Jump to content

Recommended Posts

Posted (edited)

Hi all new job at a new site and I can see we have the 365 A1 package which is currently supplied to the school by BTLancs.

 

They have a server on prem which I would love nothing more than to get rid of but could use some assistance. I have an Admin capable login for the 365 tenant and can see all the features Azure, SharePoint etc.

 

I have created a SharePoint Teams site called "Pupil Data" as a general data drive for students. I have taken a vanilla Windows 10 laptop and joined it to the azure domain by logging on as a student. At this point it asked the student to make a PIN to get a code on a mobile like 2FA is on. I have typed it in on Google and it says that it is an Intune thing? Not used Intune yet but it looks like an MDM for the site BUT i think it is there but not usable as part of the Students A1 Education licensing.

 

My main questions are...

 

Do you all use InTune with this setup? and is that what I need to knock off the questions about setting a PIN or do you do it differently?

 

Also, I wonder how you can make it so the pupil automatically sync's the SharePoint and is automatically signed into the OneDrive after login as the students move around on different laptops.

 

Any thoughts and suggestions are great!

Edited by cheekycharly
Posted

Azure AD and Intune can be a little blurred in some places

 

head over to endpoint.Microsoft.com, Devices, Enroll Device, Windows and check out the Hello For Business settings, thats the prompt for a pin (would be Face ID type thing on a fancier laptop)

Posted

Hi Chaplic, thanks for the reply.

 

I had a look over in that location and it just says "No access" and references Intune below which I am pretty sure is something we don't get as part of our free Education A1 subscription. Should it show more than this?

 

Enroll Windows.jpg

Posted

InTune itself does not come with the A1 level licence, its normally only with A3 or higher (or you can get an add on like the A3 EM&S which also covers it)

You will have access to endpoint site as any hybrid or AD registered devices will show in it, but you are limited with what you can do.

Posted
Azure AD and Intune can be a little blurred in some places

 

head over to endpoint.Microsoft.com, Devices, Enroll Device, Windows and check out the Hello For Business settings, thats the prompt for a pin (would be Face ID type thing on a fancier laptop)

Thread hijack:

 

Does this imply that to enable Windows Hello for hybrid AAD joined devices I need to change settings in the 365 tenancy rather than GPO on the domain controller?

 

We've just acquired our first set of laptops with fingerprint readers!

Posted
Hi Chaplic, thanks for the reply.

 

I had a look over in that location and it just says "No access" and references Intune below which I am pretty sure is something we don't get as part of our free Education A1 subscription. Should it show more than this?

 

[ATTACH=CONFIG]67216[/ATTACH]

I hate MS licensing. Note just the cost but the complexity… I would be tempted to buy 1 azure ad P1 license (or even a trial sub with it) and see what opens up..

Posted
Thread hijack:

 

Does this imply that to enable Windows Hello for hybrid AAD joined devices I need to change settings in the 365 tenancy rather than GPO on the domain controller?

 

We've just acquired our first set of laptops with fingerprint readers!

 

 

No, well not quite. If your DCs are new enough you’ll want to setup the key trust model. Although there’s a new way to do something like it that’s pretty straightforward but seems badly documented

 

https://dirteam.com/sander/2022/09/16/why-everyones-talking-about-hybrid-cloud-trust/

  • Thanks 1
Posted

So the educational "Azure Active Directory for 365" that comes with the educational licensing isn't enough to become serverless and cloud only and you would need to pay the £5.18 per user per month to get the Azure P1?

 

Does that come with InTune for that price or is that still a separate license. That P1 license would cost the school roughly £4500 a year pricing it out. *YIKES*

Posted
So the educational "Azure Active Directory for 365" that comes with the educational licensing isn't enough to become serverless and cloud only and you would need to pay the £5.18 per user per month to get the Azure P1?

 

Does that come with InTune for that price or is that still a separate license. That P1 license would cost the school roughly £4500 a year pricing it out. *YIKES*

Get it via a reseller much cheaper on OVES/EES or CPS. You can get P1 and Intune in a security pack if I remember right.
Posted
So the educational "Azure Active Directory for 365" that comes with the educational licensing isn't enough to become serverless and cloud only and you would need to pay the £5.18 per user per month to get the Azure P1?

 

Does that come with InTune for that price or is that still a separate license. That P1 license would cost the school roughly £4500 a year pricing it out. *YIKES*

 

Educational CSP pricing for "Azure Active Directory Premium P1 for Faculty" is 39p per month per user.

Posted
Educational CSP pricing for "Azure Active Directory Premium P1 for Faculty" is 39p per month per user.

 

 

Now i'm excited JB! How did you come across that information? Are you a reseller or currently running schools and know the price as you pay it?

 

Everything on Google states huge prices and still doesn't tell me if P1 includes InTune or if that is again separate. Is it just me or is licensing a PITA when your in the dark and don't have an MSP to contact.

Posted

Your Microsoft Licence supplier should have been able to provide you with those prices, as assuming you use Windows Servers/Office on site you should have some form of an Educational Licence scheme in place be it OVS-EES, Select etc.

Prices on the web are generally business or public pricing and not educational.

Posted

Our suppliers company shutdown and sold up so i'm picking up the pieces and scoping things out. Hence why I would rather push all logons to use azure and move data to a SharePoint then somehow do the following..

 

Make it so pupils can roam from laptop to laptop.

Restrict access i.e. stops kids doing a "reset" or accessing the MSStore and downloading a VPN etc.

Have it also so when they log on Onedrive is automatically logged in and the SharePoint site they have access to is available without manually going to the site and clicking "sync".

 

 

Anyone know if any of those things are achievable

Posted
Now i'm excited JB! How did you come across that information? Are you a reseller or currently running schools and know the price as you pay it?

 

Everything on Google states huge prices and still doesn't tell me if P1 includes InTune or if that is again separate. Is it just me or is licensing a PITA when your in the dark and don't have an MSP to contact.

 

I'm at a MAT, that is the list price showing on our CSP's licencing portal. Yes clear as mud for all of this licencing stuff, just for reference a standalone intune licence for faculty is 49p, it costing more suggests to me that it's not included.

Posted (edited)

Here are my suggestions.

 

1) take stock. Dont jump into things.

2) look at what you have, what you pay for, what is licensed already and who your providers are and refresh dates.

3) Have a plan of what you want to do and why. Remember that any changes come with staff training and sometimes issues.

4) Assuming you want to go ahead with removing all onsite you will need azure premium at the least. Do you need a bigger (and redundant) internet connection?

5) I would start with hybrid, then look at first migrating onsite email, then onsite shared files, then onsite documents/home drive. Look at what you are going to do with any "big files" software such as photoshop or CAD or media/video software.

6) BACKUPS! Its all in the cloud now.

7) decommission your file servers then look at how your other services can move to the cloud - printing, MIS, intranet, filters, cleaner clocking in devices, scanners, UPS, finance software, anything else that needs onsite AD credentials.

8) get a cloud MDM sorted, probably intune, and get the GPOs migrated to a cloud version (such as intune configuration profiles). Also look at autopilot for your new devices.

9) once all your local AD dependencies are removed from the system then you can migrate off your AD to AAD completely whether you start with new profiles or not is up to you.

10) you will still need a firewall, DHCP, DNS etc but that can be a small device.

 

I have stopped at "9" as I cannot currently fulfil all of "7".

 

For licensing I recommend John at very-pc. There are others out there of course and im not on commission.

Edited by KK20
  • Thanks 1
Posted
Here are my suggestions.

 

1) take stock. Dont jump into things.

2) look at what you have, what you pay for, what is licensed already and who your providers are and refresh dates.

3) Have a plan of what you want to do and why. Remember that any changes come with staff training and sometimes issues.

4) Assuming you want to go ahead with removing all onsite you will need azure premium at the least. Do you need a bigger (and redundant) internet connection?

5) I would start with hybrid, then look at first migrating onsite email, then onsite shared files, then onsite documents/home drive. Look at what you are going to do with any "big files" software such as photoshop or CAD or media/video software.

6) BACKUPS! Its all in the cloud now.

7) decommission your file servers then look at how your other services can move to the cloud - printing, MIS, intranet, filters, cleaner clocking in devices, scanners, UPS, finance software, anything else that needs onsite AD credentials.

8) get a cloud MDM sorted, probably intune, and get the GPOs migrated to a cloud version (such as intune configuration profiles). Also look at autopilot for your new devices.

9) once all your local AD dependencies are removed from the system then you can migrate off your AD to AAD completely whether you start with new profiles or not is up to you.

10) you will still need a firewall, DHCP, DNS etc but that can be a small device.

 

I have stopped at "8" as I cannot currently fulfil all of "6".

 

For licensing I recommend John at very-pc. There are others out there of course and im not on commission.

 

 

Great itemizing of the different factors KK20. I will run over them with you as I see them currently.

 

1: Current system is two sites with a max of 60pupils over the two sites. Both sites have a DC with AD, FS, DNS, DHCP, GPO with no link between or joined AD's (Running separate). One site has 2012 server R2 and is due replacement and the other is running 2019 and is probably 2years old and does nothing all day but wait for a logon request 3-4times a day.

 

2: Provider has gone down the pan so I will be on the hunt for a reseller who can take it on. The 365 portal I believe is part of their school broadband package with BT Lancs who do the following services for the school... Netsweeper filtering (Currently relies on GPO to push to relevant groups) Broadband line (Standard FTTC so only 50Mbps with 7-8Up) 365 Tenant with Educational A1 licensing. Last batch of MS Office 2021 Licenses were purchased through another provider who no longer exists. Our current filtering solution does not work for us on a cloud basis so I would be looking for a cloud based filter.

 

3: Aim is to free them of the overhead of a lump sum of money paying out for a new server and merge the two sites under the one cloud system. A third site is also in the picture. Staff are the ones pushing for the ability to login as the email address.

 

4: Currently no FTTP products are available which is a PITA so the speed will be an issue and a second line for fail-over is something I would be looking for. Ideally BT get their finger out in the next twelve months and get an FTTP product available to us so I can have an FTTC as a fail-over.

 

5: Shouldn't need to hybrid with the small amount of users they have and they currently run the 365 email system as a separate entity hence why they would like to login using the email address for ease. Onsite shared files is literally just a pupils share which is about 250GB and could move to a SharePoint site. Home drive data would be moved to individuals one drive accounts. Photoshop is a splinter and may need an onsite 4bay Synology just for saving the ART department data back to.

 

6: Most providers I'm currently looking at offer 365 backups such as Barracuda, PeaSoup, Axcient, Acronis.

 

7: Printing I believe can be moved to cloud platforms - not looked into those yet but I do know I could manually add the three copiers on an Admin local profile and they will be there on the laptop for the pupils when they logon using Azure. MIS, Itranet, Clocking is all on a separate network not managed by the school.

 

8: This post is me fishing for info on MDM via InTune and finding out what it can and cannot do. I know currently our GPO's a very locked down such as no right click no control panel and a custom start menu. I'm not fussed on all of that more as long as pupils cannot do any damage by right clicking then I'm fine with it. The test laptop I joined to the O365 azure tenant wasn't able to go deleting files when logged on as a pupil and was not able to perform admistrative action BUT you could go in the MS Store and download whatever you wanted which I don't want.

 

9: Like i was saying the amount of users here isn't worth the Hybrid and may as well start fresh on the tenant and roll it out bit by bit.

 

10: Options for this are either a Watchguard or just a Draytek 2862.

 

Probably loads of suggestions you guys could make and the more the better and as always your knowledge is appreciated.

Posted (edited)

With sharepoint migration tool it is trivial to uplift an onsite share with permissions to a sharepoint library. The same with onedrive although I did things differently (I had a mapped home drive to onedrive and got the staff to move their own stuff with a deadline and reduced onsite quota). I only say hybrid because that is transparent to the users and you get all the permissions sorted already but its your call of course. This also means you can have hybrid AD joined PCs so you can start migrating your settings from GPO to intune with co-existence rather than having to register each PC too. The big gotcha with hybrid is that you still need to manually remove from domain and autopilot them - however you will need to do this anyway - but with hybrid intune will already have all your devices which can be added to autopilot and profiled accordingly beforehand.

 

The biggest issues with intune are GPOs. Intune is much clunkier than GPO (IMHO), I didnt bother with the GPO migration as almost none of my more complex GPOs would work and needed tweaking. Im probably 50% way through migrating my GPOs to intune. If you rely on gpupdate /force for impatience then be aware that refreshing the intune scheduled task and restarting intunemanagement is nowhere near as quick on the uptake. Software installation in Intune is not bad (ive just pushed an update to a line of business MSI around 5 mins ago and I have a status update with waiting to install on 60% of my machines already). Intune and AAD have no concept of OUs, I created a small program that made AAD groups based on my OUs, then I could set up my intune profiles with a mimicry of the onsite setup - not for everyone but this is my network :) Apart from that ive taken a group policy result of staff and pupils, taken a spreadsheet of the settings and am working down the list creating an intune profile for each one.

 

for intune blocking of store, try this custom OMA-URI /User/Vendor/MSFT/Policy/Config/ApplicationManagement/RequirePrivateStoreOnly with a DWORD of 1 that will lock down teh store app to only show your published MSstore stuff (no idea what this will do when the store shuts down next year)

Edited by KK20
  • Thanks 1
Posted

Anyone know if there is a faculty/education version of these two all in one products I have seen...

 

 

  • Enterprise Mobility + Security E3 includes Azure Active Directory Premium P1, Microsoft Intune, Azure Information Protection P1, Microsoft Advanced Threat Analytics, Azure Rights Management (part of Azure Information Protection) and the Windows Server CAL rights.
  • Enterprise Mobility + Security E5 includes all the capabilities of Enterprise Mobility + Security E3 plus Azure Active Directory Premium (AADP) P2, Azure Information Protection P2, Microsoft Cloud App Security, Azure Active Directory [AD] Identity Protection (as a feature of AADP P2), Azure Advanced Threat Protection, Azure AD Privileged Identity Management (as a feature of AADP P2).

 

If so what do they price at?

Posted
Anyone know if there is a faculty/education version of these two all in one products I have seen...

 

 

  • Enterprise Mobility + Security E3 includes Azure Active Directory Premium P1, Microsoft Intune, Azure Information Protection P1, Microsoft Advanced Threat Analytics, Azure Rights Management (part of Azure Information Protection) and the Windows Server CAL rights.
  • Enterprise Mobility + Security E5 includes all the capabilities of Enterprise Mobility + Security E3 plus Azure Active Directory Premium (AADP) P2, Azure Information Protection P2, Microsoft Cloud App Security, Azure Active Directory [AD] Identity Protection (as a feature of AADP P2), Azure Advanced Threat Protection, Azure AD Privileged Identity Management (as a feature of AADP P2).

 

If so what do they price at?

 

Yes for both.

Enterprise Mobility + Security E3 - £1.28

Enterprise Mobility + Security E5 - £2.14

 

I recommend selecting a CSP for your O365 tenant then you can browse these as much as you want. There is no commitment required to do this and you don't have to provide them with any level of access.

  • Thanks 1
Posted
We've just changed from our old OVS licencing to EES via the Chest agreement (which reduces the minimum EQU staff requirement) and get Enterprise Mobility + Security E3 as part of our Office 365 A3 for faculty licence. We now also have Intune, conditional MFA etc, but still keep the benefit of OVS licencing in terms of the desktops and Office Pro. Horrendously complicated to understand but I used Pugh Computers following other recommendations here, one of the suppliers on the framework who were very helpful at understanding it all. We actually saved £1500 per year as against our old OVS licence.
  • Thanks 1
Posted
So I guess I just register on here?

 

https://partner.microsoft.com/en-gb/licensing

 

And what will this do link to our Tenant that we have and allow us to look at pricing direct from M$ rather than through a 3rd party supplier?

 

That is for becoming a CSP i think.

 

On your O365 admin look in Settings->Partner relationships. There is a huge list but you should see some familiar names that are big in the education sector. You will need to attach them to your tenant, then when you purchase licences via their portal/sales team they will appear in your usual licence section on O365 admin and can be assigned as normal.

Posted

Shows 2 Partners in mine.

 

1. the Indirect-Reseller that no longer exists but apparently has Global Admin access and then...

 

2. Westcoast Cloud CSP - Reseller.

 

Both of which were linked as I think Westcoast was the now bust Indirect-Resellers supplier.

 

I Guess i'm in the water for a new reseller? Currently more bothered about the level of access they have. If I bin them off does it remove the license cals we bought from them or are they part of the account at that point?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...