Jump to content

Recommended Posts

Posted

Hi

 

We are moving windows 10 devices away from On-prem AD to 365 and Intune only in the summer and we are also moving all users to the Microsoft 365 Edu A3 licences also. How do i activate windows clients using Intune now we're moving away from on-prem KMS? I think I read somewhere that there may be no need to activate as users will have the M365 A3 licence? or would i have to active each windows 10 client using Intune?

 

Thanks

Posted
It probably depends on how you’re configuring the devices ? If youre setting up windows autopilot with intune / (Microsoft Endpoint Manager) , then in theory you can setup zero touch deployment with devices ready straight out of the box. Provided the user has a w10/11 license (and it looks like they will with A3 - https://www.microsoftpartnercommunity.com/atvwr79957/attachments/atvwr79957/CEEReadiness/30/1/Education%20Licensing%20online%20training%20for%20CEE%20Partners_April%202021.pdf) the device should get activation through the user . I seem to remember that there are some really odd things about Intune and how it associates devices with users though and certain fields which you couldn’t change without refreshing devices. I think there used to be certain things that you couldn’t do with a devices based rather than user based - https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/microsoft-intune-announces-device-only-subscription-for-shared/ba-p/280817 . Not sure if this is still the case. I’d probably have a think about the lifecycle of the devices and how they are allocated to users. For application deployments- there are some really clever things you can do with dynamic user and device groups in Azure. You can set groups to automatically populate members based on license assignments. You can then use these groups in intune to automatically deploy your applications etc. you can have them appear silently or within the intune company portal. Intune is also getting more and more GPO style config options all the time. I think there used to be a GPO readiness thing, that you could evaluate your existing GPOs against to see if you could achieve the same thing through intune. Most of the things I wanted were there , ie configuration of bitlocker with key writeback. Get a test device and go through the user setup, license configuration on Azure, then device onboarding and retirement process.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...