Jump to content

Recommended Posts

Posted
Seeing more and more threads here now where intune is causing all kinds of headaches and even myself have now ran into some. Not much response on the forums at times as well. Just seem like it has broken parts to it and when people run into issue not many answers why.
Posted
Seeing more and more threads here now where intune is causing all kinds of headaches and even myself have now ran into some. Not much response on the forums at times as well. Just seem like it has broken parts to it and when people run into issue not many answers why.

 

Mainly because it's meant for 1:1 devices and technical confident users who can enroll their own device.

Posted

I definitely don't agree it is a broken product. I have been using it for a couple years successfully and we are currently enrolling over 350 new staff laptops in it. Working great for us and our trust.

 

What I would say is people really need to put some time to make sure they are doing the research before they move over to Intune. As I said on another thread, printing is one of the biggest headaches with Intune - you need to nail down how you are going to host your printing in a way that Intune is compatible. Ideally you need a cloud managed printing soloution.

 

I also think, people want some elements of cloud, and others of on-site. Intune is fully cloud product, I do not believe it is meant to hybrid setups. For example I know some schools who want to connect local file shares to an intune enrolled device. Possible... but not ideal.

Personally I want that - I am moving full steam ahead to cloud, and therefore I don't want Intune wasting there time on Hybrid stuff. But i can appreciate not everyone would have that drive, and want it to work remotely. Each to there own.

 

When I see the word Intune / Endpoint Manager on edugeek, it does tend to catch my eye, and I will try share what knowledge I have to help those trying to move to Endpoint Manager and having problems.

  • Thanks 1
Posted
Mainly because it's meant for 1:1 devices and technical confident users who can enroll their own device.

I feel like a Microsoft employee with my defence here.. but I disagree with part one... Intune has many policies to make a device a shared device.

 

The enrolling of own devices is a route you can take.. but also, you can have fully managed, where you as the tech enrol the device for them.

Posted

Agree with @MJTayloronline here.

 

Enrollment can be automatic using autopilot and there are plenty of shared device features and methods for getting it to work. KFM means documents are saved appropriately from r staff devices.

 

Most group policy settings are now available in Intune as well.

 

We have been using Intune across our 34 schools for 3 years and have been fully cloud based for 2 years.

 

Printing is a pain, but universal print has fixed it now and it's reliable and works with Papercut.

 

My advice: Don't bother with Hybrid. It's time to rethink how you are using devices and build up Intune policies and systems from scratch.

  • Thanks 2
Posted

I think, in part, it's because we're all comfortable with group policy/ SCCM and fairly rich diagnostic tools. It feels like the designers of intune have never done PC management before and it's a lot 'closer' to how you'd automate azure deployments and the like. I'd sa there are gaps in functionality and powershell scripting or fairly complex haiku is required to fill said gaps (have you tried to create your own policy templates - its utterly painful)

 

SO I don't agree, but that said that when I'm trying to fault find why something isnt working with the crap diagnostic logs - ask me again!

  • Thanks 1
Posted
I think, in part, it's because we're all comfortable with group policy/ SCCM and fairly rich diagnostic tools. It feels like the designers of intune have never done PC management before and it's a lot 'closer' to how you'd automate azure deployments and the like. I'd sa there are gaps in functionality and powershell scripting or fairly complex haiku is required to fill said gaps (have you tried to create your own policy templates - its utterly painful)

 

SO I don't agree, but that said that when I'm trying to fault find why something isnt working with the crap diagnostic logs - ask me again!

 

Like all MDMs it’s based around a protocol and schema designed to manage mobile phones from 2008. It (like all MDMs) does a poor job at the multiple edge cases that Group Policy and SCCM excel at. As long as you do what the designers (who clearly never managed enterprise desktops before they made some architectural decisions) expect it is “fine” (c.f. “OFSTED satisfactory”)

 

That said, have found autopilot to fail 1/6th of the time, and it isn’t good at multipurpose devices (devices whose purpose/restrictions need to change based on the context of the user logging on) so it feels to me too that there is something broken.

 

Incidentally has anyone looked at the abomination that is Microsoft Powershell Graph API? Hand crafting URLs anyone? Urgh. It like Microsoft have forgotten all they learned 1990-2010. It genuinely reminds me the abomination that was Perl for Win32!

  • Thanks 1
Posted

 

I also think, people want some elements of cloud, and others of on-site. Intune is fully cloud product, I do not believe it is meant to hybrid setups. For example I know some schools who want to connect local file shares to an intune enrolled device. Possible... but not ideal.

 

I know next to nothing about InTune but is Co-Management of InTune with Configuration Manager the way to do hybrid?

 

https://docs.microsoft.com/en-us/mem/endpoint-manager-overview

https://docs.microsoft.com/en-us/mem/configmgr/comanage/

Posted
We currently have laptops intuned for students to use at home. Next project is to have staff laptops intuned for home but still domain joined for access to shares. Can anyone point me in the 'neatest' direction for this?
Posted
If the accounts teachers use to sign into the laptops are synced from on prem AD you don’t need to join the devices to on prem AD, it’ll just work.
  • 2 weeks later...
Posted (edited)

I just wanted to add, that in recent months we have started to embrace and work towards utilising and implementing the latest methods and technologies of managing devices and Office365 services.

 

However, despite many weeks and months (even with 3rd Party support initially to help configure and setup a wrath of Microsoft 365, Azure policies etc.) it feels like I get a good few days of progress (with Microsoft Endpoint Manager) and then an issue arises that takes you back to square one again!

 

I definitely don't agree it is a broken product. I have been using it for a couple years successfully and we are currently enrolling over 350 new staff laptops in it. Working great for us and our trust.

What I would say is people really need to put some time to make sure they are doing the research before they move over to Intune. As I said on another thread, printing is one of the biggest headaches with Intune - you need to nail down how you are going to host your printing in a way that Intune is compatible. Ideally you need a cloud managed printing soloution.

I also think, people want some elements of cloud, and others of on-site. Intune is fully cloud product, I do not believe it is meant to hybrid setups. For example I know some schools who want to connect local file shares to an intune enrolled device. Possible... but not ideal.

 

Personally I want that - I am moving full steam ahead to cloud, and therefore I don't want Intune wasting there time on Hybrid stuff. But i can appreciate not everyone would have that drive, and want it to work remotely. Each to there own.

When I see the word Intune / Endpoint Manager on edugeek, it does tend to catch my eye, and I will try share what knowledge I have to help those trying to move to Endpoint Manager and having problems.

 

As @MJTayloronline mentioned, I too want to move ahead towards cloud, and migrate away from Local AD GPO to MEM-based profiles etc. Yes, certainly a big hurdle and amount of work initially, but we've kept telling ourselves it will be worth it long term!

 

Laptops, specifically any we issue 1:1 (e.g., the DfE laptops) we are content with setting up and enrolling with Autopilot, applying applicable device configuration profiles and deployment of software.

 

However, the main issue is that we've been attempting to do similar with our Local AD computers, which are Hybrid AD Joined using Azure AD Connect. The joining to Azure AD and autoenrollment to MDM is all working (using DEM accounts as part of the build process etc.). But sadly, it’s the policy/configuration side that is so frustrating.

 

Agree with @MJTayloronline here.

Enrollment can be automatic using autopilot and there are plenty of shared device features and methods for getting it to work. KFM means documents are saved appropriately from r staff devices.

Most group policy settings are now available in Intune as well.

 

We have been using Intune across our 34 schools for 3 years and have been fully cloud based for 2 years.

 

Printing is a pain, but universal print has fixed it now and it's reliable and works with Papercut.

 

My advice: Don't bother with Hybrid. It's time to rethink how you are using devices and build up Intune policies and systems from scratch.

 

As @Mr.Ben mentioned, that is what we have started off doing, by creating new Intune policies from scratch. Of course, we always knew that some local GPO would still be needed (e.g., print / file mappings, DPI-SSL certificates, MDM AutoEnrollment, LAPs etc) but we were hoping (and intending) that all other policies could be applied via Intune.

 

This is when we've realised that Intune policies are not applied instantly / all the time when a user logs in. That is not really an issue for a 1:1 device (e.g. laptop). However, we are wanting to do this for our (shared) desktop computers (Hybrid AD Joined).

 

In an attempt to overcome these issues, we have even tested configuring policies that apply to the computer (group) as opposed to user (group membership) level, to see if that would apply the settings properly (on the premise that perhaps they stay applied, such that when someone else logs in the setting are already in-place???). Whilst understanding the limitations of applying settings to the device (as opposed to user - meaning settings would be applied regardless of who logs in) we were prepared to compromise by assigning different computer-based polices to different builds of computers (e.g. Student, Teacher, Admin etc.) to see if that would be workable…

 

That said, have found autopilot to fail 1/6th of the time, and it isn’t good at multipurpose devices (devices whose purpose/restrictions need to change based on the context of the user logging on) so it feels to me too that there is something broken.

 

Even after trying all the above, it is quite clear that Intune policies on hybrid computers (more specifically, shared devices) is not possible(?); or they certainly do not work as efficiently as Local GPOs. As current testing has indicated that even when a user logs in (and policies are eventually applied), once logged out and another user logs in. It appears that all the applicable policies are not initially applied, and you must wait (again!). Which, if you imagine if this was as student logging in, their Windows 10 environment would not (initially) be managed / restricted!

 

Perhaps as @psydii suggested, this is indeed the case(?), and we've spent an age attempting to achieve something that Intune cannot (currently) do (as good as GPOs)?

 

That aside, there are many other elements of using Intune (MEM) which have proved very beneficial.

For example,

 

- The Windows Update Rings and Feature Updates – means we can work towards decommissioning our current WSUS server, as well as comply with updates within 14-days

- The analytics and reporting features within Intune (MEM) are really beneficial, detailed information of every device, inventory, security / patch status etc.

- Software (App) deployment – We previously deployed software via MDT and PDQ, and are now working towards adding more to Intune

- Office365 Deployment and Policies using Microsoft 365 Apps Admin Centre

 

 

Unless we are doing something fundamentally wrong (as I keep getting told that many schools are using Intune (MEM) – or perhaps the majority are using 1:1 devices, and not shared-devices?) I therefore think we will ultimately have to resort back to creating/updating Local GPOs (to reflect the Intune device configuration policies) for our School Hybrid AD Joined Shared-Devices. (e.g. computers) in respect of device restrictions (e.g. Start Menu, Taskbar, options availability, Applocker - I have this working via Intune, but may use a local GPO...)

 

Thanks,

Edited by MYK-IT
  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...