Jump to content

Hybrid Joined Devices, Intune and Logging in remotely.


Recommended Posts

Posted

Hi Guys

 

Manage a small site with an on-prem AD which is AD connect synced to Microsoft 365 for password hash only, looking shift to Hybrid Joined, but there is many questions to be answered. I will put a few main ones here to get me started. I've read some posts on here and got some idea, however always best to ask questions before, rather then after :) Basically the school wants to hand out laptops to different students that come and go on short courses, they will then hand them back after they have done, and another student will take it then. They will take the laptops which they can log on locally in the school to the local AD and then use them at home for extended periods, where they just need OneDrive, Internet and Office.

 

1. The laptops that are going to be enrolled into AAD as well as AD will be used outside the school, but will have GPOs applied to them before leaving, so they will be locked down accordingly, do we still need to buy, install and setup Intune or can we rely on the GPOs?

 

2. If no users have logged onto the laptop at the school, I assume Autopilot needs to be setup to enabled the login to be authenticated outside of the school?

 

3. If the user logs on before taking the laptop, will this still need the VPN to login and is is still AD credentials the use, so the usual cached profile, they don't use the UPN or anything?

 

4. We are looking for SSO, so when they take the laptop home they log into the laptop,, but when they sign in their OneDrive is logged in and their Office is activated linked to the local AD account but because its Hybrid Joined, it doesn't ask for passwords and is seamless... am I understanding this correctly.

 

5. Do you recommended Office 365 Shared Activation over 2019 Pro Plus in this scenario?

 

6. Finally (For now LOL), I assume we will need to upgrade to Azure P1 for password writeback too in this scenario ? Can we check "Change password on next login" so when the student gets home, it detects this and they can put their own new password in (which follows the password policy) and it writes back ?

 

These should get me going to start with, I've read lots of you that have done similar or the same, but just want some clarification on these, it would really help out a lot. Looking forward to your responses and help.

 

Cheers Guys!

 

S

Posted

1. No, but you're hamstringing yourself massively this way, unless you have a VPN back to site to apply any changes.

 

2. Hybrid devices *must* have LOS to the DC for their first authentication & then you cache like before. You'd do this either by having the device inside school or using a VPN (Always on VPN is basically built for this). - Azure AD pure devices don't have this limitation & if you have AD connect setup right, any Azure AD pure machine will still be able to authenticate fine with internal resources (When on site and via VPN) - But then you are of course, relying on Intune to do all your policies/configuration as GPO won't apply (As it's not domain joined) This is how I have all our DFE laptops setup.

 

3. As above, Hybrid devices yes, Azure AD pure no.

 

4. Yes, tho you're thinking of SSSO (Seemless single sign on)

 

5. 100% yes - Forget about the "year" versions of office, no matter how tempted you may be to just install a flat target and call it a day. The 365 version is superior in every single way.

 

6. Yes, you need Azure P1 for password write back. Yes you can enforce password changes on students with this.

  • Thanks 1
Posted (edited)

Thanks for the feedback and guidance.

 

1. The laptops shouldn't be away from the school for long, so you say its possible to not have a VPN and Intune, but if we don't then the laptops will remain static in their config, until logged back in at the school without these both?

 

2. So am I right in thinking if we log them on before they take them they don't need LOS to the DC afterward. If we do need or want a VPN (to update GPOs etc while away) is Autopilot the way to go? Can we have a mixture of Hypbrid Laptops and AAD Joined laptops? (The latter obviously management will require Intune to try and match that of the GPOs, which I understand wont be as good?)

 

3. As above once cached they shouldn't need the VPN on Hybrid Joined to actually log into the laptop?

 

4. So is this exactly what would happen if we setup Hybrid Joined, will we get this SSSO experience when using the laptop in and outside the school, no password prompts ?

 

5. Thought so yes, I've read peoples struggles, but we use Shared Activation on RDS and seems to be ok, so going with this method.

 

6. With this, if not using a VPN of any kind and using Hybrid Joined laptops, can users still change there password and it will write back using the P1 License? What about if they forget their password while away from the school, is there any mechanisms for us to change it on the AD server in the school (selecting change on next login) and this is synced to AAD and on the laptop then changed using maybe SSPR on the Windows 10 logins screen somehow (I'm just reading on this so forgive my ignorance), because how will this behave with the AD cache profile credentials on the laptop, will it in turn change this too, and not be disjoined?

 

Really appreciate the input from you and anyone else, it really helps forge a path to where we need to be going.

 

Many Thanks

 

S

Edited by Scorpio
Posted (edited)

1. If you want to apply old school GPOs and not just intune policies then yes you won't be able to send out new GPOs without a VPN. What you really want to do is avoid domain joining at all (So pure "Azure AD joined" and not "Hybrid AD joined" and just having them purely managed in the cloud by Intune policies.

 

2. Yes, assuming you have your GPOs set to cache logins - If you have "Azure AD joined" only then you don't need LOS ever.

 

Autopilot is just one way of enrolling devices to your setup - So for example with the DFE laptops we captured the hardware keys of the devices & then reset them - They run the Windows OOBE & follow our autopilot script to join our Azure AD - From there it then picks up all the correct policies/installs all it's apps. It's a thing of beauty when it works & if you ever have to reset the device again, it just does the same again. If you buy from some vendors, they can pre-register devices in your autopilot. The idea is that you can then send a brand new device to a new employee/student without ever having it touch IT.

 

Yes, you can have a mix of hybrid and azure AD joined only. 99% of what you need in GPO you can do in intune & you can import ADMXs if you really need to. Try to use the MS baselines where you can for an easier

 

3. Yes that's right, again assuming you have GPOs set to cache logins.

 

4. Yes, assuming you've got all this setup using the MS guidance. Works for "Azure AD joined" machines also

 

5. This is 100% the way forward. Don't worry about update hammering your WAN link either, as you can setup delivery optimization so clients share the update over your network.

 

6. No, Hybrid devices will still need LOS to the DC to change password. Whatever password they cache before leaving site, will be the password that laptop is stuck with. If you change the password on prem without that laptop also having LOS to the DC, you'll break the SSSO to anything on the cloud.

 

 

It's a hella lot to get your head around so don't worry about asking questions :p - I'm still learning now & I know I'm only really scratching the surface of what we can do with it. Long term you can trash your DCs & live in the cloud fully. (Scary but would already work in smaller places, eg primaries)

Edited by DrCheese
  • Thanks 1
Posted

We are heavily using intune/endpoint manager at the moment, not hybrid. We went from 0 to over 300 devices managed over lockdown.

 

I'm seriously considering ditching SCCM.

 

My thoughts with intune/endpoint since using it are:

Imaging - we currently just usb boot devices and then it hands over to autopilot.

 

However being able to order a laptop from Dell and it automatically being enrolled by them is just amazingly cool!

 

Drive management is non existent.. so windows update is your option.

 

There are a few scripts online that do helps. But only for Dell, HP and Lenovo kit.

 

It may be that better options exist.. but it's a messy one.

 

(MDT implementation may be the solution to the)

 

The ability to deploy software to a laptop even when off site is just amazing! I can't stress the convenience of this enough..

 

2D design deployed to all laptops... All in 300 various homes.. took me all of 3 clicks!

 

I did have concerns about intune and how it handled shared devices, but once again, this was out to rest after a bit of testing. Logins do generally take longer than our traditional 20 seconds.. but always under 60 seconds. So I'm happy with that.

 

It is just amazing not having to deploy from on site. Lock down chrome installs to all home learning laptops.. no recall and gp update.. it just deploys.. it's honestly scary efficient!

Also when a kid forgets the password.. having to recall it to cache the reset password was so annoying. That's now gone!

 

Just another comment about the password write back.. are we sure about that licence? We don't buy any P1 licences, and we have password write back.. to AD..

 

Hope these thoughts help! It was a mindset change, but I'm glad we moved!

Posted

Just another comment about the password write back.. are we sure about that licence? We don't buy any P1 licences, and we have password write back.. to AD..

 

It's documented here. If you licence M365 Education A3 you get AAD P1 (or P2 if you go M365 Edu A5) or it may be bundled as part of another license.

Posted

Lots to think about, great input guys, if anyone has anymore input, feel free this is coming a more and more popular scenario. It does sound like autopilot is some sort of witchcraft and can only get better/more supported hopefully!

 

Cheers

 

S

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...