Jump to content

Recommended Posts

Posted

I am planning to set up an AD for all university owned devices but would also like to give autonomy to the senior management team. Would having virtual desktops achieve this?

 

Also, I plan on having a failover AD over the cloud possibly using Azure AD but am not familiar on how to achieve this. Any help would be appreciated. Thank you.

P.S. I am new in my role as sysadmin.

Posted

What do you mean by "autonomy for the SMT"? That they can customize their "user experience", eg their own backgrounds and start menu layouts? Or full on, they can install their own programs?

I don't see why you would necessarily need virtual desktops for either of those things, although I guess it depends on if their roaming from PC to PC. Will staff need to carry settings from PC to PC (or do they have laptops, or only ever log onto a single computer)?

  • Thanks 1
Posted

A few questions for you to consider:

 

Which people/roles make up SLT?

University seniors, eg Vice Chancellor and their direct reports? Heads of School? (Humanities, Science, Engineering, Languages). Heads of department (Geography, History, Maths, Physics)? Heads of research groups (Quantum Physics, Biophysics, Astrophysics)? Academics tend to think they're fairly autonomous and have often been allowed to operate that way.

 

How many devices do you actually have control of? ie Are they bought and managed by your department? Are they bought with research grants and therefore may not belong to the university, but to the person the grant was awarded to? What about visiting academics - do you fund and provide machines for them to work on our do you allow them to connect their devices to your network?

 

I know what I'd like to happen and you should define your desired ideal outcome, but there may be several steps on the way and you might have a long path before you can get to locking down all machines that access your network.

  • Thanks 2
Posted
I now have a fair idea of what virtual desktops are, thanks for that. Autonomy as in they can still use their own laptops (change settings; install programs) but to access the university's network resources, they will have to sign in. This would be different for devices purchased by the University where users will have to log into the DC to access network resources.
Posted

SLT are those in Chancellery and HODs.

 

 

Currently, each department does their own procurement of devices (without the knowledge of IT) and then task the IT staff to configure and install. PCs purchased by the University are managed by the end-user, there is no form of control and monitoring of assets and network resources. Visiting academics have their own laptops/devices. Roughly, I would say we have more than 200 laptops/desktops purchased by the University.

Posted
Autonomy as in they can still use their own laptops (change settings; install programs) but to access the university's network resources, they will have to sign in. This would be different for devices purchased by the University where users will have to log into the DC to access network resources.

Based on what I've seen/read Azure AD with Autopilot would be the easiest way to set up something like that.

  • Thanks 1
Posted

I don't envy you your task, to be honest. Having personally "managed" devices attached to the corporate network is an exercise in frustration. On the one hand, you have the organisation pushing for better management of devices, on the other you have the user screaming at you because you're trying to put in policies for "their" devices, even when they're owned by the organisation.

 

I guess the first question has to be, what level of management are you looking to get out of this? Are you looking to put in restrictions of some description on the device, or looking to apply policies or deploy software? Do you want to manage anti-virus? Do you want to deploy printers and shares to the devices?

 

Intune with Conditional Access might be a good path to take. It's relatively easy to enrol devices in it, you can push out software, policies etc. There are bolt-ons to Azure that you can use to deploy printers, plus you can use Conditional Access to determine whether a computer is allowed to connect to your corporate resources or not, for example you could say that you need anti-virus to be up to date and Windows patch version to be 10.0.x.x or higher to connect to Office 365. You can use it to join your devices to Azure AD but they don't need to be connected to an on-premise AD to be managed.

  • Thanks 3
Posted

I think your two options are either as per @Norphy's suggestion or VDI as you said. VDI gives more security/control, but it's more expensive.

 

Either way I think you'll be looking at a massive culture change (hesitate to say war, but at least that might give you the idea of battles which you can pick from).

 

If you haven't already, it could be worth dropping "cyber essentials" into conversations. When things are working and the network hasn't been lost to a hacker, it's very difficult to change culture. The thing that talks is money; cyber essentials is starting to appear as a pre-requisite for research grants. If academics or departments start getting funding withheld, you'll start to get movement.

 

I'd start with things you can control - set up proper procurement processes for university owned devices. Start restricting access to university assets (data/file stores) from devices you don't control.

  • Thanks 1
Posted

Two paths there then:

 

1) for non-university devices, conditional access - and many of their devices will not meet the necessary specification required for secure access.

2) AutoPilot / Intune.

 

Both of these will already be available to Central IT in AzureAD / Microsoft 365. Without knowing the size of the univeristy it is difficult to offer much more advice than has already been given. But it is likely that the systems you need will already have an "owner" and they will likely be defensive about getting this set up for you... depending who is sponsoring this initiative.

 

If you have some academics on board... you will need to be at their beck and call 24/7 to fix perceived issues with the new more restrictive environment, until you and the support team are completely comfortable that you have got the onboarding and troubleshooting processes completely down. If a member of the senior management team or HoD or a tenured Professor starts throwing their toys out of the pram... that's the project dead.

Posted

The university currently has 5 faculties plus another campus in another province (state) who connect via VPN to the main campus. On top of that, we have the administrative and support staff so that’s about less than 3000 with room for growth.

I have had issues with deploying O365 since I go from one device to another. Most laptops/PCs I find have a lot of junk as in installing software they are unaware of or hardly use.

So what I want to achieve is for all devices purchased by the university to be monitored and managed at a central point especially when it comes to standard software deployment, OS upgrades and security.

Posted (edited)
So what I want to achieve is for all devices purchased by the university to be monitored and managed at a central point especially when it comes to standard software deployment, OS upgrades and security.

Sounds like an almost textbook use case for Azure and 365 Endpoint Manager/Autopilot.

Enroll all your uni-owned devices, and you can monitor and manage them through Office 365.

Edited by Rob_D
  • Thanks 1
Posted
Agree from a standing start 365 with InTune seems the best way forward. However there must be some legacy here... Where is the central email system? Who 'owns' that? How does the university currently ensure security compliance - where are they getting updates and anti-virus from?
  • Thanks 1
  • 2 weeks later...
Posted
Agree from a standing start 365 with InTune seems the best way forward. However there must be some legacy here... Where is the central email system? Who 'owns' that? How does the university currently ensure security compliance - where are they getting updates and anti-virus from?

 

The new email system is with 0ffice 365. Currently, all devices are not centrally managed. We are rolling out O365 individually to each device and I can tell you, it's a BIG challenge when each device has different Windows versions! Updates and AVs are not centrally managed as well. Basically, all devices are standalone with the user being in charge of the machine.

 

The only security measure we have is the network firewall but when it comes down to each device, then each to its own.

 

P.S. I have been tasked to come up with a system design that can cater to the needs of the university.

Posted (edited)

Microsoft 365 E5 is absolutely the toolset you should be pushing for. It has all the technical tools you need to make this work well, without needing to go back and ask for more money to fix things later. You will get a lot of support form the FastTrack teams as you stand up each new element.

 

If you can you really must ensure there are automated processes for sending HR and Student on-roll data into AzureAD/365. (https://docs.microsoft.com/en-us/schooldatasync/overview-of-school-data-sync). Getting the design of groups right and the processes for keeping them updated fundamental to success. One account per user, granting them the appropriate access to the appropriate resources, depending on the state of the device they are using at that time. Seamlessly, Secure.

 

Your focus is devices, so Intune / autopilot and conditional access will be the right way to go in this scenario. Treat the legacy devices as BYOD, how you deal with new devices really depends on how the politics is navigated. If the Principle/Chancellor wants things centralised then you almost have a free hand to build out the perfect system, (new device purchased by IT as a service to faculties, and managed as such). Otherwise some level of compromise between what it right for the reliability of the service and security against what the end users *thinks* their need are will be required.

 

Is there a modern equivalent of the 70-221 course material? I seem to recall it contained enough abstracted principals for it to still be useful, even if it technical content is based around on-prem AD.

https://www.pearsonitcertification.com/articles/article.aspx?p=30481

 

This problem here is more about people and politics than technical details. The above link might give you useful pointers on what sorts of things you need to consider. Outline of chapter two of that book:

 

 

Evaluate the company's existing and planned technical environment and goals.

 

Analyze company size and user and resource distribution.

 

Assess the available connectivity between the geographic location of work sites and remote sites.

 

Assess net available bandwidth and latency.

 

Analyze performance, availability, and scalability requirements of services.

 

Analyze data and system access patterns.

 

Analyze network roles and responsibilities.

 

Analyze security considerations.

 

This objective will help you determine how to translate the goals of the business into a technical design. You will learn how to assess the existing network infrastructure from a technical point of view and compare it to the proposed goals to determine which Windows 2000 features will need to be included in your design.

 

Analyze the impact of infrastructure design on the existing and planned technical environment.

 

Assess current applications.

 

Analyze network infrastructure, protocols, and hosts.

 

Evaluate network services.

 

Analyze TCP/IP infrastructure.

 

Assess current hardware.

 

Identify existing and planned upgrades and rollouts.

 

Analyze technical support structure.

 

Analyze existing and planned network and systems management.

 

This objective addresses the considerations that must be made to determine the impact of a new network infrastructure design on the existing network infrastructure. Windows 2000 was designed to be deployed gradually. To successfully deploy, you must fully understand the areas where changes to the existing infrastructure will be the most disruptive and plan accordingly. You must also be able to identify the areas of the existing network infrastructure requiring improvement or change.

 

Analyze the network requirements for client computer access.

 

Analyze end-user work needs.

 

Analyze end-user usage patterns.

 

The primary function of any network infrastructure is to support the needs of the end users. This objective will help you learn to identify the needs of the end-user community and focus your network infrastructure design on meeting those needs.

 

Analyze the existing disaster recovery strategy for client computers, servers, and the network.

 

This objective helps you examine the disaster recovery strategies that exist to support the current network infrastructure. You will need to consider these strategies and determine whether they are sufficient for the existing infrastructure as well as for the new network infrastructure design.

 

It would be a good idea to get a solid grounding in 365 and Intune first though:

https://docs.microsoft.com/en-us/learn/certifications/microsoft-365-fundamentals/

https://docs.microsoft.com/en-gb/learn/paths/manage-enterprise-deployment-m365/

https://docs.microsoft.com/en-gb/learn/paths/defender-endpoint-fundamentals/

https://docs.microsoft.com/en-gb/learn/paths/m365-information-protection/

 

While compiling that list (I need to update the training materials for my own team, so excuse me if I'm deep diving this a bit) I found this which, at a quick glance, appears to cover similar ground that old course: https://docs.microsoft.com/en-gb/learn/paths/m365-service-adoption/

 

As for a simple reciepe to success my gut feeling is that you should bring in old devices as BYOD and mostly "untrusted" you can run with that model for a year or two as you get expertise with intune and 365 and conditional access. While you are doing that, new computers for those that don't need admin can be centrally managed and secured (Intune/autopilot/defender). Once you are really good with conditional access and security, you can then offer fully managed devices (where users read and sign an AUP) *and* allow people local admin.

Edited by psydii
Posted

We're looking to do something along the lines of what Roberto suggests. The imperfect analogy used when we're discussing it with non-IT people is internet banking. The bank doesn't care much what state your device is in, you can access the data that you're authorised to see, any processing happens on their infrastructure.

 

We'll have some devices - admin and teaching networks - that are standardised, but expect that mostly people will choose their own devices and manage them. We'll focus on securing or networks and systems. All proposals at the minute, but definitely looks like where we're heading.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...