Jump to content

Recommended Posts

Posted

Hi.

 

I'm currently doing things in an old fashioned way, but they seem reliable, and we often get compliments from PGCE students about how good our systems are compared to other schools in the area.

 

Windows Domain with DFS, GPO and network mapped drives.

WSUS and WDS on separate VMs. (Sat on a Vmware vsphere essentials 3 host cluster including mostly file storage. Backups to NAS using VEEAM).

Exchange on prem in hybrid mode for use with Exchange Online protection.

Smoothwall providing web filtering, HTTPS Inspection and firewall.

PDQ Deploy and Inventory (Deploy doing package/app deployment).

Perpetual Office 2016 on Windows 2019 Enterprise LTSC, maybe looking at Office 2019 next summer to align with our increasing Mac AD joined estate.

Papercut with some pull me printing in place.

ABtutor 8

Citrix XenApp 7 1808 for thin clients using Ncomp N500 and Chromebooks in kiosk mode.

 

Some services moved to cloud hosting:

planet estream

Library (Accessit)

Mosyle MDM for MacOS and iOS management using Munki for non VPP app deployment.

Google classroom with SSO using ADFS 3.0

 

Only a few minor compaints from a few staff about lack of storage space for files and emails.

 

Always get told I shouldn't be using LTSC for production but every time I look at edu, it doesn't seem to offer anything over and above what LTSC offers apart from one or two tiny features (sticky notes, Metro photo app that allows printing of photos onto A4).

 

Convince me to start using SCCM/Config manager. Seems like a sledgehammer to crack a nut in my honest opinion. Im already covered in most respects by PDQ, WDS and WSUS.

 

Any other suggestions welcome.

Posted

Very similar to my domain.

 

I'll need some convincing to change some of my stuff... Recently moved to office365 which was more of a pain than I expected.

 

I do feel my ltsc is bingg left behind... But not sure how.

Posted

Hi.

Thanks for replying. I'm assuming that with Office 365 your talking about the office suite only and not use of one drive/exchange online?

I'm guessing the issues you faced were around shared computer activation, and learning about the change in managing updates? Do you have static computer suites/labs as well?

Posted

I moved Exchange 365 a couple of years ago, I've only moved a handful of computers to Office 365 as our LSU wanted dictate and Dragon licensing is just stoopid.

 

I'm not using comp activation, I eventually found out that a group policy was stopping the activation for the users but I've sorted it now so they log straight in.

 

I did have Smoothwall till a couple of year ago but jumped to Sophos when I needed a new Smoothie box and the ££ was too much.

 

PDQ is awesome, my fave tool.

Posted
Can I ask what/how your backing up Exchange mailboxes? Veeam o365 V2 was a bit painful with some difficult power shell commands, but it's on v5 now so might take another look.
Posted

I think the question has to be, what problems are you looking to solve by moving to Configuration Manager?

 

I’ll say right now, ConfigMgr is one of my favourite tools but you’re right, it’s a beast and it sounds like you’ve got things going fairly well as it is. Unless you’ve got a specific thing that you need to address or there is a gap that you’re looking to plug, moving over to ConfigMgr sounds like it would be a lot of work for not very much gain.

Posted

There are a few things:

Rolling out latest drivers as part of a step by step process rather than having drivers in an image go out of date and having to recapture an entire image just to update drivers.

 

Just had our MS Licensing model reviewed and I'm trying to get the number of VMs down.

By integrating 2 VMs together (WSUS and WDS) and introducing MCEM I was possibly looking at going down the Win10 Edu route rather than LTSC so wanted better overall visibility of machines being on a specific version.

 

Apparently MCEM can also do reporting on client application usage, something that would be a great benefit going forward. Is this possible/feasible?

 

Also seems a way to keep an eye on InTune managed devices as well as on-prem. Something I learned in a Microsoft training demo this week.

 

PDQ Deploy/Inventory still and amazing product set IMO. Would be hard pushed to go to something else even if you can do this on MCEM.

 

Thoughts feedback on please?

Posted

Intune co-management with ConfigMgr is a thing, but I see it more as a path to migrate away from ConfigMgr to Intune, rather than a selling feature for ConfigMgr.

 

ConfigMgr doesn’t replace WSUS and WDS, instead it uses both technologies for its respective parts. That said, it extends both quite considerably; using OSD in ConfigMgr lets you run thin deployments, i.e. deploying a bare OS them installing software and drivers as part of a task sequence. Software updates in ConfigMgr uses WSUS to acquire updates and to detect whether an update is needed, but ConfigMgr uses its own mechanisms to distribute and install them and is considerably better at reporting.

 

Don’t go into this thinking that you’ll just be able to replace a couple of VMs with one; depending on the size of your organisation, you could easily end up with a lot more. At the moment, I have it running on about 12 VMs spread across multiple sites, looking after different parts of the product. It wants a lot of RAM and storage space for its databases, plus space for its library, multiple copies of things it’s actually distributing to computers and more. It’s a big, complex, hungry product and not something to be installed on a whim

Posted

You really don't need 12 VMs for SCCM, unless you're trying to make it complex or have 12 schools :p I've only ever run it on 1 VM and it can easily support 2k+ users/devices.

 

In terms of your original question though, as others have said, I'd query more along the what are you missing. Whether it's inTune/SCCM/MDT/other, they each have their benefits/downsides, it's more weighing up what you're trying to do and what's most efficient for your own site. If you're heavy on mobile devices etc you can link these all into SCCM/Co-Management etc, something you couldn't do with MDT natively.

 

It's a big change moving to SCCM with a large setup at the start, but once it's setup you're unlikely to want to move backwards :p

 

Steve

Posted

We are an SCCM site. However we are taking the drive into Intune/endpoint manager for our new staff laptops.

 

I've personally struggled with less control over the devices. But I'm warming to it, given the advantages.

 

Given the way remote education is going, I reckon I will move everything over to intune soon.

Posted

Right now and even in the next 5 years, I just can't see us moving to O365 fully with Intune. The only reason we have a domain right now is due to SIMS.Net, and I've been in impromptu meeting where a possible replacement is being discussed, most likely web based. This really does put the onus on what devices could be used on teachers desks.

 

Student devices will most likely be Chromebooks, as we are using Google classroom, plus a load of other web based learning platforms such as Kerboodle, mathswatch, GCSEPod, etc.

The use of windows computers will seriously decline to specialist STEM subjects like Computing DT etc. A level students may also be in a position where they will be using their own devices as the variety of the work and small class sizes, will not require full-size computer suites.

 

Even science only use basic apps, such as excel, which could be replaced with similar tools. The science block currently have Chromebooks setup as Citrix thin clients.

 

I'm not currently utilising MDT, just plain old WDS. GPO for settings and PDQ for app deployment and inventory. Hands down it just works simply, and with PDQ D and I at £700 a year for the Enterprise license for package library, it's a real time saver.

 

I guess I'm possibly trying to fix something that's not broken....

Posted

@_techie_ sounds to me like you have have things setup the way that works for your site and (as much as I love SCCM, and I do!) chucking sccm into the mix would be a fair amount of work and, perhaps, marginal benefit.

 

Also, the direction of travel for MS is to push Intune as their tool of choice so, for my money, if you want to look at anything, that would probably be a better long term bet.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...