_techie_ Posted April 25, 2024 Posted April 25, 2024 From a sysadmins point of view I have the following issues with Intune: 1) not designed for shared devices environments (often occurs in schools) 2) Unresponsive compared to on-prem technologies (important for exams) 3) restrictions taking time to apply after login, therefore making any cyber security policies broken and students taking advantage of this (not just messing about but being able to run scripts/bad processes 4) You cannot easily see what is inside any existing scripts to refer back to for troubleshooting... 5) waiting for devices to check back in to follow up 6) unhelpful error messages when installing software. Win11 23H2 seems particularly bad when using IntunePckgr apps... 7) costs and additional costs for tiering and add-ons. 8) Deploying printers... Still hell even using Paper cut Print Deploy client. I have had reasonable success with Win10 but Win11 is giving me serious issues with reliability. Thanks 1
free780 Posted April 25, 2024 Posted April 25, 2024 I’ve had this debate for quite a few years. Even deploy VPN profiles is easier with a PowerShell script wrapped in an app deployment within Intune. I think you need MECM for Servers and shared clients. There also nothing to say that you can’t deploy from both. You get so many logs with MECM but not Intune. The idea is good but the speed is slow and 1:1 devices are the primary focus. It’s also a lot quicker to apply GPP items than having to write scripts within Intune to do the same thing.
RLR Posted April 25, 2024 Posted April 25, 2024 From a sysadmins point of view I have the following issues with Intune: 1) not designed for shared devices environments (often occurs in schools) 2) Unresponsive compared to on-prem technologies (important for exams) 3) restrictions taking time to apply after login, therefore making any cyber security policies broken and students taking advantage of this (not just messing about but being able to run scripts/bad processes 4) You cannot easily see what is inside any existing scripts to refer back to for troubleshooting... 5) waiting for devices to check back in to follow up 6) unhelpful error messages when installing software. Win11 23H2 seems particularly bad when using IntunePckgr apps... 7) costs and additional costs for tiering and add-ons. 8) Deploying printers... Still hell even using Paper cut Print Deploy client. I have had reasonable success with Win10 but Win11 is giving me serious issues with reliability. Thanks Just about to start deploying our new machines using intune and it's funny everything you've mentioned are issues I've come accross in my testing. Waiting around for things to apply is the most frustrating part as you're still not sure if it's going to work and if it doens't, you're having to wait around again.
Steve101 Posted April 25, 2024 Posted April 25, 2024 Not being able to run scripts at log in is annoying, but at least it makes you avoid having tons of scripts at log in.
DrCheese Posted April 25, 2024 Posted April 25, 2024 Just about to start deploying our new machines using intune and it's funny everything you've mentioned are issues I've come accross in my testing. Waiting around for things to apply is the most frustrating part as you're still not sure if it's going to work and if it doens't, you're having to wait around again. Yes, it boils my urine. With GPO, I can make a change, quickly logon, test & logout. Within Intune, I have to apply a policy and... wait. One change I made a few months ago I had to go to bed and wait overnight it was so stupid. It's maybe fine once you've got everything setup right, but when you starting out it can make deploying it a real pain in the backside as you can't quickly test & reiterate Most of the policies (even user policies) being applied directly to the device really gets on my nerves as well - eg If we've applied user restrictions to a student account & then we logon (as admins) later, we have to wait until it figures out that we're admins and pull the student restrictions. It works the other way around as well in that it can take a while to apply student restrictions. It's so blatant that Microsoft only see how they work (Full 1:1) and don't get the need for shared devices. 1
CHiLL Posted April 25, 2024 Posted April 25, 2024 (edited) We use Intune for the devices that students use at home (basically the DFE laptops given our during the pandemic). We now use them for students who do not have their own dedicated computer, laptop or tablet. If they have to rely on their phone or a shared family device to do their homework, they get a school laptop and return it when they leave the school. The Intune policies we had at the time were a slap dash get it working ASAP, even if things are done wrong, such as computer policies to control browser settings, etc. I've now taken time to rectify those incorrect policies, but Intune is making me want to jump off a cliff. I have absolutely no control over whether a device checks in or not and it doesn't tell me why it doesn't (I've had a laptop on for days and not checked in once). Policies and apps are incredibly slow to install and validate. Reporting back to the console takes an absolute age. There's a policy applied to the machines that blocks access to the C:\ drive but I can't locate it, as far as I can tell, it's not being applied yet it is. I have a laptop in front of me that has just downloaded an app we pushed recently and some policies configured last week, yet Intune reports it's last check-in date as 26/10/2023, 0:19:05. Edited April 25, 2024 by CHiLL
TheHyperTechie Posted April 25, 2024 Posted April 25, 2024 Chromebooks all the way! But no, in all seriousness this is why I haven't opted for Intune. I just can't commit to something that costs so much money yet doesn't work seamlessly. 2
dmj Posted April 25, 2024 Posted April 25, 2024 Why not just choose a tool that better suits your needs? There's plenty of stuff available that deploys a registry key or script, which is essentially all it's doing.
mavhc Posted April 25, 2024 Posted April 25, 2024 The Cloud - you are in a queue, maybe, you do not know what order in the queue you are in, or if it's actually failed and you're not in a queue at all
slugshead Posted April 25, 2024 Posted April 25, 2024 I much prefer a traditional setup with DirectAccess/AlwaysOnVPN
dmj Posted April 25, 2024 Posted April 25, 2024 Suppose the question is how did it get past the procurement process? Random deputy head like the idea....
Olliedawg Posted April 25, 2024 Posted April 25, 2024 Still fully on prem at my school, no inTune devices as of yet. Not looking forward to getting started with inTune if i'm honest.
Squelch Posted April 25, 2024 Posted April 25, 2024 We're hybrid, can't see us going any further for a while as hitting the same problems as everyone else.
midweek Posted April 25, 2024 Posted April 25, 2024 Hybrid also. MDAC is hard work compared to applocker.
free780 Posted April 25, 2024 Posted April 25, 2024 More like OutOfTune One of my colleagues calls it this. I actually delved into the scheduled task that look like the exes that get triggered for a sync. I couldn’t sync via command line which would have been helpful. Other times it’s quite fast. I think a lot of the slowness is server side. Changing the image for a Win32 app got updated very quick in company portal. For testing it was easier to revert a VM to checkpoint to prevent caching. We had a licensing issue for months and was suddenly fixed after a lengthy support call. 1
_techie_ Posted April 26, 2024 Author Posted April 26, 2024 My colleague started work on it before I started. It's been disappointing I must say comparative to things like Mosyle.
ThatBoringBloke Posted April 26, 2024 Posted April 26, 2024 We're a Google school. It just works. I'll get my coat on the way out. 4
Popular Post PotNoodleTech Posted April 26, 2024 Popular Post Posted April 26, 2024 We're a Google school. It just works. I'll get my coat on the way out. Don't worry I will be booted out with you *glances at the 1000 chromebooks which literally work perfectly day in day out and receive policy updates/apps/etc within 60 seconds anywhere in the world* 5
DrCheese Posted April 26, 2024 Posted April 26, 2024 Don't worry I will be booted out with you *glances at the 1000 chromebooks which literally work perfectly day in day out and receive policy updates/apps/etc within 60 seconds anywhere in the world* That's what bugs me. Our Chromebooks instantly refresh with any setting we make. If I want to lock one out, it's super quick and easy. Unlike Intune, which last I checked didn't have a quick way to lockout/kill a device. Microsoft - Please PLEASE PLEASE just copy what Google do with ChromeOS & make "EdgeOS" - Stop trying to make some half baked Windows 11 SE or whatever every few years and then ultimately cry about it when it doesn't sell. 2
dmj Posted April 26, 2024 Posted April 26, 2024 Microsoft - Please PLEASE PLEASE just copy what Google do with ChromeOS & make "EdgeOS" - Stop trying to make some half baked Windows 11 SE or whatever every few years and then ultimately cry about it when it doesn't sell. They keep basing their consumer products on windows. they got a winner with Azure because they based the infrastructure on Linux.
mavhc Posted April 26, 2024 Posted April 26, 2024 Does anyone use a not Itunes MDM for their Windows machines?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now