Jump to content

Recommended Posts

Posted

Hi Guys

 

I'm not sure if its just us, but this applies to multiple different schools where we use Intune, the applying of policies, settings, scripts, installs etc is just not acceptable for deploying, as when a user logs in they do not have settings applied to them for some time, meaning this could cause a security risk if the setting is protecting something etc. We've applied a scheduled task to get the SharePoint to sync on login as this is known issue for the folders not appearing for many hours, but just seems to be hit an miss overall and not really workable. Is there any tips or tweaks we can do to ensure the users / devices have the right settings in good time. Obviously we have manually synced from both the machine and portal but still many take a while to apply.

 

Cheers

 

S

Posted

Welcome to Intune.

 

Not sure what the security risk could be though? Surely they would be standard users so shouldn’t be able to do much.

Posted

We have found InTune to be generally..rather quick, up until last week when we did a mass enroll of a full site.

 

I wondered if maybe we were hitting some kind of throttle from MS.

 

I am keen keep an eye on the thread though, to see what people might suggest.

 

But as the other comment put, not sure on the risk to your network? The benefits to InTune are zero trust.. they don't have access to anything other than the local machine.

Posted
The risk to to the machine, or at least the user will have access to all the control panels to change the look and feel of the machine, showing local disks, which further down the line will cause us headaches. I know they will be limited but will be able to change many things they wouldn't normally do if the polices were already applied on login. When connected to a local server there would be a setting "Wait for Policies". It doesn't seem fit for purpose in a school environment, where you will get them trying the play with every setting if not locked down.
  • Thanks 1
Posted

Just come to this forum to ask this and other questions regarding Intune, as I'm piloting it. I totally agree regards security concerns. High School students are not professionals in the work place. So when they see an open door they go and mess stuff up. Generating work for me to fix. When they log into a device for the first time its showing the C:\ drive within "my computer / file explorer" Task manager is available to them.

 

I've had to leave the test machine running for at least 30mins then reboot and log in with the same user for the policies to fully apply and lock down the device. By which point it could be to late and the student has caused havoc. Students don't sit at the same device each lesson so this open-ness is going to be a frequent occurrence.

Posted

Basically this:

 

Welcome to Intune.

 

As it applies settings after logon, some settings only take effect after Explorer has been killed and re-launched, e.g. all the ADMX settings for "Remove Run from the start menu", "disable command prompt" etc so you only notice them on second logon.

 

Regarding slowness, it all depends on the connection, and the load on the tenant location. I've had one tenant that takes 8 hours to report anything back to the console, where I'd normally expect this to take 5-10 minutes. Microsoft said the location is under heavy load, the fix is move location (not an easy task) where there is no guarantee the target location will remain under light load...

 

Where there's a "(User)" and "(Device)" option on the policies, setting the device instead of the user might get round this - although you then block it for your admin accounts.

Posted
I found it very effective at applying software and restrictions but it is designed for modern management of one to one machines. Which to me it seems very effective at especially if your machines are home workers where 12-48 hours is acceptable.
Posted
I found it very effective at applying software and restrictions but it is designed for modern management of one to one machines. Which to me it seems very effective at especially if your machines are home workers where 12-48 hours is acceptable.

 

I disagree. There is a plethora of intune policies designed for shared devices.

Posted

Agree - I think this is Microsoft being myopic because in their world they issue devices to their employees and that's it - The lack of caring about shared devices is because the concept is alien to Microsoft themselves.

 

This is one of big downfalls of intune for us at the moment and I can't see us converting our fixed IT suites to it any time soon. I can easily deploy software to an IT suite quickly via AD/GPO & update policy in about 5 minutes, knowing that it'll hit every machine.

 

The other big BIG downfall for us is that they don't seem to care at all about sorting the NPS 802.11x wifi issue - In that Azure AD devices can't use a machine certificate to authenticate against a Windows NPS server, because it also relies on a computer account in AD, which doesn't exist.

There are bodges to fix this but nothing is officially supported - Microsoft say to use a user certificate, which again is utterly useless on shared devices & again, a result of them only caring about 1:1. They could easily fix this with an NPS extension but won't - We're far from the only ones with this issue as the Internet is full of complaints but they don't see a need for it themselves.

  • Thanks 1
Posted
Agree - I think this is Microsoft being myopic because in their world they issue devices to their employees and that's it - The lack of caring about shared devices is because the concept is alien to Microsoft themselves.

 

This is one of big downfalls of intune for us at the moment and I can't see us converting our fixed IT suites to it any time soon. I can easily deploy software to an IT suite quickly via AD/GPO & update policy in about 5 minutes, knowing that it'll hit every machine.

 

The other big BIG downfall for us is that they don't seem to care at all about sorting the NPS 802.11x wifi issue - In that Azure AD devices can't use a machine certificate to authenticate against a Windows NPS server, because it also relies on a computer account in AD, which doesn't exist.

There are bodges to fix this but nothing is officially supported - Microsoft say to use a user certificate, which again is utterly useless on shared devices & again, a result of them only caring about 1:1. They could easily fix this with an NPS extension but won't - We're far from the only ones with this issue as the Internet is full of complaints but they don't see a need for it themselves.

 

How are you connecting them to WiFi at the moment as we have this and are using our Mac authenticated ssid for the intune only devices.

 

I don't see it replacing our main network and sccm yet taken ages today to just get 10 shared devices through autopilot enrollment and half haven't reported back of office installed or not. We are just using it for low spec devices on windows currently acting like a windows Chromebook minimal installed, safeguarding software, cloud filter, office.

  • 5 months later...
Posted (edited)

Apologies for hijacking the thread but I am encountering a similar issue and wondering if anyone has came across any alternatives, fixes, workarounds or if it's just the way it is.

 

Currently experimenting with Intune. Have created apps and policies and set up autopilot. All works great but I've just spotted today that policies don't seem to apply to the second user that logs onto a machine.

 

Current scenario - we install Win11 and log in as an admin account at the first OOBE wizard to install our baseline apps, register to Azure and so on. This finishes and the machine reboots. The next person that logs onto the laptop for the first time gets a quick OOBE wizard, which is great as it prompts for their 2FA. Once successful it logs them in and their OneDrive, outlook, teams etc is all fully functional. - Perfect scenario.

 

However, from now on, anyone else that logs onto the device receives no OOBE wizard meaning no 2FA prompt. I have to force a 2FA login once at the desktop, either through the verify account or an office app. We also see that at this stage no policies have applied. OneDrive KFM, mapped drives and so on have not applied. Regedit is accessible, the usual.Within Intune it shows the policies as being applied successfully. Policies are linked to machines rather than users.

 

Am I missing something? - Intune seems very much set up for single use, one-to-one arrangements where in this scenario would be ideal but when it comes to shared use the 'instant' application of policies similar to GPO is not what it's intended use is for.

Edited by Sc00by
  • 1 month later...
Posted

Myself and colleagues have this rolled out to many sites at the moment, and we have noticed that in the morning, builds/software deployments etc are all decently quick and acceptable. However, we see a slow-down on afternoons.

 

We call this the 'Americans have Woke Up' time.

 

Whether or not this is true, but it does seem to coincide - and has been the topic of a few observations from us techies when having a moan.

 

Anyone ITK shed any light on this?

Posted
we are still hybrid, the intune policies do take longer to apply. I still havent migrated the core "lock this down" GPO to intune yet.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...