Planehazza Posted May 20, 2024 Posted May 20, 2024 We have say 1000 laptops across our schools. Vast majority stay on site for classroom use and do not leave site. Staff allocated ones however, are mobile and so can leave site or traverse sites. Our problem? We do not have Intune or anything set up for Windows mobile devices. We are a Google site and so do not have any fancy Microsoft licenses other than office, CALs, and Window essentially. SO, this means that laptops for home use etc, are currently imaged EXACTLY the same as a standard PC, domain joined. They're BitLockered' but obviously this means we have zero remote management or deployment when they're not on site and reporting back to SCCM etc. Getting Intune is not going to happen. I haven't even bothered looking at license costs, because our climate will prohibit any expendature - even if it's cheaper in the long run than all the wasted tech time. So, TL;DR... how are you managing pools of windows laptops that can leave site without Intune? What other MDM product would you recommend that would keep devices compliant, allow for remote blocking/wiping, remote support etc.? Thanks!
paulkerton Posted May 20, 2024 Posted May 20, 2024 Windows device management in Google Workspace : https://support.google.com/a/topic/9695954?hl=en&ref_topic=9441473&sjid=8556768303991843204-EU
PotNoodleTech Posted May 20, 2024 Posted May 20, 2024 If your a already google school then use Chromebooks instead on your next device refresh - built in MDM, cheaper, better, longer battery life, more reliable, easier to maintain, easier for the end user to use, the list of positives is endless! 1
Planehazza Posted May 20, 2024 Author Posted May 20, 2024 If your a already google school then use Chromebooks instead on your next device refresh - built in MDM, cheaper, better, longer battery life, more reliable, easier to maintain, easier for the end user to use, the list of positives is endless! Yup, the problem is we're not fully committed to the Google world. Too many people want Windows and Office because it's what they know and use. Next device refresh, I think that that option is going to be on the cards, but no idea when that will happen. Unfortunately, right now, it means we have several hundred staff laptops that float between sites and home that are domain joined. "Make sure you log on to this before you go home" is not a management solution... 😱
adamsund Posted May 20, 2024 Posted May 20, 2024 DirectAccess was fairly simple to setup DirectAccess | Microsoft Learn Always On VPN is it's successor but not used it/set it up About Always On VPN for Windows Server Remote Access | Microsoft Learn Both of these would allow devices to connect to your network from home and showing as online in SCCM. Would that fix the issue?
Planehazza Posted May 20, 2024 Author Posted May 20, 2024 DirectAccess was fairly simple to setup DirectAccess | Microsoft Learn Always On VPN is it's successor but not used it/set it up About Always On VPN for Windows Server Remote Access | Microsoft Learn Both of these would allow devices to connect to your network from home and showing as online in SCCM. Would that fix the issue? It would, but my naïve mind has alarm bells ringing at the thought of essentially joining two networks together. Some of our users are dangerous...
Planehazza Posted May 20, 2024 Author Posted May 20, 2024 Windows device management in Google Workspace : https://support.google.com/a/topic/9695954?hl=en&ref_topic=9441473&sjid=8556768303991843204-EU Going to look into this more, as I think it would tick the boxes. It won't replace AD accounts and GPOs for on site devices over night, but if staff just need to access their Google account on a a remote device and we can manage the device with it, it should be quite good.
DrCheese Posted May 20, 2024 Posted May 20, 2024 It would, but my naïve mind has alarm bells ringing at the thought of essentially joining two networks together. Some of our users are dangerous... It's completely safe. If you do it properly (with a DMZ) your AOVPN clients can only connect to hosts you specify anyway. Other hosts on the end users network can't so much as breathe on your network & as you own the connecting device anyway it's setup as you want it
dhicks Posted May 20, 2024 Posted May 20, 2024 SO, this means that laptops for home use etc, are currently imaged EXACTLY the same as a standard PC, domain joined. A couple of similar threads: https://www.edugeek.net/forums/cloud-services/237812-integrating-google-accounts-intune.html https://www.edugeek.net/forums/cloud-services/232324-migrate-100-google.html You can use GCPW to allow user to login to Windows with their Google account: https://support.google.com/a/answer/9250996?hl=en Works even on domain-joined machines, or you can use machines not joined to a domain. The only thing it doesn't support, it turnsout, is USB 2FA keys, which we use for our staff, so instead we're using pGina: pGina - Open source Windows authentication We point pGina at Google's LDAP server where it can authenticate Windows users with their Google username/password. We're then using Action1 to manage devices.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now