Jump to content

Recommended Posts

Posted

Hi All,

 

Happy Star Trek day, Nanu Nanu and all that...

 

I've decided to put my thoughts onto paper about InTune policies with the hope we can get a good 'vanilla' thread going.

 

I've decided to approach InTune from a fresh slate, so as to make it easier.

 

So far I have;

 

* Blocked the ability for anyone except O365 admins to join AzureAD

* Created a USB stick with a default profile using the 'setup schools PC app'

-This will join a factory device to Intune/azure and allow basic login

* Setup two groups, Staff Intune Devices and Student Intune Devices for policy creation.

 

All Devices -

* Bitlocker as standard

* Branding

* MAK key for W10/11

* Windows Update policies (may need clarification on this one)

*GMT time zone (this was a weird one)

 

Extra Student Restrictions -

* No access to settings or control panel

* No access to C: drive or local storage

 

I've also got a few apps that try to deploy but seem to fail.

 

Has anyone else gone this route? Is there some basics I'm missing - I'm trying to keep this as simple as possible RE depoyment and maintenance.

  • Thanks 1
Posted

Currently running a hybrid environment at the moment but shifting over to intune more and more every day. Currently use just intune to manage all laptops in the school and also the pc in each classroom. Currently use the hybrid for the office machines and for the IT suite as using some old software that I cannot get to deploy over intune yet (work in progress) so deploy them over GPO.

 

Currently have a lot of what you have already stated setup and working.

For windows update policies it all works through "Update Rings". There is a lot less control than WSUS from what I have experienced but you can step things like version upgrades (e.g. W10 to W11) from happening automatically and you can also setup groups to allow these through for testing etc. I believe you can set a delay on updates being downloaded in days so you can hold all updates back a period of time if you are worried about issues they could cause.

 

For student restrictions I have managed to build a lot of the settings I had in Group Policy in Intune and it is working really well. My restrictions are quite a few in number due to issues that have happened over the years and I have been able to maintain that level of restriction when moving over to Intune.

 

As for apps, I have a very hit and miss experience as I am still learning this myself. I tend to look to install through the Microsoft Store if possible as I have never had an issue with deploying from there. For programs that aren't on the store, there are tools that can help package apps for Intune (This might help if you haven't seen it before: Prepare a Win32 app to be uploaded to Microsoft Intune | Microsoft Docs).

 

I hope some of that helps, I am still fairly new to it myself but have been building it gradually for the last 2 years now.

Posted

We are currently Hybrid too we are now pushing more over from GPO.

 

We now do pretty much all our Apps through intune including PaperCut Deploy App to deploy our Follow You Printer.

 

With Policies we've moved a lot of our Computer Configuration GPO's over as they apply at device level but have also activated the "MDM wins over GPO" setting so GPO is there as a fallback. The issue we found is a lot of our devices can be logged into by either staff or students and the user level policies seem to take an amount of time to apply through intune vs group policy where it applies on login so it's just not reliable enough for us yet to do user level.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...