Jump to content

Recommended Posts

Posted

Is there anyone that has successfully implemented Intune into their Microsoft school and it is working successfully with Microsoft devices, as we are looking to this solution as our servers require a refresh and instead of going back to onsite we are looking at a hybrid version to release some servers to sit in the cloud whilst those bespoke products that are still required can be dealt with onsite. We will also require cloud storage and force students to now only use OneDrive. Is it also wise to have some backup onsite just incase both our leased line and backup line were to go down? We have A3 licences so we can get Intune running now but need to understand if this is a realistic choice and would need external assistance and wondered if there was a suitable company that would help?

For those using it would it be possible to come an see it in action and get some positive and of course negative analysis?

Do any of you provide all students with a Microsoft based device and what should we be looking for including staff?

Posted

You brave man -

 

Feel free to call me and we can chat; we need to catch up anyway

 

For a general answer yes and no; we have a hybrid system running with nearly all 'portable' devices running on Intune, but it's really nowhere near as solid a solution as old fashioned networking.

 

Of course thanks to the Academy I need to recall all these devices and start again :mad:

Posted

Here’s our experience…

 

I’ve tested Autopilot and Entra Join (formerly Azure AD Join) for our trust. For shared devices, it just simply doesn’t fit our needs at the moment. For 1:1 staff laptops, it might be possible though.

 

I found that Autopilot wasn’t always that reliable, policies/apps would intermittently fail and diagnosing the failures during OOBE was a nightmare. You can’t easily ‘retry’ anything either so your main option is to wipe/reset and restart the whole process over again.

 

I briefly tested the ‘Shared PC’ mode and ‘Education policies’ but we have things like exam, controlled assessment, staff, student, visitor, open evening etc. accounts that need unique user-based policies that just would never reliably apply using Intune compared with Group Policy that works 99% of the time straight at logon.

 

We have a lot of shared laptop cabinets and computer suites where we need a very autonomous setup/imaging process.

Autopilot does now have a self-deploying mode (currently in preview) but this doesn’t support hybrid currently so Autopilot is pretty much a non-starter for our shared devices.

 

Personally, I think 1:1 student devices are a bad idea as they often get damaged at home, and financial consequences are impossible to impact/enforce so the school ends up paying for repairs/replacements. But Microsoft seem to think education can afford 1:1 devices for everyone!

 

We have ConfigMgr, so we’ve setup co-management. The way we’re approaching Intune in our Trust will be using a hybrid of AD, GPO and Intune to get the best of both worlds.

 

We’ll use a ConfigMgr task sequence to play the part of the ‘OEM’ in the Autopilot workflow (https://learn.microsoft.com/en-us/autopilot/pre-provision) which will wipe the device, install Windows, install drivers and Windows Updates.

It’ll then also join it to AD and ConfigMgr/GPO will Entra hybrid join and Intune enrol it.

 

We’ll then assign some GPO’s and Intune configuration profiles to these devices.

We’re starting with the things Intune does fairly well with - Microsoft Store Apps, WUfB, Defender, LAPS, BitLocker, Remediation Scripts and a few other bits. We’ll then look to maybe start migrating all computer GPO’s to Intune device configuration profiles and keep user-based ones as GPO’s where we need to ensure settings are applied on logon reliably, but I need to test this more yet.

 

If we end up going full Entra join and Autopilot for our 1:1 staff laptops, then there should be a much easier migration path as a lot of things will already be in Intune and we can just assign user configuration profiles to 1:1 devices instead of using the user GPO’s.

 

All our files are on Sharepoint/Teams/OneDrive (although macOS Logic Pro files don’t play well with the OneDrive app) so the storage requirements are a lot less than they used to be when we had on-prem file servers.

 

Any 3rd party services we host internally, we try to migrate to the providers own cloud-hosted solutions where possible and cost-effective.

 

I think having 2 internet connections would be enough and it’s rare that Microsoft services like OneDrive/Sharepoint are completely inaccessible, especially for more than an hour.

 

Interested to see how other people are approaching it though…

  • Thanks 3
Posted

I have a fully serverless setup with 1:1 computing for all staff and students. Its a long process of moving bit by bit over time but worth it in the end in my opinion. I just have phones left to move then all I'll have is a desktop running a tiny bit of dns and salamander.

We run 500+ iPad and 500+ Chromebooks. all staff have a 2 in 1 laptop and an iPad. I don't recommend running windows for students the lower priced devices just can't handle it.

We use teams and sharepoint heavily for everything.

Intune has improved massively since we started moving which was summer 2019. it was all scripts and compromise back then and now i'm struggling to keep up with the changes. We went serverless as it fits in what we aim to deliver. We have a full digital strategy and a full time employee who drives the sharepoint content and user training aspects. Most importantly our head is on board and drives the change from the top.

Without the schools support i would only move the things that would help you operationally. Files to onedrive, department files to teams etc which will save you on server costs and backup costs. I highly recommend intune over SCCM especially now intune is working better but once you start dipping into intune you start needing A3. Then you don't need your AD anymore so you decide to remove it which means you need to change to a print system that uses cloud etc etc. you start a little chain reaction and end up in the cloud anyway.

 

1:1 devices are great for students 90% of them look after them better than the teachers look after their laptops. The other 10% can be controlled by good cases, screen protectors and form tutors helping imbed the message that they need to be looked after. We also do regular form checks on devices. We get a damaged device at least one a week but we've just learnt how to fix them. Once you know how replacing an iPad screen or an iPad LCD is easy and cheaper than you'd think.

  • Thanks 2
Posted

Did this to the school I look after just before covid (completely serverless, everything in cloud) it's a small primary.

 

works best for 1:1 stuff, I think you're suitably resilient network connectivity wise already, if you don't have internet connectivity most stuff these days will be useless no matter how much on prem stuff you've got.

 

getting the basics working with intune and autopilot is pretty straightforward, and the in-box policies now are much more flexible than they used-to-be but I'd suggest you need to be comfortable crafting powershell scripts to get the look and feel just like you want it.

Posted
Here’s our experience…

 

I’ve tested Autopilot and Entra Join (formerly Azure AD Join) for our trust. For shared devices, it just simply doesn’t fit our needs at the moment. For 1:1 staff laptops, it might be possible though.

 

I found that Autopilot wasn’t always that reliable, policies/apps would intermittently fail and diagnosing the failures during OOBE was a nightmare. You can’t easily ‘retry’ anything either so your main option is to wipe/reset and restart the whole process over again.

 

I briefly tested the ‘Shared PC’ mode and ‘Education policies’ but we have things like exam, controlled assessment, staff, student, visitor, open evening etc. accounts that need unique user-based policies that just would never reliably apply using Intune compared with Group Policy that works 99% of the time straight at logon.

 

We have a lot of shared laptop cabinets and computer suites where we need a very autonomous setup/imaging process.

Autopilot does now have a self-deploying mode (currently in preview) but this doesn’t support hybrid currently so Autopilot is pretty much a non-starter for our shared devices.

 

Personally, I think 1:1 student devices are a bad idea as they often get damaged at home, and financial consequences are impossible to impact/enforce so the school ends up paying for repairs/replacements. But Microsoft seem to think education can afford 1:1 devices for everyone!

 

We have ConfigMgr, so we’ve setup co-management. The way we’re approaching Intune in our Trust will be using a hybrid of AD, GPO and Intune to get the best of both worlds.

 

We’ll use a ConfigMgr task sequence to play the part of the ‘OEM’ in the Autopilot workflow (https://learn.microsoft.com/en-us/autopilot/pre-provision) which will wipe the device, install Windows, install drivers and Windows Updates.

It’ll then also join it to AD and ConfigMgr/GPO will Entra hybrid join and Intune enrol it.

 

We’ll then assign some GPO’s and Intune configuration profiles to these devices.

We’re starting with the things Intune does fairly well with - Microsoft Store Apps, WUfB, Defender, LAPS, BitLocker, Remediation Scripts and a few other bits. We’ll then look to maybe start migrating all computer GPO’s to Intune device configuration profiles and keep user-based ones as GPO’s where we need to ensure settings are applied on logon reliably, but I need to test this more yet.

 

If we end up going full Entra join and Autopilot for our 1:1 staff laptops, then there should be a much easier migration path as a lot of things will already be in Intune and we can just assign user configuration profiles to 1:1 devices instead of using the user GPO’s.

 

All our files are on Sharepoint/Teams/OneDrive (although macOS Logic Pro files don’t play well with the OneDrive app) so the storage requirements are a lot less than they used to be when we had on-prem file servers.

 

Any 3rd party services we host internally, we try to migrate to the providers own cloud-hosted solutions where possible and cost-effective.

 

I think having 2 internet connections would be enough and it’s rare that Microsoft services like OneDrive/Sharepoint are completely inaccessible, especially for more than an hour.

 

Interested to see how other people are approaching it though…

 

You could do all that or just get Chromebooks!

Posted
You could do all that or just get Chromebooks!

 

Not when you have lots of Windows-only applications that are needed for lessons/courses! Especially in secondary/further education.

 

Chromebooks might be more feasible for primary schools though!

Posted

Print server we moved to Canon Uniflow. Canon are hard work but the uniflow print system is fantastic. I think other companies host uniflow now.

 

DHCP and DNS we still just run on MS server of a little NUC. There are alternatives. DHCP on a modern core switch is quite good. There is a free one as well which i haven't bothered with yet as it involved reading

 

https://sourceforge.net/projects/dhcp-dns-server/

  • Thanks 1
Posted (edited)
Not at the moment. I need to just add in a second device that has DHCP setup more wisely. As long as you have a good backup of your DHCP scopes it easy to get DHCP working again if a devices fails. Same for DNS but to be honest there isn't much on the DNS i don't use it to name devices as most of our devices are named and managed in intune. I just have DNS to add some forwarding for our website and things i don't like remembering IPs for. Once you take AD out of the equation DNS and DHCP aren't as complicated Edited by jblackburnHWGA
  • Thanks 1
Posted

Ive used DHCPServer.DE for DHCP and DNS, it also provides a simple web server which at one point I used for hosting a proxy.pac. I found one bug in it years ago that the developer fixed and it's been utterly flawless otherwise in years.

 

I had a DNS zone called proxy.pac with an entry called pac, pointing at the IP of the server hosting the DHCP server. So clients try to resolve pac.proxy.pac and if the server is down connect to the other DNS server and get a IP of that machines thats up.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...