Jump to content

Recommended Posts

Posted

Hello,

 

I am working with a school that is already pretty cloud focused - they have Arbour Cloud MIS and all of their data is in Teams, SharePoint or OneDrive already.

 

Long story short, their on premise AD is massively out of date - users and polices are not configured correctly and there is no Azure AD connect or similar setup. Essentially we would have to rebuild the AD to make it useful and up-to-date.

 

We are looking to use Intune for the management of their devices and everything looks reasonable here in terms of policies and restrictions, Autopilot etc etc.

 

The only on-premise software they need to run is authentication to the Sophos XG web filter and PaperCut MF. MF can be synced with Azure Active Directory via Secure LDAP. I've got this up and running in a test environment and everything seems to work as expected. Sophos was a bit more a pain and would require the MSI connect client but would achieve the end goal allbeit with another logon to the client.

 

Is there anyone already doing this - and if so is anything obvious I am missing with this *almost* serverless approach? Is there going to be some big gotcha and I will end up wishing we had just built an on-premise AD?

 

Thanks

Joel

Posted

I am doing this - decomm'd the AD servers a good few months ago, but everything was cloud drive since before lockdown.

 

Requires a different skill set and some things are incredibly frustrating but I'd never go back

  • Thanks 1
Posted
Thank you - I am happy with the skillset of Azure AD and Intune and got our policies 90% right… so that’s not worrying me I was just concerned I would come across something later on that I’d regret and have to go back to an on premise!
Posted

My biggest challenge was not having anything on prem to do DHCP, (and also DNS and host the PAC file for the web browser, but DNS and PAC file were solved by intune being able to specify proxy per wifi connection). None of the switches etc did it. I have a little NUC device which runs VMs and the management server for the wifi, so I run the DHCP software from dhcpserver.de on it and the sims machine (aka the SBMs PC, we're a small school).

 

Having to get rid of LAPS functionality was annoying, I see now there are community solutions but its poor that MS haven't provided this functionality.

 

Windows Licensing was a pain - I used KMS so that runs in a VM too. Office pro plus could have been problematic too but teachers have a single device and the pupil laptops have accounts per device.

 

The NUC also runs PRTG in a VM just to keep an eye on network switches and so on,

 

 

so I guess you could say we have servers (with no resilience) but the thinking is that it's not mission critical and not that stateful, plus I can stand it up on the SIMS machine if needed.

 

 

I also had to bodge something with credmgr to access SIMS fileshare (I think there are better options now), and remote support was a right pain to persuade to work and still isn't perfect (intune integrates with teamviewer but this is ££). Printing took a little graft (Just IP port printing) but I read the other day about an MS proposed approach for intune.

Posted

Thank you again for taking the time to explain this it has given me some food for thought.

 

Just wondering did you go with the Azure Domain Services extra add on for the secure ldap - and if so how did you get this? I’ve been trying to see if we can get the license somehow through CSP but nobody seems to know. It’s running on trial credit on Azure at the Moment.

 

I’ve managed to get the Azure printing solution setup via the papercut mf as it has a connector already built in so this seems easy to deploy for us.

 

Thanks again

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...