Jump to content

Recommended Posts

Posted

Hi everyone

 

Longtime lurker, first time poster (well, this account, I've long since lost my last one..)

 

I'm in the process of getting a Azure-only student Intune deployment hammered out for our ICT suites for reimaging over the summer and wanted a sanity check..

 

Our environment currently is Google Workspace with onprem AD, other than staff laptops that are already Azure/Intune and working fine. Most depts are using Google Classroom for everything, with students uploading and downloading as necessary, but some things like Python need local folders to work. I'm testing with W11

 

#1 insanity - I've been trying to avoid OneDrive for students as we're not a Microsoft site, but I ​_cannot_​ get Mapped Drives to work properly with Shared Device enabled. It seems that if the profile is deleted, Intune just gives up mapping it next time. I'm using the templates (due to the below)

#2 insanity - am I right in thinking that for scripts to run against a user they need to have access to the engine (cmd or powershell) enabled, unlike with GPOs?

#3 insanity - it just seems to ignore my user group assigned policies, is that normal? I've read that Microsoft have said it can take hours for some settings to apply and it's best to apply them to computer groups if it's sensitive?

 

Is anyone using Shared Devices successfully in their schools with students? If so, what's your model for it? Am I better throwing in the towel and going Hybrid Joined?

 

Thanks in advance!

Posted (edited)

Yes we have it working well. To address the issues you listed

1) don't do that. Just access via the web.

2) don't do that. Just take the vanilla OS, settings use them.

3) don't do that. Use Machine policy only.

 

 

Basically its not a replacement for traditional AD/GPO managed IT Suites. But if you can get away from needing network drives, traditional windows printers, and per-user restrictions and settings, its great.

 

We run a blend of trad AD/GPO and pure Intune. For all of the non technical courses Intune managed shared devices are 100% better than the AD/GPO managed solution of yore. But as soon as the workflow unavoidably requires 'local' data persistence (e.g. Photoshop / Premier / most coding and development environments compsci teachers are comfortable with, etc etc,) then the AD/GPO managed devices are best.

 

 

Edit: I'm expecting to hybridise our AD/GPO devices this coming year, just to reduce administrative/cognitive load on managing some things in both places (defender, updates etc), but where fine-grained control with a guaranteed first-time logon experience with per-user/group settings interacting with other on-prem server resources being required on a shared Device, I don't see Intune gaining ground any time soon.

Edited by psydii
  • Thanks 1
Posted

Thanks for the quick reply psydii

 

Ok, that helps a bit. I hope you don't mind some further questions?

 

- so you don't do OneDrive known folder redirection for students?

- are you using the Shared Device and Education Policies, local storage off?

- For the latter, are you using hybrid joined with Intune still, or vanillia AD and GPO? I was thinking I'd have to go Hybrid because of software deployment..

 

Thanks!

Posted
Thanks for the quick reply psydii

 

Ok, that helps a bit. I hope you don't mind some further questions?

 

- so you don't do OneDrive known folder redirection for students?

- are you using the Shared Device and Education Policies, local storage off?

- For the latter, are you using hybrid joined with Intune still, or vanillia AD and GPO? I was thinking I'd have to go Hybrid because of software deployment..

 

Thanks! ��

 

Others may have fought with this to achieve closer to what you want. However, to answer your questions about how we do it and what I meant:

 

- KFM: Not on the intune shared devices. We do an equivalent on the AD/GPO managed devices, but using a mechanism that predates KFM. (If I was implementing it now I'd use KFM for the AD/GPO devices)

- We use the Shared Device option. We do not use the Shared Device with OneDrive policy. This I believe does not force the "no local storage" option, but prevent the OneDrive sync client from running.

- Windows hybrid joins by default if your ad and 365 instance are linked via AAD/Entra Connect. We use Configuration Manager to on prem software deployment (and monitoring). We have a test group where we co-manage them. This co-management mode is what I meant when talking about hybridising in the future.

  • Thanks 1
Posted

That's really helpful, thank you!

 

I'm interested in if anyone else has success with it, I have reached out to the contacts that I have but none of their schools are running Intune yet..

Posted

Same as above really, which is why we don't use it in shared places and use hybrid. Still don't think it's truly fit for purpose unless you're happy to make lots of changes/workarounds to "make it fit"

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...