m0bov Posted April 4, 2023 Posted April 4, 2023 Hi all, I have seen a few other threads about this. We are using A1 at the moment on OVS, but we are using a lot of InTune now and want P1 Azure for online password changes. We also want RMS on Sharepoint. We have a choice of either staying on OVS and adding in the extra (EMS) to get what we want. Or sign up with Chest and go for the full A3 under a Campus agreement. I've been told that if we go for Campus, we can't access windows licenses keys for desktops, we need to use the license the machines come with (BIOS activated). We do buy machines with a Pro license anyway. The Campus is quite a bit cheaper. Any pit falls to doing this? How long does it take to get the Chest and Campus agreement up and running? Really appreciate any feedback from those that have done this before. Thanks!
Steve21 Posted April 4, 2023 Posted April 4, 2023 That’s not right regarding the KMS keys, as I raised that at my previous work place when we changed to EES and we got them enabled on it, so that’s an easy win on that side Regarding time, it took a little longer than a standard renewal as you have to do the chest and then the renewal as two orders (or at least we did), but nothing to worry about really as there’s overlap built into the expiry dates Steve
m0bov Posted April 4, 2023 Author Posted April 4, 2023 Thanks for the feedback Steve. So you still get access to the MS license portal for ISOs and keys as usual?
sister_annex Posted April 4, 2023 Posted April 4, 2023 So you still get access to the MS license portal for ISOs and keys as usual? They've moved most of it to the M365 Admin Portal now, but yes, in our case, when we moved to EES we retained access to our keys etc.
DavR Posted April 4, 2023 Posted April 4, 2023 Bear in mind if you go for M365 A3, that won't cover any onsite servers. We were weighing up OVS vs A3 for our recent renewal, and stuck with OVS, adding AAD P1 as an extra for things like conditional MFA and password writeback. It was the server licensing that swung it for us, as those were licensed through the existing OVS and would have cost a lot to buy out.
Steve21 Posted April 4, 2023 Posted April 4, 2023 Bear in mind if you go for M365 A3, that won't cover any onsite servers. We were weighing up OVS vs A3 for our recent renewal, and stuck with OVS, adding AAD P1 as an extra for things like conditional MFA and password writeback. It was the server licensing that swung it for us, as those were licensed through the existing OVS and would have cost a lot to buy out. EES can still have additional products added in like windows server, so no requirement to buy it out Unless you mean CSP wise? Steve
timbo343 Posted April 4, 2023 Posted April 4, 2023 We are looking at the A3 EES license for our Trust moving away from OVS. One thing to bear in mind is the new EQU (aka what used to be FTE). You'll find those that aren't classified as an EQU (aka a "lite user") don't get access to 2FA so youbhave to buy the P1 license to license those "lite users". In my mind this is a bit of a "shoot your self in the foot" moment especially when we are being askednto enable 2FA to emails as default.
Steve21 Posted April 4, 2023 Posted April 4, 2023 We are looking at the A3 EES license for our Trust moving away from OVS. One thing to bear in mind is the new EQU (aka what used to be FTE). You'll find those that aren't classified as an EQU (aka a "lite user") don't get access to 2FA so youbhave to buy the P1 license to license those "lite users". In my mind this is a bit of a "shoot your self in the foot" moment especially when we are being askednto enable 2FA to emails as default. Who are you defining as a light user? As we basically found no-one in the Trust that fell under that category really (apart for external guests etc who wouldn’t need 2fa etc) Steve
DavR Posted April 4, 2023 Posted April 4, 2023 EES can still have additional products added in like windows server, so no requirement to buy it out Unless you mean CSP wise? Steve We were too small for EES, so had the option of a new OVS, or buying into M365 as a separate item, which wouldn't have covered our servers.
Steve21 Posted April 4, 2023 Posted April 4, 2023 We were too small for EES, so had the option of a new OVS, or buying into M365 as a separate item, which wouldn't have covered our servers. Not sure if you know (appreciate some schools are smaller), but EES is only 100 users under chest agreements rather than 1000, so generally most secondaries would be able to Obviously an issue for primaries etc as you said Steve
m0bov Posted April 4, 2023 Author Posted April 4, 2023 Hi, Our supplier added the server and SQL licenses, remote desktop/RDP etc... so that's all good. What about using SCCM and imagining? I hear we can't use volume keys/KMS to activate? Is there any issue with how we deploy machines and a new license agreement? Thanks!
DavR Posted April 4, 2023 Posted April 4, 2023 What about using SCCM and imagining? I hear we can't use volume keys/KMS to activate? Is there any issue with how we deploy machines and a new license agreement? In theory you should be relying on the BIOS-embedded Windows 10 license key for reinstalling machines. Anecdotally though, I know people have had success getting a limited MAK key from Microsoft support to cover those devices which didn't come with a BIOS license. Not sure if they'll go as far as KMS keys, but probably depends on how hard you argue.
timbo343 Posted April 4, 2023 Posted April 4, 2023 Who are you defining as a light user? As we basically found no-one in the Trust that fell under that category really (apart for external guests etc who wouldn’t need 2fa etc) Steve I suppose we are different as we are predominantly Google so our emails and files are mainly in Google but if if users have more than one mailbox to check, this is where this falls over. For example, a finance mailbox or a HR mailbox. I've not used MS Exchange for a few years but would you need to 2FA shared mailboxes?
Mr.Ben Posted April 4, 2023 Posted April 4, 2023 Who are you defining as a light user? As we basically found no-one in the Trust that fell under that category really (apart for external guests etc who wouldn’t need 2fa etc) SteveAs a primary only Trust we found lots of light users - Lunch time assistants, Keyholders, non specialist TA's and governors - we bought Intune and Azure P1 for them.
Mr.Ben Posted April 4, 2023 Posted April 4, 2023 I suppose we are different as we are predominantly Google so our emails and files are mainly in Google but if if users have more than one mailbox to check, this is where this falls over. For example, a finance mailbox or a HR mailbox. I've not used MS Exchange for a few years but would you need to 2FA shared mailboxes?In the O365 world shared mailboxes don't need a licence and don't have a username/password. We do have some 'shared' mailboxes that require a login (and 2FA) to send mail (from printers etc), but with have limited these to a handful.
Steve21 Posted April 4, 2023 Posted April 4, 2023 As a primary only Trust we found lots of light users - Lunch time assistants, Keyholders, non specialist TA's and governors - we bought Intune and Azure P1 for them. All of those would fall under EQU based on MS descriptions “Any employee or contractor (except Students) who accesses or uses an Education Platform Product for the benefit of the Institution” which they all would be I thought? (I know some resellers word it different but MS don’t seem to agree) Then you’d start running into further issues if you’re counting them like that, as they wouldn’t be covered for CALs/Windows licenses etc either regarding your Intune comment (assuming that’s for logging into school devices?) Steve 1
Mr.Ben Posted April 4, 2023 Posted April 4, 2023 (edited) All of those would fall under EQU based on MS descriptions “Any employee or contractor (except Students) who accesses or uses an Education Platform Product for the benefit of the Institution” which they all would be I thought? (I know some resellers word it different but MS don’t seem to agree) Then you’d start running into further issues if you’re counting them like that, as they wouldn’t be covered for CALs/Windows licenses etc either regarding your Intune comment (assuming that’s for logging into school devices?) SteveThe whole thing has been approved by MS for us after some length discussion through the reseller (who were not particularly useful) I find it easier to use MS's inconsistent documents against them sometimes! This document for resellers (the latest one to date) is my current go to. https://www.microsoftpartnercommunity.com/atvwr79957/attachments/atvwr79957/CEEReadiness/30/1/Education%2520Licensing%2520online%2520training%2520for%2520CEE%2520Partners_April%25202021.pdf Specifically slides/pages 17-21 EQU is anyone using an A3 or A5 product. If I don't assign them a licence, they are not an EQU. These non EQU users are covered to use windows as long as they don't use a device for more than 50% of their work day (which none do!) 'Windows may be installed on shared devices, such as kiosks or lecture hall computers, for use by infrequent users like janitors or café workers' Most of our non EQU users are using personal devices to access email and SharePoint docs read only. We buy P1 and Intune for security for these users because I don't want a scenario where we can't manage BYOD policies and compliance and for conditional access. Edited April 4, 2023 by Mr.Ben 1
Steve21 Posted April 4, 2023 Posted April 4, 2023 Specifically slides/pages 17-21 Do you have anything from MS that says that email wise etc? It just seems we read that differently, as that's the same document I've discussed with them EQU is anyone using an A3 or A5 product. If I don't assign them a licence, they are not an EQU. -> I agree that if you're using an A3/5 product it counts (but remember it includes all aspects of A3/5, not just an assigned license, which includes Windows/CALs/Office etc) These non EQU users are covered to use windows as long as they don't use a device for more than 50% of their work day (which none do!) -> This seems to be clashing two rules into one. A shared device is something used under 50% by one person yes "however" if it's their primary device it still counts as the primary user making it EQU. e.g. A catering manager who uses a pc in their office to do reports then that is their primary device so not licensed that way, even if it's only used 1 hour a day to do those reports then it's no longer a shared device as it's primary. Compared to say a cleaner who logs into a shared library pc for 5 minutes, or a till assistant who only uses a kiosk style till, who wouldn't count. You can't just say they use their machine under 50% of the day and count it at light. Otherwise under that logic a teacher who teaches in 3-5 classrooms a day isn't EQU either As they aren't using it over 50% of the day Steve 1
timbo343 Posted April 4, 2023 Posted April 4, 2023 I had a chat to my reseller and decided that EQU in primary was: Headteacher | SLT | Admin Staff | Teachers. Non-EQU was Kitchen Staff | Cleaners | Site Teams | TAs. In a Secondary we said that EQU was: Headteacher | SLT | Admin Staff (IT / Office staff) | Teachers | TAs | Main Cook / Catering Manager | Site Team. Non-EQU was Kitchen Staff | Cleaners. 1
Mr.Ben Posted April 4, 2023 Posted April 4, 2023 Do you have anything from MS that says that email wise etc? It just seems we read that differently, as that's the same document I've discussed with them EQU is anyone using an A3 or A5 product. If I don't assign them a licence, they are not an EQU. -> I agree that if you're using an A3/5 product it counts (but remember it includes all aspects of A3/5, not just an assigned license, which includes Windows/CALs/Office etc) These non EQU users are covered to use windows as long as they don't use a device for more than 50% of their work day (which none do!) -> This seems to be clashing two rules into one. A shared device is something used under 50% by one person yes "however" if it's their primary device it still counts as the primary user making it EQU. e.g. A catering manager who uses a pc in their office to do reports then that is their primary device so not licensed that way, even if it's only used 1 hour a day to do those reports then it's no longer a shared device as it's primary. Compared to say a cleaner who logs into a shared library pc for 5 minutes, or a till assistant who only uses a kiosk style till, who wouldn't count. You can't just say they use their machine under 50% of the day and count it at light. Otherwise under that logic a teacher who teaches in 3-5 classrooms a day isn't EQU either [emoji14] As they aren't using it over 50% of the day Steve Interesting that we have different takes on it (and it seems different results). Which reseller are you using - ATM I only have their say that MS have agreed - apparently it was also checked by MS given the size of the order (which may of course have contributed to the result). There is a device based licence for Office for Shared PCs available using EES at no additional cost. There is no information on how and when that can be used and it is an undefined grey area. We use the Core CAL version of A3 (which saves approx £4 per head). CALs wise I have less to consider as we are 100% cloud based. We have a few servers (12) within Azure and we do buy user cals for the staff that access them and don't have an A3 licence (around 250) You could extend our logic to teaching staff, but I think it would at that point it would be a stretch to say you are licencing correctly. I'm comfortable about our position, but as with anything it's on our risk register just in case. We licence based upon job role description (as I'm dealing with approx 1000 EQU and 550 Light users (300 governors) Teachers, HLTAs, Site Mangers, Admin staff with a designated device are all counted as EQUs regardless of hours worked. We did a big piece of work to profile all users and found that Teaching Assistants, LSAs, Catering Staff, Cleaners and Caretakers/Keyholders and found that on average they were spending less than 30 mins per day checking emails and sharepoint and that 85% of these staff did so on personal devices/non windows devices (iPads etc). That informed our decision and gave us an evidence to treat them as light users - as I mentioned, we still buy Azure P1 and Intune because I don't like the security stance without them Governors are mainly light users - we do buy A3 for Chairs as a courtesy for all of the work they do (Clerks are treated as employed admin staff).
Mr.Ben Posted April 4, 2023 Posted April 4, 2023 (edited) I had a chat to my reseller and decided that EQU in primary was: Headteacher | SLT | Admin Staff | Teachers. Non-EQU was Kitchen Staff | Cleaners | Site Teams | TAs. In a Secondary we said that EQU was: Headteacher | SLT | Admin Staff (IT / Office staff) | Teachers | TAs | Main Cook / Catering Manager | Site Team. Non-EQU was Kitchen Staff | Cleaners. The same as us - TAs I thought were borderline, so we split them to HLTAs and TAs and our user profiling backed this up. We have a multi site manager setup (1 for every 5 primaries), so they were definitely EQUs, with the Keyholders/caretakers definitely within the light users. Edited April 4, 2023 by Mr.Ben
m0bov Posted April 25, 2023 Author Posted April 25, 2023 Hi guys, where does CSP fit into all this? So many options!
timbo343 Posted April 25, 2023 Posted April 25, 2023 Hi guys, where does CSP fit into all this? So many options! My understanding is that CSP fits into all this if you want to license any non-EQU users or add additional ad-hoc licenses at a later date. You might have a member of staff (or a couple of members of staff) who need specific applications from MS. This is where CSP comes into it.
m0bov Posted April 25, 2023 Author Posted April 25, 2023 Hi, I don't think we need that so I think we will stick to Campus. I can't find a disadvantage to the Campus model, other than needing an OS license with the PCs when we purchase them.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now