Jump to content

Recommended Posts

Posted

Hi All,

 

What's the best practice nowadays for to do a Win 10 Build and deploy across your school/college?

 

Is is WDS? SCCM? InTune?

 

We currently use a WDS server and I need a fresh Win 10 image with MS Office 2021. However before I go through this process I am wondering if I am wasting my time and should be looking to do it another way......

 

Appreciate your thoughts.

 

Thanks

Posted

If you re-image every year, then it might be worth deploying Windows 10, but next summer you'll have to re-image to Windows 11 anyway.

 

I'm sure @thimon was making a tongue in cheek comment, but I certainly wouldn't be looking at changing how I deploy Windows 10 at this stage. Focus on preparing for Windows 11 - coming ready or not!

  • Thanks 2
Posted

If you're yet to explore a Windows 11 rollout, I'd start on that. That will then tell you whether you have computers that aren't officially supported. At which point you can build a Windows 10 image for them, perhaps based on LTSC to squeeze the maximum support life out of it.

 

We used to use just WDS for deploying our Windows+Office image, with apps and config deployed afterwards via GPO as much as possible. We then switched out WDS for WDS+MDT. MDT allowed us to completely automate the build & capture process (pretty much zero-touch apart from network booting a VM and supplying some network creds and a desired capture filename), which it sounds like is still an involved manual job for you at present.

 

As for best practice, it doesn't seem like MDT has too much life left, so MECM would be the best choice for an on-prem solution. InTune and AutoPilot are obviously what MS want everyone using, but that's a big departure from WDS. Lots of commenters will say to not build a Windows+Office thick image, but instead just use MDT/MECM task sequences to deploy the latest vanilla Windows image and install Office and Windows updates on the fly during deployment. IME that makes a deployment take about 3 or 4 times longer, so we still have a 'thick' image with Office and updates baked in during capture. Automating the build+capture takes a lot of the pain away though, and allows you to deploy the latest Windows version just as easily whilst minimising the time it takes to image a machine.

  • Thanks 2
Posted
MDT here been using for over 8 years, for both windows 10 & 11, Use to do Thick images with MDT at my last job, but now use Thin images, this way every 2 months I check and update software packages so the latest versions of software is always being deployed. Then use WSUS to patch after afterwards.
  • Thanks 1
Posted
FOG in here and working well, replaced MDT/WDS setup. W11 image ready to go and deploys fine with it, as does the current W10, but the InTune/AutoPilot stuff does look good, so may be the last outing for it now. Plus it's a bit of a niche thing to be running these days I think.
Posted
If you're yet to explore a Windows 11 rollout, I'd start on that. That will then tell you whether you have computers that aren't officially supported.

 

We install Windows 11 via a USB image automated with a simple Unattend.xml file. We've yet to find a machine that Windows 11 refuses to install on - our 8(?) year old VeryPC all-in-ones have no problem, even our 11(?)-year-old Acer laptops install okay (if slowly). The Unattend.xml file we used is exactly the same as the previous Windows 10 one, there seems to be little practical difference in installing Windows 11 instead of Windows 10 these days.

Posted
We install Windows 11 via a USB image automated with a simple Unattend.xml file. We've yet to find a machine that Windows 11 refuses to install on - our 8(?) year old VeryPC all-in-ones have no problem, even our 11(?)-year-old Acer laptops install okay (if slowly). The Unattend.xml file we used is exactly the same as the previous Windows 10 one, there seems to be little practical difference in installing Windows 11 instead of Windows 10 these days.

 

It's not so much the deployment of Windows 11 to unsupported hardware, as much as whether those computers will continue to receive updates. At the moment, our oldest models (which are non-UEFI) will install Windows 11 and do receive updates, but I'm assuming that at some point those updates could just quietly stop working, so it's a case of should we rather than can we.

Posted
It's not so much the deployment of Windows 11 to unsupported hardware, as much as whether those computers will continue to receive updates. At the moment, our oldest models (which are non-UEFI) will install Windows 11 and do receive updates, but I'm assuming that at some point those updates could just quietly stop working, so it's a case of should we rather than can we.

 

Isn't the support 10yrs ?

An LTS branch was released in 2021 so there should be another 7 yrs before it becomes a problem.

Posted
LTSC 2019 is the last one that's 10 years support. 2021 is only 5 years sadly.

 

That's outrageous. Isn't there an 'enterprise' version for schools?

Ubuntu, ChromOS, RedHat all have full ten year support lifecyles - cost lot less too, even without keeping them for double the time.

Posted (edited)
Isn't the support 10yrs ?

An LTS branch was released in 2021 so there should be another 7 yrs before it becomes a problem.

 

It's important to distinguish between Microsoft's support of a particular OS version (i.e. how long they will continue to provide updates to it for) and whether Windows is 'officially' supported on particular hardware (e.g. https://www.microsoft.com/en-gb/windows/windows-11-specifications?r=1 and https://learn.microsoft.com/en-gb/windows-hardware/design/minimum/windows-processor-requirements). Although it may well run on older hardware and receive updates (I've had Windows 10 happiy installing monthly updates on machines that don't meet it's stated requirements), Microsoft have been more vocal around Windows 11 not necessarily continuing to receive updates indefinitely if the hardware spec doesn't meet the mark. You're also unlikely to get any driver updates for older hardware, which could have secuirty implications.

Edited by jthompson
  • Thanks 1
Posted
That's outrageous.

 

Out of interest, how long do you think they should be providing updates/patches for then? 10 years is a very long time in the cyber world we live in.

Posted (edited)
Out of interest, how long do you think they should be providing updates/patches for then? 10 years is a very long time in the cyber world we live in.

I think an LTS release should be at least 10 years.

As @liamread2000 said, the 2021 release is 'LTS' but only has 5 years of support. That doesn't count as an LTS release in my mind. I think the Ubuntu model is pretty good - they release an LTS release every two years and that release has 10 years support.

 

edit: they extended it to 12 years: https://canonical.com/blog/canonical-expands-long-term-support-to-12-years-starting-with-ubuntu-14-04-lts

Edited by dmj
Posted
I think an LTS release should be at least 10 years.

As @liamread2000 said, the 2021 release is 'LTS' but only has 5 years of support. That doesn't count as an LTS release in my mind. I think the Ubuntu model is pretty good - they release an LTS release every two years and that release has 10 years support.

 

[/url]

 

Microsoft have said going forward all Windows Client LTSC releases will align with the 5 year life cycle of perpetual Office. Only the IOT variant will remain on 10 year lifecycle.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...