Jump to content

Recommended Posts

Posted (edited)

We are and EDU organization. Right now we are looking at converting staff computers to AAD/Intune/Autopilot, and move away from SCCM.We have about 2000 staff endpoints some of those are shared machines. So those shared devices would been to be self-deployment.About 3000 endpoints are student use, with deepfreeze (we know we would have to UWF, for Intune switch.)We are a dell shop.

Endpoint licensing:

How does one handle the licensing of the device? When using SCCM we license against our KMS server on premise. And OSD the computers with EDU. However with autopilot the computers come from Dell with Professional. So my questions are.Do you just leave the machine at professional? This is something we are considering, but i wonder if others do it...

Does anyone see a hang up of just leaving the machines Professional, and the off chance someone needs ENT/EDU, we assign them to the group that changes Edition upgrade and mode switch?We have access to the Volume license servers, that has MAK keys, however we only have lots of 500 and don’t think that is sustainable. Has anyone here used MAK keys? I heard you can call your Microsoft rep to have more issued.

I also read that one can get user assigned licenses for edition update so when the user signed in that edition is licensed. However how does that work for shared devices that our students would sign into? Wouldn’t that be super expensive to license the thousands of students? Unless I'm missing something that does not make sense.

Can one provision a self-deployment machine with AAD/Intune/Autopilot, and the machine is on premise (will always be on premise), and have the machine check in to a On premise Domaine joined KMS server? Is that even possible? I think the DNS activation would be the only option...?

 

Intune permission Management:

Currently I'm the sole admin of Intune, however we have techs at various locations. Some of our devices will be shared devices. Obviously I don’t want to have to delete the Intune object of a device, every time a tech has to reload it. What permission level should the techs have so then can delete the objects and view objects in Intune, along with their bit locker keys. Also they will need to be able to set device names as well.

What type of permissions is recommended for the above?Thanks,-AA

Edited by AlteredAdmin
Posted
We just use MAK keys while imaging and call to increase the limit when getting close to running out of licenses. I think there is a way to do a version switch using an Intune policy if you do not reimage when purchasing. For licensing we license all of our Full time Staff and receive a student use benefit that has licenses for all of our students. Any account that logs into a Intune joined device should have a Intune license assigned.
Posted

1/ We build every device as Pro, and then have an intune policy to update it to Education editionn using MAK. The policy only allows an upgrade and won't apply unless it is changing versions.

 

2/ Scope tags are your friend here and you'll need them. You can create roles that only allow users to edit devices under a specific scope tag.

Posted
We just use MAK keys while imaging and call to increase the limit when getting close to running out of licenses. I think there is a way to do a version switch using an Intune policy if you do not reimage when purchasing. For licensing we license all of our Full time Staff and receive a student use benefit that has licenses for all of our students. Any account that logs into a Intune joined device should have a Intune license assigned.

 

So walk me trough your provision process.

 

  1. Have you ever had trouble increasing the amount MAK when you talk to your Microsoft rep?
  2. Why didn't you try to get User licensing to license the machine from office 365 when a user signs in?

    1. Is it because your may have shared devices?
    2.  

      [*]How do you handle you Open computer LABS? Self deploy Autopilot?

      [*]For example Dell ships with win pro, why didn't you leave the machines Wipro?

Posted
1/ We build every device as Pro, and then have an Intune policy to update it to Education edition using MAK. The policy only allows an upgrade and won't apply unless it is changing versions.

 

2/ Scope tags are your friend here and you'll need them. You can create roles that only allow users to edit devices under a specific scope tag.

 

Can you give more information about your provision work flow?

why didn't you leave the machine PRO?

What is your process for requesting more MAK keys from Microsoft?

Posted (edited)
So walk me trough your provision process.

 

  1. Have you ever had trouble increasing the amount MAK when you talk to your Microsoft rep?
  2. Why didn't you try to get User licensing to license the machine from office 365 when a user signs in?

    1. Is it because your may have shared devices?
    2.  

      [*]How do you handle you Open computer LABS? Self deploy Autopilot?

      [*]For example Dell ships with win pro, why didn't you leave the machines Wipro?

      1. No we have not had any issues increasing the limit. We have been using devices with Intune this way for several years without any issues.

      2. I'm not exactly sure what you mean by this. I don't think device licenses were a thing when we started with Intune. We currently have a mix of A3/A5 licenses for Staff and with the student use benefit all Students have an A3 license. We also have a handful of spare licenses for generic accounts.

      3. Computer labs are currently imaged with MDT and Hybrid joined and mostly managed with Group Policies currently looking into removing the group policies and managing with Intune policies.

      4. I believe there are some things like the Microsoft consumer experience, Cortana and the store that you can not remove if running pro. I also prefer to image them to remove any bloatware the manufacture might have preloaded on the devices.

Edited by NicholasEsping
Posted
Can you give more information about your provision work flow?

why didn't you leave the machine PRO?

What is your process for requesting more MAK keys from Microsoft?

Provisioning wise, we have 3 paths:

 

Manufacturer images devices to our specification. This is the preferred route and our suppliers do this at no cost now.

In the office MDT to build devices in bulk.

Out of the office a customised Windows 10 USB with drivers imported (Techs have a few, one for each brand of device).

 

For option 1, the supplier imports Autopilot information

For option 2 we gather Autopilot data during the build and we import this

For option 3 The techs either gather Autopilot data (for devices with TPM) or we use a provisioning package.

 

Anything in autopilot has the single self provisioning profile applied automatically. We also add devices to groups before they are shipped so that they are ready to go when they get to site.

 

We don't leave devices as Pro as we use some enterprise features that are only in Education. Because our devices across the 4,000 trust devices are a mixed bag of licensing, everything is upgraded to the same version.

 

In our environment there is no KMS server - we need to license the devices which have Pro/Home - the upgrade process using Intune solves this and inserts an appropriate MAK key.

 

I just phone the VLSC service desk and they increase the MAK keys.

 

https://www.microsoft.com/en-us/licensing/existing-customer/activation-centers

  • Thanks 1
Posted
1. No we have not had any issues increasing the limit. We have been using devices with Intune this way for several years without any issues.

2. I'm not exactly sure what you mean by this. I don't think device licenses were a thing when we started with Intune. We currently have a mix of A3/A5 licenses for Staff and with the student use benefit all Students have an A3 license. We also have a handful of spare licenses for generic accounts.

3. Computer labs are currently imaged with MDT and Hybrid joined and mostly managed with Group Policies currently looking into removing the group policies and managing with Intune policies.

4. I believe there are some things like the Microsoft consumer experience, Cortana and the store that you can not remove if running pro. I also prefer to image them to remove any bloatware the manufacture might have preloaded on the devices.

 

Question about #3

 

your computer labs are they shared devices self deployment profile? how are the machine hybrid joined? I thought you could not hybrid join self deployed machines....? Explain some more on this... Unless you are doing it a way I'm not thinking about...

Posted
Provisioning wise, we have 3 paths:

 

Manufacturer images devices to our specification. This is the preferred route and our suppliers do this at no cost now.

In the office MDT to build devices in bulk.

Out of the office a customised Windows 10 USB with drivers imported (Techs have a few, one for each brand of device).

 

For option 1, the supplier imports Autopilot information

For option 2 we gather Autopilot data during the build and we import this

For option 3 The techs either gather Autopilot data (for devices with TPM) or we use a provisioning package.

 

Anything in autopilot has the single self provisioning profile applied automatically. We also add devices to groups before they are shipped so that they are ready to go when they get to site.

 

We don't leave devices as Pro as we use some enterprise features that are only in Education. Because our devices across the 4,000 trust devices are a mixed bag of licensing, everything is upgraded to the same version.

 

In our environment there is no KMS server - we need to license the devices which have Pro/Home - the upgrade process using Intune solves this and inserts an appropriate MAK key.

 

I just phone the VLSC service desk and they increase the MAK keys.

 

https://www.microsoft.com/en-us/licensing/existing-customer/activation-centers

 

 

You said you use self deployment, do you use that for everything?

 

We are thinking about using User driven for staff/faculty and self for computer labs.

Posted
Question about #3

 

your computer labs are they shared devices self deployment profile? how are the machine hybrid joined? I thought you could not hybrid join self deployed machines....? Explain some more on this... Unless you are doing it a way I'm not thinking about...

 

Our labs are not using autopilot. We image with MDT to domain join them and during the task sequence we use powershell to enroll as a shared device in intune using a provisioning package created with Windows configuration designer.

  • Thanks 1
  • 3 weeks later...
Posted
Our labs are not using autopilot. We image with MDT to domain join them and during the task sequence we use PowerShell to enroll as a shared device in Intune using a provisioning package created with Windows configuration designer.

 

Do you mind sharing how you deploy the Provisioning package with PowerShell?

 

Does it deploy the Provisioning package from MDT with no user interaction?

Posted
Do you mind sharing how you deploy the Provisioning package with PowerShell?

 

Does it deploy the Provisioning package from MDT with no user interaction?

 

Below is the powershell command I use I have it added in the State Restore section right after Applications and Updates get installed. After running the PowerShell I have the computer reboot and then let it finish the task sequence. I do have to update the package every 6 months as it does have an expiration date. There is no user interaction needed for adding the provisioning package.

Add-ProvisioningPackage -Path "\\WDS\DeploymentShare$\Scripts\ProvisioningPackage\AzureEnroll.ppkg" -Quietinstall

Screenshot 2022-03-23 100406.png

  • Thanks 1
Posted
Below is the powershell command I use I have it added in the State Restore section right after Applications and Updates get installed. After running the PowerShell I have the computer reboot and then let it finish the task sequence. I do have to update the package every 6 months as it does have an expiration date. There is no user interaction needed for adding the provisioning package.

Add-ProvisioningPackage -Path "\\WDS\DeploymentShare$\Scripts\ProvisioningPackage\AzureEnroll.ppkg" -Quietinstall

[ATTACH=CONFIG]65092[/ATTACH]

 

 

When we create the provisioning I'm forced to create a device name.

But we would want the device set from MDT and not the provisioning package.

 

What happens on your end?

Posted
Our labs are not using autopilot. We image with MDT to domain join them and during the task sequence we use powershell to enroll as a shared device in intune using a provisioning package created with Windows configuration designer.

 

Also when you say domain joined are they domain join on premise so that makes then hybrid or are you domain joining to Azure AD only? Our goal for student machine will be hybrid.

Posted
Below is the powershell command I use I have it added in the State Restore section right after Applications and Updates get installed. After running the PowerShell I have the computer reboot and then let it finish the task sequence. I do have to update the package every 6 months as it does have an expiration date. There is no user interaction needed for adding the provisioning package.

Add-ProvisioningPackage -Path "\\WDS\DeploymentShare$\Scripts\ProvisioningPackage\AzureEnroll.ppkg" -Quietinstall

[ATTACH=CONFIG]65092[/ATTACH]

 

Ok i was able to get the package to install on a on prem domain joined machine, and it is both domain joined and Azure AD joined according to dsregcmd.

I was able to figure out the naming thing https://deviceadvice.io/2021/04/06/exploring-hybrid-azure-ad-join-with-a-provisioning-package/

 

The device does show in Azure AD and on prem AD.

 

However the device does not show in Intune. Am i missing something?

Posted
Also on the devices what do you have set for "Enable Automatic MDM enrollment using default Azure AD credentials"? Does that need to be set if you are using provisioning package.
Posted
Also on the devices what do you have set for "Enable Automatic MDM enrollment using default Azure AD credentials"? Does that need to be set if you are using provisioning package.

That shouldn't need to be set when using provisioning packages since the package is enrolling the device. To get the devices to enroll into Intune and not just in Azure do you have Intune set as your MDM under Mobility in Azure AD?

Screenshot 2022-03-29 090952.png

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...