role I have no access to them) so a bit of a change but my view is I may as well try learn it a bit.

Edited by Davit2005
Posted
If it works for you then fantastic.

 

My thought process is for business continuity/disaster recovery and for simplicity. If the site burns down or we have a power failure, using inTune I can send key staff to work from home or another location and they have access to everything and notice nothing different. Also when staff go to conferences there are often weird and wonderful Wifi and network setups so without having to add technologies in-between I can better guarantee a smooth experience.

It also streamlines support. With AutoPilot I can turn a laptop on and it gets our details and settings. Potentially I could ship a new laptop direct from the manufacturer to a member of staff, they click a few buttons and they are up and running. Laptop is playing up? Set it to factory reset from the console and it will revert, setup and be ready for them, no need to even come to you.

 

If MS and the manufacturers could just get image deployment like Apple have, I would be a very happy bunny.

 

It would be the same as reasons for moving to O365 and other online services. We have been slowly moving over and when all this looked like kicking off at the beginning of the year staff came to us to ask how we would proceed and the only thing we had to show them was how to use Teams effectively and how to access their phones from offsite. Staff were used to OneDrive, shared documents in SharePoint, OWA for email and key people were used to collaborating on documents so led the others with them. I would stick my neck out and say that at one point when the school was in lockdown, we were more efficient than when we were al in school.

 

I guess for me it is seeing how I can improve our provision for staff and make things easier, rather than getting to a point where I look at our IT estate and say "I am done, this is it".

Pretty sure I saw in the notes for 2004 (released last week) that it now has online image deployment built in.
  • Thanks 1
Posted
Pretty sure I saw in the notes for 2004 (released last week) that it now has online image deployment built in.

 

Thanks, I'll take a look. I thought it needed a deeper UEFI change to be able to get an image from before the OS started, but if they have solved it I will be a happy chappy.

Posted

I'm moving stuff over to 'pure' intune/ azure AD with no on premise domain.

 

Just bought a new laptop for a teacher the other day, logged in with azure ad creds, changed the name to match our convention, added it to a group and boom, all our software is on it. All done from my living room

 

But setting up sophisticated stuff is challenging. If you're old enough to remember pre GPO it feels a bit like that, though using powershell rather than batch files!

 

and when it goes wrong it's a complete nightmare.

Posted
Pretty sure I saw in the notes for 2004 (released last week) that it now has online image deployment built in.

I thought it needed a deeper UEFI change to be able to get an image from before the OS started, but if they have solved it I will be a happy chappy.

The cloud reset feature isn't as good as Apple's Internet Recovery since you need to do the restore from within the OS or from the recovery menu (which means you still need a copy of Windows installed first). Pretty disappointing to be honest.

 

Windows 10 Gets a Cloud Reset Feature, Here’s How it Works

 

Reinstall-Windows-page(1).jpg

 

reset-this-pc-recovery.jpg

  • Thanks 1
  • 2 months later...
Posted

One of the small primary schools I work with has decided to move from Server 2012/Windows 8.1 (which has worked very well for the last 6 years) to 365, Sharepoint, Azure, Intune for Education etc. This is due to needing to replace or rebuild the server and to move to Windows 10 as I'm retiring soon and they'll have an OS that more people will be familiar with etc. One of the school Governors works in IT support so knows 365, Sharepoint and Teams fairly well whereas I would be the first to admit I don't know it well at all, having come from a server/client environment. I had imagined it would be a fairly straightforward with our combined knowledge but so far, that's not been the case.

 

The desktops all have Windows 10 Pro Education installed and work well as standalone machines. They're joined to an Azure domain and I'm finding management via Azure and Intune a real pain. In the old environment there was a local admin account on each domain joined PC so it was possible to have full control of the machine and to quickly test GPO changes you'd made. In this new environment, even with a local admin account, the PC keeps the settings from what's been defined in Intune. So, you lock down Settings for example, only to find when you're logged on as local admin that you can't access Settings. Instead you have to disable blocking settings in Intune and then wait an indeterminate amount of time for this to permeate through. OneDrive only appears when you're running Office so you have the problem of where to store data from other apps. If you lock down local storage then the non Microsoft apps can't see any storage location, if you leave it unblocked the the pupils can see the C Drive. If you hide the C drive in local machine GPO then you get a srcipt error message when logging on. Some things just don't seem to work like assigning Browser home page etc. There are also a lot less settings compared with the server GPO templates.

 

Sure, you can manage it virtually anywhere and hopefully it will get better but it seems to me that this is not a mature product set and doesn't compare with the rich function in a traditional client/server environment. As I said earlier I'm in no way an expert in this new environment and if anyone has more experience and/or advice that would be appreciated....

Posted

Not sure what you mean by OneDrive only working in Office? We have it installed and within seconds it logs in and is available without any issues and access through the usual Explorer.

 

Hiding C: is possible via the registry and causes us no issues at login.

Posted (edited)
Do you have the OneDrive app installed on the machine - we only have it via the web at the moment as it seemed simpler. Does the user have to log into OneDrive just the once or everytime they logon the machine and are they signing in across multiple machines which is what we'd be doing. It seems each machine holds user profiles as the first time a user logs onto a different machine it has to prepare the environment. I had considered the registry option so will give it a try if it works for your. Hiding it in GPO causes an Intune script to throw up an error message. Any other advice/tips would be appreciated. I've had a much shorter time than I would have liked to get all this tested and working properly before term starts for a number of reasons outside of my control..! Edited by peakrock
missed some text off
Posted

We have OneDrive installed on the machine with the /alluser switch.

They don’t login manually ever, it all signs them in automatically. Just like the Store and Office will sign them in without user intervention.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...