donkeymusic Posted March 14, 2022 Posted March 14, 2022 Good Morning, Apologies for reopening this thread, I am currently looking at using GCPW and Enhanced desktop with our Windows 10 devices. And I have a few questions, that I wondered if anyone can assist with, if possible? I have followed all the Google guidance to set this up but I'm not sure I'm getting it right. I have a test user, that can log in via Google on the Windows 10 machine, however, I'm not sure it's pulling down its Windows 10 profile, is there a good way to test this? Secondly, My test devices doesn't appear in the Google Admin console as an Endpoint, so not sure why the auto-enrolment is not taking place. I haven't added any of the registry fixes as I have made these changes in the Admin console. Thirdly, to make sure this solution would be an option for our school, do our Group Policies still apply? will I still get a student desktop/start menu? Thank you for any guidance
rogerdnixon Posted March 14, 2022 Posted March 14, 2022 OK - there are two approaches here. Option 1 - pure cloud management using Enhanced Desktop Security This require Plus or Standard Google licences and does not require local AD - you manage the devices entirely in the Google Admin console. In this case - see my blog post: https://wpsit.blogspot.com/2020/02/google-mdm-for-windows-10-devices-more.html - Works fine with Win 11 as well. We use this at primaries that have Windows devices and Secondaries that have ditched local AD. Option 2 user GCPW and manage devices in AD with local group policy This does not require any licenses from Google and you manage devices in AD with group policy. Users sign in with their Google account and get SSO to Chrome (as above). In this case see my post here: https://wpsit.blogspot.com/2021/03/google-login-and-single-sign-on-to.html This does require so reg keys and the attribute popping in the user on the Google Admin console. Other than signing in with their Google account - the experience is the same for end users. We use this at some of our Secondaries that still have local AD. Roger
donkeymusic Posted March 14, 2022 Posted March 14, 2022 (edited) Thanks for your reply. I have it all working, the test users I had forgot to add their AD usernames. so now its working, my next question is, is there anyway to get Google Drive to load as a mapped drive? or to auto log that in so that's it mounts? Thanks Edited March 14, 2022 by donkeymusic
rogerdnixon Posted March 14, 2022 Posted March 14, 2022 Not that I'm aware of. You can set Drive to auto launch and force sign in with browser - buts thats as far as I ever got.
donkeymusic Posted March 14, 2022 Posted March 14, 2022 Thanks, thats all i have as well, worth asking the question, but if no one else has managed it then will save some investigation time. thanks
jmak Posted March 14, 2022 Posted March 14, 2022 If you use Drive for Desktop it appears in File Explorer (as G: drive unless that's taken) and in context menus in all programs. You can deploy the app by Group Policy.
donkeymusic Posted March 15, 2022 Posted March 15, 2022 We have it on the devices, I was looking for a method to get it to auto-launch at start-up, just to save students from having to load it each time they change device. another question relating to GCPW, my devices don't appear to be enrolling into endpoint device management, I have the option set within the admin console to allow enrollment and Windows Deveice Management is enabled. Any ideas why they are not enrolling? Thanks
rogerdnixon Posted March 15, 2022 Posted March 15, 2022 Have you got a Plus or Standard license? Required to use Advanced desktop security and for the policies you set on the admin console to do anything.
donkeymusic Posted March 15, 2022 Posted March 15, 2022 Have you got a Plus or Standard license? Required to use Advanced desktop security and for the policies, you set on the admin console to do anything. We have the plus licences. Thanks
Jaan Posted March 15, 2022 Posted March 15, 2022 This might help with the auto start. Control Drive for desktop via reg edits Not had chance to try it here yet.
agomez Posted February 13 Posted February 13 I managed to do it without making any modifications to the active directory using msDS-PrincipalName; if this information is helpful, I'm sending the configuration screenshots. Schema Name: Enhanced desktop security Ldap : msDS-PrincipalName , Google: AD accounts, Multi-Valued: TRUE Ldap : o , Google: Local Windows accounts, Multi-Valued: TRUE
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now