Jump to content

Recommended Posts

Posted

Afternoon,

 

I'm having a tough time getting my head around the thinking for InTune. I understand it and that is possibly the way forward, but going from shared machines where settings are downloaded depending on usertype on logon over to pupil/staff dedicated machines is troubling me.

 

How have others got over this? On-site is a lot more flexible.

 

I'm interested in how others think or changed their thinking.

 

Gareth

Posted

I've dabbled with Intune a fair bit since COVID, others here may well have done more in a production environment though. After attending the Google IT Admin Summit last week, I am not ashamed to say that I feel like I have backed the wrong horse on this, things just seem better thought out with Google, most changes can be applied on the fly, no need for a sync / restart / investigation into why the policy didn't apply. Literally the only thing that would hold me back is if there are win32 apps being used that don't have a viable web or Android alternative.

 

It seems that the best compromise with Microsoft, is to be hybrid joined, but then you've got the complexities of running and supporting two systems. At least this way you can still have user policies that are applied at login, rather than an unknown amount of time.

Posted

I mean google is like next gen compared to Microsofts offering - I disable a chromebook it's done in a couple of mins max wherever it is in the world, I add an app, it starts appearing generally in a matter of seconds.

 

For every windows device you set up, depending on your deployment method, you san set up 10-50 chromebooks in the same amount of time.

 

Microsoft and mobile devices remind me of Capita/ESS vs Bromcom/Arbor- 10 years behind suck in a quagmire of past bloatware and poor programming, simply put unable/impossible to catch up.

Posted

Thank you both for your honest replies and feedback. It's exactly how I feel. I've not tried Google for managing Windows devices as Welsh Government offer InTune/Autopilot for free to schools. I'm just experimenting, but there are so many red lines that need to be worked through before it gets pushed out to the school(s).

 

Gareth

Posted

We opened a "cloud" only (*windows*) secondary school a few years back and there were quite a lot of teething issues - but I think it's probably as good now as we're going to get it.

 

I don't think InTune needs to mean designated devices for staff and students.

Posted
but I think it's probably as good now as we're going to get it.

 

Comparing that to a normal GPO-led system, are you actually seeing any benefits to it? Or was that more a "as good as it'll get, but still not as good"

 

Steve

  • Thanks 1
Posted
Thank you both for your honest replies and feedback. It's exactly how I feel. I've not tried Google for managing Windows devices as Welsh Government offer InTune/Autopilot for free to schools. I'm just experimenting, but there are so many red lines that need to be worked through before it gets pushed out to the school(s).

 

Gareth

 

Yeh the LA are forcing us to move to HWB intune etc in a year or two and deleting their active directory etc.

 

Luckily I won't be there at that time to have to deal with that

Posted
Yeh the LA are forcing us to move to HWB intune etc in a year or two and deleting their active directory etc.

 

Luckily I won't be there at that time to have to deal with that

 

Not in NPT are you?

Posted
Comparing that to a normal GPO-led system, are you actually seeing any benefits to it? Or was that more a "as good as it'll get, but still not as good"

 

Steve

 

No benefits at all, but we wanted to see if we could go completely serverless - which we have.

 

You're still borked if you lose your internet connectivity, but no servers to continually patch is a godsend.

  • Thanks 1
Posted (edited)
No benefits at all, but we wanted to see if we could go completely serverless - which we have.

 

You're still borked if you lose your internet connectivity, but no servers to continually patch is a godsend.

 

Thanks, that's interesting to hear and as expected really! Still seems to only really be of use for off-site or 1-to-1 (at least for secondary, primary is a different kettle)

 

Steve

Edited by Steve21
Posted (edited)

I think autopilot/Intune is fantastic for what we use it for where I am, but it’s clearly a design by Microsoft that assumes everyone is *like* Microsoft - a global org with 1:1 devices and hot and cold scripting ninjas on tap if necessary to do something clever.

 

In many ways it’s better than SCCM from the architecture/strategy view, while still having loads of gaps at the sharp end where something that was trivial in SCCM is difficult or impossible right now in Intune.

 

Its benefits revolve more around not having device updates fail in Myanmar because the local SCCM DP went wonky and there no techies in that region at the moment, or worrying about how your “standard” laptop model isn’t available in Belize. Those are real problems btw (my last two weeks have been insane) but probably not that common for most of their customer base.

 

Bit like “one size fits all” clothing - technically possible, but it won’t fit anyone well.

Edited by Roberto
Posted
I think autopilot/Intune is fantastic for what we use it for where I am, but it’s clearly a design by Microsoft that assumes everyone is *like* Microsoft - a global org with 1:1 devices and hot and cold scripting ninjas on tap if necessary to do something clever.

 

Yeah, this is the conclusion we came to as well. It's built with Microsoft in mind. For them, not being 1:1 just doesn't compute. I learnt pretty quickly that user level policies are utterly useless with intune as it applies them at device level anyway.

That I *still* can't do WPA2-Enterprise 802.11x auth with device certificates instead of user certs just blows my mind.

 

I've come across bugs that just make no sense & only have it confirmed as a bug by some random MSFT poster on Reddit, rather than it being documented anywhere. Autopilot sometimes fails with devices that are exactly the same type and configuration? Why?. Who knows. Just re-run it.

 

I completely agree with posters above that Google have it licked up perfectly. A Chromebook gets everything within minutes out of the box. Policy changes apply depending on users instantly. If I disable a device, it's done instantly. It's so beautiful and it utterly confuses me why MS haven't just cloned ChromeOS but in an edge flavouring yet.

 

Intune is.. meh whenever it feels like it - If it even has the feature you want at all. I wanted to quickly disable a device once and basically brick it. Nope, no quick way.

 

Yuck.

Posted

You're still borked if you lose your internet connectivity, but no servers to continually patch is a godsend.

 

Surely you have redundant internet connections?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...