Jump to content

Recommended Posts

Posted

Dear all,

 

Sorry if this has been asked but my tests keep confusing me!

Say I want desktop backgrounds / homepages to be different between staff and students...

Now I have a shared device (in a computer lab, 99% of the time students login, 1% of the time staff)

 

Testing intune shared device managed / not on the domain, logging on as a user gives the first login setup screen and gets stuck on apps, have to re-login, or I can hide that screen, but I'm noticing the home page/desktop stays as the previous user, until the next sync which can take an hour... I cannot have this, atleast login is fast.

 

Could try and fix the app issue (seems to be an issue removing an app what isn't even on) but its still like a 15 minute login until I had the screen, not very good in a classroom.

 

Due to the above I'm settling on hydrid and group policy, but my existing intune staff configuration policies and assigned apps end up eventually getting applied on my shared test pc, do I start re-assigning all this to device groups instead of user groups?

 

How are people managing shared devices and intune? Really for anyone doing it fully azure and intune as this would be my end goal.

 

Thanks for any help/hints or advice!

 

Regards

 

Martin

Posted

We are in the planning stage of a cloud migration for one of our schools. The basic conclusion is that we will be applying policies at the device level, we will have student shared devices and staff shared devices, but the appropriate user type will have to use the appropriate device. Truth be told, there isn't much difference in the policies being applied to the different device types.

 

Yes, it is annoying but the point is that Entra & Endpoint Manager ≠ AD & GPOs. We are considering going Chromebook for students down the line, which speaks volumes in itself.

Posted

I'm in the very early planning stages for Intune, but am already aware that Intune is not really geared towards shared devices. As you've seen, changes of policy aren't evaluated immediately, they're staggered, which is no use if different people are logging into a device.

 

Our shared devices are staying hybrid-AD with regular GP for now. What I'm looking to Intune for is for managing hybrid/off domain devices, that get assigned to particular users long term 1-to-1. That's the model Intune is designed to work with, really.

Posted

Thank you foofigher and dav, atleast I'm not going that insane, seemed to be so many choices in joining, deploying, and managing was wondering if I was missing something glaring.

Our places are heading towards chromebooks as-well bar a few IT suites, staff devices going 1 to 1 except supply, looks like hydrid+group policy is best for shared, and for those few user facing policies, although agreed its not that many.

I have found filtering (yesterday) which I may try out basically creating a shared device group and filtering them out of the already setup staff 1to1 policies and apps I have... having the casting app install itself on my test student device when a teacher logged in wasn't much fun but all part of testing, ironically I had been switching app deploys to user groups for 1to1 which I like as if someone requests something and replaces the device in the future it fully configures itself back, but comes with these niggles.

Eventually we would like no local AD, but we are not even close to that yet so will worry about it in a few years.

Posted

Device policies are where you want to be as others have said. We've got 5 IT rooms & 4 sets of laptops as Intune shared and they work well. We have no local AD.

 

Devices between staff and students used to have lots of different settings and configs but now aren't really any different except student devices just have a little less access to the settings menu. We deploy core apps to all devices and then if staff need anything else they use the company portal on their surface to install what they need.

Posted

I came to the same conclusion, in our school there isn't really any difference between staff and pupil devices. I use the public desktop for shortcuts to Office and Teams and anything else that everyone needs to have. I deploy a managed bookmark folder to Edge for staff users that contains links to CPOMS and Arbor and any other resource that the students do not require.

 

Initially I was unsure that Intune devices could be made to work in a shared environment but after a fair bit of research and tinkering around I am just about to deploy a few test devices to let users loose on to see what breaks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...