CyBeRkId2002 Posted December 17, 2021 Posted December 17, 2021 Hi all, I am currently trying to centralise services across our trust and I think it is likely to end up with a single forest and RODC's at all sites due to them being extremely rural and having pretty terrible broadband speeds. That bit I am fairly happy with. In addition we also have a central team of 10ish people based elsewhere who it just seems over the top to install an RODC for. I wondered how other people are managing devices which very rarely check in to a network. Do you have them domain joined for compliance / to set policies? Am I missing a trick with Azure connected devices (as in, could I just get them to sign in to their cloud account. Interested in hearing any tips and tricks for people who rarely connect to a domain and what people have come up with to manage these with the minimum of fuss!
kylewilliamson Posted December 17, 2021 Posted December 17, 2021 If you're using a single forest you could sync into Azure for 365, but also allow mobile devices to sign straight into Azure AD and use Endpoint Manager to run any mobile devices. We took a secondary earlier this year from a single forest into a full Azure AD setup using endpoint manager and having log ins straight into Cloud Accounts; you should really consider this in your scenario as it effectively means no DC's at all to maintain on any site. Kyle
p858snake Posted December 18, 2021 Posted December 18, 2021 Although it may be over the top due tot he size, it might be worth while to still consider a RODC, That way all the sites are configured the same and may make configuration easier in the future.
5tu Posted December 18, 2021 Posted December 18, 2021 Definitely go Azure AD only and manage with Endpoint / Intune. Perfect solution for what you’re describing.
CyBeRkId2002 Posted December 18, 2021 Author Posted December 18, 2021 I think I agree that AzureAD may be the best fit ... and using this small team as a trial it may actually influence what we do in the primaries. To replicate what we join these devices to AD for right now what I would need from Azure/Intune/Endpoint is: Set Defender policies Push out a small amount of software (realistically for our central team this is mainly just Chrome and Office) Enforce bitlocker and, ideally, store the key in AD Enforce a password policy Enforce Windows Update policies and keep an eye on these (Baselines etc.) Allow sign-in when a network is not available (I presume even using cloud credentials the ability to sign-in offline is available?) Push out a CA cert for when they connect to I am guessing all of this is do-able using these three technologies, and is it covered in a typical E3 licence. How does the process work? Do we add the device to Azure AD administratively and then hand the device over? Or is there an OOBE option that is really hands-off. Any guides, pointers, walkthroughs on options that people have found particularly useful would be great!
kylewilliamson Posted December 18, 2021 Posted December 18, 2021 The OOBE experience is called Autopilot - there's a good link here on the different enrollment methods for Endpoint Manager - https://www.petervanderwoude.nl/post/windows-10-enrollment-methods/ You want A3 Licensing, rather than E3, a) it's cheaper and b) each A3 licence for faculty/staff comes with a free Student A3 License.... And yes, all of this is doable with AzureAD - you do have to get to grips with Powershell I'm afraid to say but it's a really neat install. What do you use for Internet Filtering and how does that slot in? Both Censornet and Smoothwall now have a agent based operation rather than Proxy based, which fits much neater with this type of setup as with AzureAD, the device doesn't tend to operate any different wether it's onsite or being used remotely. Kyle
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now