Jump to content

Windows 10 activating as Enterprise - but should be Education?


Recommended Posts

Posted (edited)

Hi all. Truly not sure where I should post this cause I feel like there are multiple potential cooks in the kitchen. I'm testing Intune, we have A3 license subscription, and Windows 10/11 Enterprise is tagged with the student group so they should have the ability for Windows to automatically "step up". With our test machines, we're starting wtih Win 10 Pro (device has an OEM license for this), and upon logging in to a test student account which has the A3 Win 10/11 license, it should activate.

 

On two machines in particular, it comes up as Windows 10 Enterprise. All others I've tested (so far) come up as Windows 10 Education. The ones that say Windows 10 Education specifically say "Windows 10 Education A3 subscription is active", whereas the two problematic machines simply say "Windows 10 Enterprise subscription is active".

 

These laptops have the exact same configuration. Both managed by Intune using Self Deploying profiles. I really can't find a reason as to why these two machines are getting picked up as Enterprise. Has anyone seen this before?

 

While one could argue that there's minimal difference between Enterprise and Education, I worry about how this will act at scale. Are these 2 Enterprise machines a sign of more to come once we get into the mode of mass setups? Likewise, I stumbled on a Reddit post with someone who had this same exact issue and they mentioned after quite some time the handful of systems they had coming up as Enterprise began to drop their Windows activation... kind of my worst nightmare...

 

Would appreciate any and all insight!

 

EDIT - Just a random thought hit me. I'm using some old laptops to test. I wonder if I just got luck of the draw and these two problematic laptops actually had motherboard swaps in the past, and perhaps the OEM key on it happens to be Enterprise from who-knows-what box Dell pulled it from... I can dig up the OEM key via wmic. Any suggestions on how to identify what edition this key is attached to? slmgr /dli returns Windows Professional edition, RETAIL channel, and ends in 3V66T. Huh...

Edited by intense_username
Posted (edited)

So the way the A3 Win 10/11 licensing works is that it "upgrades" the device to either Education or Enterprise depending on the embedded device license. A few examples below + diagram:

 

Scenario: The device comes with an embedded Windows 10 for Education Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Education.

Scenario: The device comes with an embedded Windows 10 Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Enterprise.

Scenario: The device comes with an embedded Windows 10 for Education license and a user with an A3 license user logs in. Outcome: The device will stay on Windows 10 for Education.

Scenario: The device comes with an embedded Windows 10 Home license and a user with an A3 license user logs in. Outcome: The device will stay on Windows 10 Home.

Scenario: The device doesn't come with an embedded license and a user with an A3 license user logs in. Outcome: The device will remain unactivated until activated with a product key.

 

after.png

 

Note, if the device has come with an embedded license but Windows is showing as unactivated, the A3 license will not take effect. You will need to extract the embedded license key and then activate Windows. I have a proactive remediation (that you can import into Intune) that will do this for you, all it does is extract the key and activate Windows + report the status based on a 1 or 0 return value (IntuneProactiveRemediations/Repository/DigitalLicense/).

 

Microsoft has further guidance on subscription activation here that goes into a bit more detail.

 

Hope this helps!

Edited by dylanm
Posted
So the way the A3 Win 10/11 licensing works is that it "upgrades" the device to either Education or Enterprise depending on the embedded device license. A few examples below + diagram:

 

Scenario: The device comes with an embedded Windows 10 for Education Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Education.

Scenario: The device comes with an embedded Windows 10 Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Enterprise.

 

Thanks for the info! I wonder if this varied a little bit depending on which Dell rep we had at the time. See the reality is the Windows that came with our student laptops back then didn't really matter, seeing as though we had Edu licensing with MAK keys. I know Pro was the focus but I believe that one Dell rep vs the others may have built the quotes differently. For example, one quote contains this line "Win10 Pro 64bit Nat'l Aca NTRY" and another quote from a year earlier has this line "Windows 10 Pro Natl Aca Strategic EDU CARE K12 and HIGHER EDU only." So maybe that bounced between Pro and Pro Edu with those different Dell reps, and the reality is, we would have never noticed because first time we booted them up it was off to a PXE boot with SCCM they went and the OEM image was pulverized by our SCCM image.

 

Do you think these will upgrade and step up to Windows 11 Education/Enterprise without issue? I'm hopeful (and would think) they would... we're on the brink of putting 11 on these systems to test further and see how things go.

 

I also question if this is reason for concern. I mean, we all know Enterprise and Education is quite similar to one another, so feature wise I think it'd be fine. I'm more concerned about "licensing compliance" or anything like that regarding our A3 license access. I would hope that one student being on A3 Enterprise and the next being on A3 Education wouldn't set off any alarms on the Microsoft side to cause a hurdle.

 

Appreciate your response! Especially given I'm on the brink of building our summer quote out... Windows 11 Pro Education will be one of those "ensure you don't forget this" things moving forward.

  • Thanks 1
Posted

This is really interesting and something I haven't seen - it's given me the jitters that I need to check tomorrow!

 

We are heavy Intune/autopilot users in our Trust.

 

We rebuild all devices that come in as Win 10 Pro, then use and Intune policy to upgrade and apply our education key. End result is an extra reboot and the device is upgraded. We can generally tell this from our custom background being visible and Techs know not to log in until this point.

 

When a user with an A3 licence then logs in the device doesn't change licence as the Education version has been applied.

Posted
This is really interesting and something I haven't seen - it's given me the jitters that I need to check tomorrow!

 

We are heavy Intune/autopilot users in our Trust.

 

We rebuild all devices that come in as Win 10 Pro, then use and Intune policy to upgrade and apply our education key. End result is an extra reboot and the device is upgraded. We can generally tell this from our custom background being visible and Techs know not to log in until this point.

 

When a user with an A3 licence then logs in the device doesn't change licence as the Education version has been applied.

 

Are you using the Windows Edition and Mode Switcher policy? I have that set up, but right now it's not applying to any systems. I began to question if that policy even has a point to it... (??). See I was having issues getting Windows Activation with A3 subscription working until I started using a script to apply the embedded key as the Windows key. The A3 subscription doesn't seemingly kick in unless your "local" licensing of the machine is in good standing, and since mine was erroring out the A3 subscription never kicked in. So with that script, that problem seemingly went away, and my systems would step up to A3 subscription (excluding the few that went to Enterprise instead which lead to me making this post of course).

 

Reason I share all of this is before using the script to apply the embedded key I was using the Windows Edition and Mode Switcher policy, but it didn't seem to really... do anything? It seemed far more consistent to use the script to apply the OEM key then let the user logged in as a licensed A3 user to step up the license from there. /shrug

 

PS - you're a big Intune shop? Students I assume? Side question - User Driven or Self Deploy for students? I've been on the fence but leaning more towards User Driven with techs running pre-provision then resealing the device. I originally wanted to do Self Deploy but I'm having some issues with the Company Portal (I want to make apps available for students to self-service-install but that acts a little weird on Self Deploy, unfortunately...)

Posted
Do you think these will upgrade and step up to Windows 11 Education/Enterprise without issue? I'm hopeful (and would think) they would... we're on the brink of putting 11 on these systems to test further and see how things go.

 

I'm sure it will be okay however would do testing first.

 

I also question if this is reason for concern. I mean, we all know Enterprise and Education is quite similar to one another, so feature wise I think it'd be fine. I'm more concerned about "licensing compliance" or anything like that regarding our A3 license access. I would hope that one student being on A3 Enterprise and the next being on A3 Education wouldn't set off any alarms on the Microsoft side to cause a hurdle.

 

Should be fine as your devices have come with the license already (you paid for the license when you bought your device) however I'm not the best when it comes to Microsoft licensing & the fine print so I would say to speak to your Microsoft licensing reseller/supplier (if you have one).

Posted
I'm sure it will be okay however would do testing first.

 

 

 

Should be fine as your devices have come with the license already (you paid for the license when you bought your device) however I'm not the best when it comes to Microsoft licensing & the fine print so I would say to speak to your Microsoft licensing reseller/supplier (if you have one).

 

You know what's kind of funny about all of this? In my tenant, if I go to our license products, it literally says verbatim "Windows 10/11 Enterprise A3 for students". So right there in the name it even name-drops Enterprise. Not that it means anything, I just find it saying Enterprise with us being an Educational institution and a lot of my test devices activating as Education (likely from the Win 10 Pro Edu batch from the one order) as a bit of a "huh, imagine that" kind of thing.

 

But yeah, I can definitely see that Pro Edu needs to be our focus going forward for any new orders as far as OEM licensing goes.

Posted
Are you using the Windows Edition and Mode Switcher policy? I have that set up, but right now it's not applying to any systems. I began to question if that policy even has a point to it... (??). See I was having issues getting Windows Activation with A3 subscription working until I started using a script to apply the embedded key as the Windows key. The A3 subscription doesn't seemingly kick in unless your "local" licensing of the machine is in good standing, and since mine was erroring out the A3 subscription never kicked in. So with that script, that problem seemingly went away, and my systems would step up to A3 subscription (excluding the few that went to Enterprise instead which lead to me making this post of course).

 

Reason I share all of this is before using the script to apply the embedded key I was using the Windows Edition and Mode Switcher policy, but it didn't seem to really... do anything? It seemed far more consistent to use the script to apply the OEM key then let the user logged in as a licensed A3 user to step up the license from there. /shrug

 

PS - you're a big Intune shop? Students I assume? Side question - User Driven or Self Deploy for students? I've been on the fence but leaning more towards User Driven with techs running pre-provision then resealing the device. I originally wanted to do Self Deploy but I'm having some issues with the Company Portal (I want to make apps available for students to self-service-install but that acts a little weird on Self Deploy, unfortunately...)

 

 

 

Yes, that's the one we are using - it's applied to device groups (not user groups).

 

We have it working for Windows 10 and 11 in this way.

 

I haven't seen the behaviour of not upgrading if the licence isn't in good standing - we had 100's of machines at one point that came with Home licences and built them all to Pro 10 before the policy upgrades them. What image/source are you using to build them?

 

We are quite big, but Primary only, about 2000 Windows devices across 40 schools and we manage our 1000 iPads through Intune as well. In the last few weeks we have started looking at how we can manage Chromebooks through the Endpoint manager as well (we have 1300 of them so even getting inventory data into Intune would be fab).

 

Side Answer ;-) - We use Autopilot Self Deploy and deploy them before they get to schools.

 

User Driven deployment posed a few operational issues for us, specifically:

 

Once a device is user deployed, it's owned by than user and that restricts the use of the company portal to only that user.

 

As laptops get passed between staff on a regular basis and we only have a tech per 15 schools rebuilds often don't happen. Also was an issue for our fixed desktops with multiple users.

 

It just wasn't reliable enough in schools and we found we have to visit our initial roll out sites frequently to fix laptops that failed to deploy. We cover 900sqm of Somerset and Avon so it's costly to send techs to sites, better to get them reliably built before they go to sites.

 

As we transitioned from local servers we found a host of issues with TPM attestation during deployment. Some of this was due to internet filtering and bandwidth issues. As it was so unreliable on site we found our office (with a gig connection) was far more reliable. That issue seems to have faded over time.

 

I can see how it would work for a true 1:1 environment if you have one!

 

Happy to have a chat if you want!

Posted
(text removed for brevity)

 

You definitely raise some valid points there. I have been ferociously on the fence about Self Deploy vs User Driven to the point it's almost driven me bonkers. One day I'm in one camp, the next day I've 180'd and I'm swearing by the other option. I think as it stands (for now?) I'm leaning more towards User Driven. See, I want to put some agency (and responsibility) on end users/students to download the apps they feel they need (or simply want to poke at for sake of learning/curiosity). We use Intune to manage apps for our iPads which we use for our younger grades and honestly... it was a sustainability nightmare at first. This isn't a fault of Intune at all, but rather the nature of the beast. One group wants one app, the next wants another, and we go in circles trying to figure out how to apply them. So what we did there is we created grade-level groups, so all 1st grade iPads get the same apps regardless, same with 2nd grade, etc etc. This seems to work well and tends to boost "app awareness" when apps magically show up on iPads because school A requested it but school D had no idea, but now, school D sees it on their screen and get curious and that leads to more use. That functionality has worked well.

 

But I really didn't want to get into it with laptops. We start laptops at 4th grade. Some folks may disagree with me on this and that's fine, but we live in an app store driven world anymore, so I felt we should acknowledge that and lean into it a bit. So starting with our Windows Intune laptops (e.g. 4th grade moving forward), I want students to be able to go into Company Portal to download any additional apps necessary. All *core* apps are blasted to every single laptop regardless of grade. That includes things like our testing software, Office 365, and other critical apps. This way the discoverability is still kind of there thanks to Company Portal, but we're not carpet bombing all of our laptops with apps that the students may never need or use.

 

The reason I share that mindset is because I was hardcore in the boat of Self Deploy. There's something so satisfying about getting to our branded login screen and shutting the laptop down and having confidence "it's ready to go!" But the thing is I ran into a few select cases where a Self Deploy laptop wasn't seeing all available apps in Company Portal. It would see some, but not all. The apps had no restrictions, scope settings, anything like that. It didn't matter if it was applied to All Devices or All Users (or both). I couldn't make sense of it, but buried somewhere in Microsoft's documentation was this little FYI box that explicitly said something about Company Portal apps and Self Deploy might have issues. That read to me as though I can either give up on Self Deploy and double-down on my "students should be able to download what apps they want in Company Portal" by embracing User Driven mode, or... give up on the Company Portal/students download idea and set apps as required installs.

 

As a result, this is where I landed, with leaning more towards User Driven. Yeah - we do have a 1:1 setup, so perhaps it would be more fitting for us. I think as some of our labs of desktop systems make their way to Intune we'll simply stage them as Self Deploy and put those systems in their own group, and then mark apps needed for that lab as required, thereby skipping over the need for Company Portal/available app installs anyway (I mean, we're talking about CADD labs and video editing labs - they're kind of single-purpose anyway so hitting them with only required app installs doesn't strike me as terrible).

 

Who knows, maybe I'll rethink this years down the road and think "what on earth was I thinking..." but for now I think this might be the plan.

 

The User Driven mode originally struck me as a nightmare until I realized pre-provisioning pulls some serious weight here. It's still weird to me to hit "reseal" and power off the device without seeing our branded login screen, but maybe I'll get more used to that over time.

 

You mentioned TPM issues - I originally ran into a lot of TPM issues as well, but that only ever seemed to happen with Self Deploy mode for the most part. Somewhere in a YouTube tutorial guide it was mentioned that a lot of recent updates took place to make TPM less terrible to deal with. I have no idea what video that was but I recall it being dated fall 2023, so it was pretty recent. Stands to reason that this should be less of a headache into the future.

 

In response to you addressing the "if the licensing isn't in good standing activation issues" comment, I inadvertently left a key factor out of that on accident. You see, originally I was USB wiping my test systems with Windows 10 Education and that's where I would get the license error. I was doing that thinking Education is the final goal, so why not USB install (takes just under 5 mins, so it's quick) and since Edu is the end goal I'll use Edu on the USB install. But therein lies the issue - OEM license for the device was Pro/Pro Edu, not Edu proper, so it would error out and I would never get the A3 subscription license. If I USB'd with Pro (or Pro Edu rather), then after an A3 user logs in it would step up to Edu. Shot myself in the foot during testing without even realizing it. :D

 

(pardon the length of this post - part of me feels the need to share these details somewhere in case someone in the future stumbles on this)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...