Jump to content

Recommended Posts

Posted

Looks like I may be getting my wish and getting laptops for staff or use with everyday teaching and possibly for home/remote teaching/usage etc.

 

We currently use SCCM to manage desktops in school and have just recently starting using Intune to manage student laptops offsite.

 

Since staff laptops will be used in school and at home - it has got me thinking how best to manage these devices in terms of software deployments and updates.

 

  • DoI open up SCCM to the internet and manage devices that way?
  • Do I go solely with Intune and AzureAD joined only and deploy apps based on user/device groups?
  • Or do I go SCCM/Intune Co-Managed with Hybrid AD and AzureAD Joined?

 

User Documents will all be sync'd to Office 365 and will slowly be moving Shared Docs to SharePoint - so mapped drives shouldnt be needed.

 

Would be interested in hearing peoples thoughts - especially if you have already done this and can point out any "Gotcha" scenarios.

 

Cheers

Mark

Posted
We are currently using option 3, co-management. Allows you to selectively choose which workloads to move from sccm to intune for all or some devices. Works really well. Also using functionality to sync sccm collections to azure AD groups which is super handy.
  • Thanks 1
Posted

Using Intune here to manage over 1500+ devices all being used by staff and students offsite and onsite.

Works really well from a management point of view - Auto Pilot deployment was impressive as well as the Company Portal for software rollout to specific groups of students and staff.

Kept it all separate from SCCM and all onsite desktops / laptops with a view to perhaps decommissioning in future.

  • Thanks 1
Posted
Using Intune here to manage over 1500+ devices all being used by staff and students offsite and onsite.

Works really well from a management point of view - Auto Pilot deployment was impressive as well as the Company Portal for software rollout to specific groups of students and staff.

Kept it all separate from SCCM and all onsite desktops / laptops with a view to perhaps decommissioning in future.

 

Need to look at the portal - any pointer on best practices etc?

Posted

Really depends on Win32 Apps that require connection back to site. If you nee this then you need a VPN or Remote Desktop Gateway.

Intune really gives you control when a VPN connection fails (for whatever reason).

I'd probably go with co-managed ideally.

  • Thanks 1
Posted

Fastest thing to do is open the MEMCM (nee SCCM) DP to the internet. Advisable to make sure you've fully updated and have implemented best practice for the various accounts SCCM uses (hint: if any of them are domain admin, you have some work to do)

 

Longer term, link them up with MEM (nee InTune). Longer term still, retire MEMCM.

 

Also using functionality to sync sccm collections to azure AD groups which is super handy.[/quote @gybe78 I did not know about this - super handy tip!

 

Still grumpy that MEM/MEMCM/AzureAD still can't control settings as flexibly as AD/GPOs: Computers are either shared devices, or 1:1 devices, and behave as such regardless of who is logging on. AD/GPO OU/user/group/computer and loopback filtering allowed us to do some much more with our available assets.

  • Thanks 1
  • 2 weeks later...
Posted
Interesting reading this thread, as I'm contemplating how shared computer suites would work on InTune! InTune from my point of view is really made for 1:1 rollouts. GPO and shared computer suites go hand in hand at the moment, especially if they are desktops! Be interested to hear people's thoughts on this
Posted

The Shared Device profile in Microsoft Endpoint Manager (formerly InTune) is pretty good. It makes them work quite a lot like a ChromeBook, but with the ability to run win32apps.

 

With a bit of jiggery-pokery you can get them integrated with legacy services over smb (GPO, File and Print Shares)... however DO NO DO THIS*. Just accept them for what they are, and build out alternatives - that you will likely have already pivoted to to provide services during the pandemic. While we haven't finished getting it right just yet, PaperCut seems to be the key 3rd party product one needs.

 

*You may need domain joined with a GPO for 802.1x device based authentication. Some WiFi systems have a suitable alternative deployment, but typical out of the box solutions from the big vendors do not (Aruba, Cisco etc). If you go down this route keep the GPO to the bare set minimum, and where ever possible deploy settings via MEM.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...