Jump to content

Recommended Posts

Posted

We are a cloud only environment using M365 and effectively no other apps. We have no onsite servers. We have a couple of scenarios that I'd be interested in how you manage or how you would *like* to manage. We have an outsourced 'IT department' that is effectively remote only managed.

 

i) a new laptop is purchased. How would you bring the laptop in to the controlled environment such that the remote management agent (ConnectWise Automate) and Sophos AV is installed?

ii) a laptop for a leaver is passed to another new user - how do you handle this?

 

For ii), do you have laptops assigned to just a single user requiring a degree of reconfiguration to switch to a new user?

 

What's the current method for what I recall as roaming profiles, but I believe is now out of legacy technique, in a cloud based environment. Are there concerns about data risks with documents stored on the desktop or root of c: drive for shared device use, or is that restricted.

 

Hope the questions make sense, but I'm happy to clarify as best I can if you need that.

Posted (edited)
We are a cloud only environment using M365 and effectively no other apps. We have no onsite servers. We have a couple of scenarios that I'd be interested in how you manage or how you would *like* to manage. We have an outsourced 'IT department' that is effectively remote only managed.

 

i) a new laptop is purchased. How would you bring the laptop in to the controlled environment such that the remote management agent (ConnectWise Automate) and Sophos AV is installed?

ii) a laptop for a leaver is passed to another new user - how do you handle this?

 

For ii), do you have laptops assigned to just a single user requiring a degree of reconfiguration to switch to a new user?

 

What's the current method for what I recall as roaming profiles, but I believe is now out of legacy technique, in a cloud based environment. Are there concerns about data risks with documents stored on the desktop or root of c: drive for shared device use, or is that restricted.

 

Hope the questions make sense, but I'm happy to clarify as best I can if you need that.

 

Using InTune/Endpoint Manager to manage these devices would help. For the autonomous new laptop you can configure Autopilot...user opens the box and logs in and all your config profiles/apps etc will download and install.

We've set up all devices in InTune/Endpoint Manager to be used by anybody, so when a machine is passed to a new user we only have to update our inventory.

You can configure the laptops to auto encrypt so data on the device is kept safe, and you can set up auto OneDrive syncing for files (including those on the desktop).

We only use local profiles on devices with a script to delete any profiles that haven't been used in 60 days to keep the devices clean.

Edited by EssentialRug
  • Thanks 1
Posted
Using InTune/Endpoint Manager to manage these devices would help. For the autonomous new laptop you can configure Autopilot...user opens the box and logs in and all your config profiles/apps etc will download and install.

We've set up all devices in InTune/Endpoint Manager to be used by anybody, so when a machine is passed to a new user we only have to update our inventory.

You can configure the laptops to auto encrypt so data on the device is kept safe, and you can set up auto OneDrive syncing for files (including those on the desktop).

We only use local profiles on devices with a script to delete any profiles that haven't been used in 60 days to keep the devices clean.

I know InTune is in use, and there is a project quoted for us to be moved to that being used, but the quote is in the thousands so maybe for another day. I believe the EndPoint manager will enable them to more easily manage the things you mention like encryption, synching, etc. but the haven't really done a good job at explaining the benefits yet.

 

For the autonomous scenario, what steps need to happen locally to get that started? Onsite, we don't really have any IT people, but our provider isn't really fulfilling the role of our 'IT Department' (their terminology) for anything that isn't remote. We can get hardware sent to them for setting up, but they want to bill delivery, insurance, setup and could end up effectively adding 50% to the laptop device cost.

Posted

We’ll you need skills somewhere, so either buy them or learn them. the notion of ‘building’ a laptop is dead. You don’t ‘build’ a smartphone, a PC today is the same

The gold standard would be you buy a laptop from dell, you tell them your tenant ID and essentially the machine IDs are bound to you. You get machine, turn on, software you defined in intune gets deployed.

 

Or the same but manually updating their serial numbers in Azure AD portal

Or the same just allowing any machine to join your tenant and be managed

 

 

Devil is in the detail of course, but properly set-up you need zero touch from IT for a new laptop.

  • Thanks 1
Posted (edited)

We are moving to a leasing model academic year 2023/24, we will still be hybrid so although we are using autopilot, a domain visibility will still be needed for us for the time being. Serverless is looking like 24/25

 

i) a new laptop is purchased. How would you bring the laptop in to the controlled environment such that the remote management agent (ConnectWise Automate) and Sophos AV is installed?

The leasing company know our tenant and the computer ID appears in autopilot. I assign a profile to it. User gets given the laptop IN SCHOOL and it sets itself up using intune configuration policies. We are hybrid so the device needs to see our onsite domain controller. In the future it wont when we arent hybrid. Intune sorts out the software and all the necessary locking down, certificates, universal printer settings, etc etc

 

ii) a laptop for a leaver is passed to another new user - how do you handle this?

I hit wipe on the laptop in intune and the process starts again from above. The same if the device is lost, sold, broken, returned to lease company etc.

 

here is another scenario:

I have a hard drive failure on a device that isnt leased but it owned by us. I use OSDcloud to get OS and autopilot profile up and running. Then we are back to (1)

Edited by KK20
  • Thanks 1
Posted (edited)
We are moving to a leasing model academic year 2023/24, we will still be hybrid so although we are using autopilot, a domain visibility will still be needed for us for the time being. Serverless is looking like 24/25

 

i) a new laptop is purchased. How would you bring the laptop in to the controlled environment such that the remote management agent (ConnectWise Automate) and Sophos AV is installed?

The leasing company know our tenant and the computer ID appears in autopilot. I assign a profile to it. User gets given the laptop IN SCHOOL and it sets itself up using intune configuration policies. We are hybrid so the device needs to see our onsite domain controller. In the future it wont when we arent hybrid. Intune sorts out the software and all the necessary locking down, certificates, universal printer settings, etc etc

 

ii) a laptop for a leaver is passed to another new user - how do you handle this?

I hit wipe on the laptop in intune and the process starts again from above. The same if the device is lost, sold, broken, returned to lease company etc.

 

here is another scenario:

I have a hard drive failure on a device that isnt leased but it owned by us. I use OSDcloud to get OS and autopilot profile up and running. Then we are back to (1)

 

If the HDD fails you reinstall windows and then provision with Intune.

 

You can wipe the device with Intune as well as start over and other options.

Edited by nicholab
Posted
We’ll you need skills somewhere, so either buy them or learn them. the notion of ‘building’ a laptop is dead. You don’t ‘build’ a smartphone, a PC today is the same

The gold standard would be you buy a laptop from dell, you tell them your tenant ID and essentially the machine IDs are bound to you. You get machine, turn on, software you defined in intune gets deployed.

 

Or the same but manually updating their serial numbers in Azure AD portal

Or the same just allowing any machine to join your tenant and be managed

 

 

Devil is in the detail of course, but properly set-up you need zero touch from IT for a new laptop.

In terms of skills, we thought we had bought them but are feeling is we are being asked to buy them buy them again, from our IT supplier who sold themselves as our 'IT Department'!

To be frank, their promise of being our 'IT department' isn't quite living up to the pitch. So, I'm supporting my manager who is non techie to get a balance between convenience and excessive additional charges from our IT provider. I'd be interested to understand a little more about telling Dell about our tenant ID and have them do that piece. Irritatingly, our provider say they can't buy from Dell on our behalf and get the charity discounts. So, we are looking at having look at sourcing them ourselves, defeating our goal of a one stop shop.

 

I share the vision of once on, it gets 'managed'. They want to move us to Endpoint Manager at great expense, but I know they are already using Intune and Automate, so I still think it shouldn't be a big deal. In terms of apps, all we need is a M 365 desktop apps installed plus Sophos Intercept X which seems to need a planned push install but we have done that with a cluster of devices in the recent past (at again extra cost).

Posted
If the HDD fails you reinstall windows and then provision with Intune.

 

You can wipe the device with Intune as well as start over and other options.

 

 

yes. Use OSDcloud to get OS and autopilot profile up and running, no faffing with latest ISO or drivers, OSDcloud sorts it all from a lightweight WinPE. If there is nothing on the drive you need to get an OS on the machine, then the autopilot profile. OSDCloud is automated, you boot off a USB stick and away it goes. Of course there are other methods, I prefer automated ones.

  • Thanks 1
Posted

I would expect your IT provider is providing a steady-state ongoing management service unless you have some sort of innovation or technical currency baked into the contract. My story is a little convoluted, but the previous incumbent rocked up for 2 hours every 2 weeks and fixed issues and took a CD from laptop to laptop to install software (this was about 7 years ago). Maybe the school didn’t know there was anything better, but as an IT pro I’d be embarrassed to be doing that.

 

 

Just looked on the dell website as at a latitude, bit buried in the options but autopilot is there, think Lenovo have it too.

 

It does take skill and effort to get it up-and-running well, but when it’s it in Ive found it zero drama; my effort on PC admin is practically zero; keep an eye on compliance stuff, patches and push out new versions of windows now-and-again, that’s about it. I should note it is in my interest to automate and put myself out of a job, others may not have the same view..

Posted
We’ll you need skills somewhere, so either buy them or learn them. [\QUOTE]

 

Is there any course out there, teach you everything about intune/endpoint manager?

Posted

There's a couple of books out there too... my advice would be get yourself a test tenant setup (free) and spin up a few VMs. If you are comfortable with AD, GPOs and so on this will be 'WTF' for a while as there is practically zero carry-through knowledge.

 

Also have in the back of your mind anything written down could be out of date. Cloud trust is a very cool solution but brand spanking new.

Posted
I would expect your IT provider is providing a steady-state ongoing management service unless you have some sort of innovation or technical currency baked into the contract. My story is a little convoluted, but the previous incumbent rocked up for 2 hours every 2 weeks and fixed issues and took a CD from laptop to laptop to install software (this was about 7 years ago). Maybe the school didn’t know there was anything better, but as an IT pro I’d be embarrassed to be doing that.

 

Just looked on the dell website as at a latitude, bit buried in the options but autopilot is there, think Lenovo have it too.

 

It does take skill and effort to get it up-and-running well, but when it’s it in I've found it zero drama; my effort on PC admin is practically zero; keep an eye on compliance stuff, patches and push out new versions of windows now-and-again, that’s about it. I should note it is in my interest to automate and put myself out of a job, others may not have the same view..

I think you have nailed it with the statement 'steady-state ongoing management service'. In terms of 'technical currency baked into the contract', we get 1 day per quarter from someone who I'd say is the equivalent of a network manager plus some systems skills - baked in, but charged though.

 

Today we had the installation person in a meeting today to explain how they manage a new device coming on-board, but also a device switching to another. Literally, we have 365 Office desktop apps to install and maybe Chrome and Adobe Reader, which we learnt are policy driver (Intune I guess?). We asked about the shared laptops as we have a few. They effectively said it should be one device per user. I said that kills the concept of hot-desking. The talked about profiles chewing space. I asked if they make use of UE-V - I got the impression they had no idea what that was. So ultimately for a new device, the ask the end-user to WiFi login, ring them up, go to their website and click on a link - they link is for LogMeIn. They then take-over and complete the setup. But, in my mind Office desktop Apps, AV, Chrome, Windows updates, Adobe reader should all auto-install once linked to the tenant. So, the justification for the so called 'Bronze' install at £100 a pop, is to check it's all working - perhaps harshly from my POV, it feels like they are billing us in case their device management doesn't work!

 

So, our vision of a zero-touch new device being given to an end user, well it's not be some margin. Am I expecting too much?

 

Oh, and one more thing, whilst looking at my device, I noticed it had the profile for our old IT provider, and a colleague had one for the provider before that. Yeah, they can get rid of from all devices, made it sound like a significant task an said it'll be another chargeable task. In my mind it should have being picked up on at the onboarding stage.

Posted (edited)
I think you have nailed it with the statement 'steady-state ongoing management service'. In terms of 'technical currency baked into the contract', we get 1 day per quarter from someone who I'd say is the equivalent of a network manager plus some systems skills - baked in, but charged though.

 

Today we had the installation person in a meeting today to explain how they manage a new device coming on-board, but also a device switching to another. Literally, we have 365 Office desktop apps to install and maybe Chrome and Adobe Reader, which we learnt are policy driver (Intune I guess?). We asked about the shared laptops as we have a few. They effectively said it should be one device per user. I said that kills the concept of hot-desking. The talked about profiles chewing space. I asked if they make use of UE-V - I got the impression they had no idea what that was. So ultimately for a new device, the ask the end-user to WiFi login, ring them up, go to their website and click on a link - they link is for LogMeIn. They then take-over and complete the setup. But, in my mind Office desktop Apps, AV, Chrome, Windows updates, Adobe reader should all auto-install once linked to the tenant. So, the justification for the so called 'Bronze' install at £100 a pop, is to check it's all working - perhaps harshly from my POV, it feels like they are billing us in case their device management doesn't work!

 

So, our vision of a zero-touch new device being given to an end user, well it's not be some margin. Am I expecting too much?

 

Oh, and one more thing, whilst looking at my device, I noticed it had the profile for our old IT provider, and a colleague had one for the provider before that. Yeah, they can get rid of from all devices, made it sound like a significant task an said it'll be another chargeable task. In my mind it should have being picked up on at the onboarding stage.

 

Hot desking and roaming can be a PITA, you can tell where Microsofts only real customer is theirself and they dont put so much energy into it if they dont use it, but of course many of here will testify it's doable. I have seen a place that uses UE-V and puts the config for it inside onedrive which worked pretty well.

 

In terms of new laptops I still get hold of them first to do first-time-setup, if only because I do it on a normal internet connection (the intune policy pulls down the inspection certificates and proxy settings and its a faff to do that during autopilot). But assuming the laptop is new this is basically just signing into it, adding an asset tag and then renaming the device to the asset tag - the effort to 100% hands off wasnt worth the time. I also add the device to a 'all teachers' or 'all pupils' device group. Intune then kicks in and applies policy to deploy software and settings. Laptop handed to teacher, they login and everything is there, azure ad stores various profile stuff, mydocs redirected to onedrive a couple of teams file areas are synced to the device simliar to a network drive. Intune can refresh the device or if SSD dies it's rebuild from a win10 ISO and go from there. The school has taken on about half a dozen staff recently and input from IT has been zero.

 

Do your staff also have local admin rights on their PC?

 

I can see the argument for a 'white gloves' service on every new laptop setup, but this does not appear to be it. I'm also reticent to criticise service providers as there is often two sides, but on the surface of it this is pretty poor. 100 bucks for such and engagement is probably fair, but this is a 'wouldn't start from here' type problem.

 

I think in your 1 day per quarter you challenge them to deliver you a solution where a user logs into the laptop for the first time and the standard suite of apps and settings is automatically delivered to them, minus any annoying first-run popups and removing the need for any manual configurations that can be automated, then for that being maintainable going forward. It's not a one-day piece of work but at least you can gauge the appetite for it and the understanding. Business case for doing it properly would be the amount of £100 setups you've done in the last couple of years..

Edited by chaplic
Posted (edited)
We asked about the shared laptops as we have a few. They effectively said it should be one device per user. I said that kills the concept of hot-desking. The talked about profiles chewing space. I asked if they make use of UE-V - I got the impression they had no idea what that was.

 

Autopilot self deployment profile for the shared device (as there will be no primary user). then a configuration profile in intune set up for shared multi user enabling shared PC mode and probably locking down guest mode so you need an azure account to log in. Thats about it really. Ive not looked at any sort of roaming at the moment though, our users are used to mandatory profiles so this is not an issue for us. I am looking at enterprise state roaming as a potential solution, this is the "new" UE-V I believe but im some way off that yet.

 

One gotcha with this approach is to delete the device before repurposing with self deployment https://learn.microsoft.com/en-us/mem/autopilot/known-issues

Edited by KK20

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...