Jump to content

Recommended Posts

Posted

Hi,

 

We are currently considering starting to move all our on-prem services to the cloud but starting to question whether its the right thing to do. It would be good to know what other peoples experiences were like when migrating and continue to be on a day to day basis using Azure, Autopilot, Intune etc.

 

Do you find you get any delays in configuration policies applying? One of my worries is that I lock things down on student devices i.e. access to admin apps such as Powershell, cmd and regedit or even access to Settings but the polices don't apply straight away like they would with GPO's and Students have access to things they shouldn't.

 

Also what is the experience with Printing and MIS like and how difficult was it to life and shift these services away from on-prem?

 

If anybody on here is from the NW of England and has move fully away from on-prem it would be great if we could connect and maybe visit your site to have a look at how you are doing it.

Posted
One of my biggest issues is with Applocker in Intune, you can only specify local groups for the policies to apply to, so you can't have different rules in place for different users. I'm really not sure why group membership can't be checked against Azure.
Posted

I have a very very basic Applocker policy in place using the OMA-URI ./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/IntuneEdu/EXE/Policy with an XML string which currently only blocks Microsoft things like Powershell, reg and terminal for Windows 11 which I target at 365 user groups. I think my worry is that the more and more configuration profiles I build up (especially ones targeted at users that apply at login) the more chance of them taking a while or not applying at all. How do you find Intune for this?

 

I don't know if I am going about my profiles the wrong way because I still have my GPO head on but I have a selection of individual profiles such as one that sets Default AAD, OneDrive, Power Options as well as others that are pointed to groups of devices. I then have ones targeted at 365 User Groups like Start Menu customisations, Edge settings, Windows Store settings. Am I right in the way I am doing it or should be changing something?

Posted

As far as is my understanding you are on the right track, you do after all need to have device and user based policies, unless you are 1:1 where you could just look at device based restrictions, I'm not sure if this would be best practice though. The approach I have taken so far is to have quite broad default policies with more granular ones targeting specific groups. My use case is quite small at the moment, I've only deployed the DfE supplied laptops to a selection of students on user driven deployments. I've yet to tackle shared devices properly. In terms of policies not applying, I haven't had any many issues so far outside of me breaking things when I was testing, but that could be because of my relatively small sample size and low complexity setup.

 

I think the usual mantra is very appropriate as far as Intune is concerned, keep things as simple as possible for as long as possible.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...