mdrabble Posted January 14, 2021 Posted January 14, 2021 Looks like I may be getting my wish and getting laptops for staff or use with everyday teaching and possibly for home/remote teaching/usage etc. We currently use SCCM to manage desktops in school and have just recently starting using Intune to manage student laptops offsite. Since staff laptops will be used in school and at home - it has got me thinking how best to manage these devices in terms of software deployments and updates. DoI open up SCCM to the internet and manage devices that way? Do I go solely with Intune and AzureAD joined only and deploy apps based on user/device groups? Or do I go SCCM/Intune Co-Managed with Hybrid AD and AzureAD Joined? User Documents will all be sync'd to Office 365 and will slowly be moving Shared Docs to SharePoint - so mapped drives shouldnt be needed. Would be interested in hearing peoples thoughts - especially if you have already done this and can point out any "Gotcha" scenarios. Cheers Mark
5tu Posted January 18, 2021 Posted January 18, 2021 We are currently using option 3, co-management. Allows you to selectively choose which workloads to move from sccm to intune for all or some devices. Works really well. Also using functionality to sync sccm collections to azure AD groups which is super handy. 1
Max_Power Posted January 18, 2021 Posted January 18, 2021 Using Intune here to manage over 1500+ devices all being used by staff and students offsite and onsite. Works really well from a management point of view - Auto Pilot deployment was impressive as well as the Company Portal for software rollout to specific groups of students and staff. Kept it all separate from SCCM and all onsite desktops / laptops with a view to perhaps decommissioning in future. 1
mdrabble Posted January 18, 2021 Author Posted January 18, 2021 Using Intune here to manage over 1500+ devices all being used by staff and students offsite and onsite. Works really well from a management point of view - Auto Pilot deployment was impressive as well as the Company Portal for software rollout to specific groups of students and staff. Kept it all separate from SCCM and all onsite desktops / laptops with a view to perhaps decommissioning in future. Need to look at the portal - any pointer on best practices etc?
free780 Posted January 18, 2021 Posted January 18, 2021 Really depends on Win32 Apps that require connection back to site. If you nee this then you need a VPN or Remote Desktop Gateway. Intune really gives you control when a VPN connection fails (for whatever reason). I'd probably go with co-managed ideally. 1
psydii Posted January 18, 2021 Posted January 18, 2021 Fastest thing to do is open the MEMCM (nee SCCM) DP to the internet. Advisable to make sure you've fully updated and have implemented best practice for the various accounts SCCM uses (hint: if any of them are domain admin, you have some work to do) Longer term, link them up with MEM (nee InTune). Longer term still, retire MEMCM. Also using functionality to sync sccm collections to azure AD groups which is super handy.[/quote @gybe78 I did not know about this - super handy tip! Still grumpy that MEM/MEMCM/AzureAD still can't control settings as flexibly as AD/GPOs: Computers are either shared devices, or 1:1 devices, and behave as such regardless of who is logging on. AD/GPO OU/user/group/computer and loopback filtering allowed us to do some much more with our available assets. 1
_techie_ Posted January 28, 2021 Posted January 28, 2021 Interesting reading this thread, as I'm contemplating how shared computer suites would work on InTune! InTune from my point of view is really made for 1:1 rollouts. GPO and shared computer suites go hand in hand at the moment, especially if they are desktops! Be interested to hear people's thoughts on this
psydii Posted January 29, 2021 Posted January 29, 2021 The Shared Device profile in Microsoft Endpoint Manager (formerly InTune) is pretty good. It makes them work quite a lot like a ChromeBook, but with the ability to run win32apps. With a bit of jiggery-pokery you can get them integrated with legacy services over smb (GPO, File and Print Shares)... however DO NO DO THIS*. Just accept them for what they are, and build out alternatives - that you will likely have already pivoted to to provide services during the pandemic. While we haven't finished getting it right just yet, PaperCut seems to be the key 3rd party product one needs. *You may need domain joined with a GPO for 802.1x device based authentication. Some WiFi systems have a suitable alternative deployment, but typical out of the box solutions from the big vendors do not (Aruba, Cisco etc). If you go down this route keep the GPO to the bare set minimum, and where ever possible deploy settings via MEM.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now