Jump to content

Recommended Posts

Posted

One of the schools that I support has a traditional setup of Server with AD and group policies in place for many years. They have also have Office 365 setup and all accounts from AD are synced with Entra (formerly AAD!).

 

So far so good. The school have planned to go with some new Windows SE devices running Windows 11 SE (another story about that saga) and so I have successfully imported many of their existing GPOs into various CSPs. That seemed to go ok.

 

The existing hierachy of GPOs on the server are:

existing OUs.png

We tend to have loads of "little" GPOs rather than 2 or 3 huge ones. So we have an "All Users" which has some key settings for everyone then specific ones in the OUs for Pupils and Class logins and individual logins and Staff etc which build on those - so obvious settings so that students cant see or mess with the C drive - while we trust staff to have C drive access ! :)

 

Quite a few failed to import - mostly as setting not applicable. However more than enough did to use as the basis going forward.

New CSPs.png

 

From what I can see I believe all the device scoped CSPs are applying correctly. However I can not work out what is happening with the user scoped CSPs.

 

Even though I have assigned groups to relevant CSPs they are not being applied when the pupil logs in.

 

 

What I have found is that the "All Users" CSP does seem to apply - or at least does for "staff" and the admin accounts - ones that I have assigned EMM licenses to - however if I log on as a "student" then nothing applies not even the "All Pupils" CSP which I have assigned to the relevant Security Groups.

 

I am clearly doing something wrong - but I really cant see what!

Posted
The policies should get applied after the device syncs after the user has logged in. Depending on the policies you are trying to deploy this does not always work well if you have staff and students use the same computers with different policies this might not be the best solution.
  • Thanks 1
Posted
The policies should get applied after the device syncs after the user has logged in. Depending on the policies you are trying to deploy this does not always work well if you have staff and students use the same computers with different policies this might not be the best solution.

 

I had about this - which I think is daft! - if you cant guarantee the "tstate"/user experience of the device using CSPs - AT LOGON - whats the point of them? Yes in this case I would say that over 98% of the time the "pupil" laptops are going to be signed in by pupils so I could apply these CSPs to the device - but I do know that TAs use them.

 

The staff machines would be the ones that worry me more as we deliberatly dont restrict staff as much as pupils - so if a pupil walks upto a staff device and signs on - then chaos could ensue!!!!

 

However I did leave the test machines logged in as a pupil for maybe an hour and NO change!!! :(

Posted

After some "playing" around yesterday I am still confused about the whole user side of CSPs.

 

I can not get any user CSP to apply to the pupil accounts I am testing with. I can apply those CSPs to the device and then they apply to everyone who logs onto the device - which I do not want.

 

If i have an account called say class1a and its a member of a security Group called "ClassLogins" then surely all I need to do is assign the security group "ClassLogins" to my user CSP and it should work.

 

Is it because my user "class1a" is synced from an on premises AD and is not a pure MS Entra (AAD) account???

Posted

I cant think what else to try. User is a member of "ClassLogins". My CSPs are all assigned to "ClassLogins". I have created a policy set with 3 CSPs in it and assigned that to "ClassLogins". I have just now created a "Scope" tag and assigned that to Class Logins and changed the Scope on my CSPs and PolicySets to that new scope only.

 

Still nothing being applied! My device CSPs are all working fine!

Untitled1.png

Untitled2.png

Posted
I cant think what else to try. User is a member of "ClassLogins". My CSPs are all assigned to "ClassLogins". I have created a policy set with 3 CSPs in it and assigned that to "ClassLogins". I have just now created a "Scope" tag and assigned that to Class Logins and changed the Scope on my CSPs and PolicySets to that new scope only.

 

Still nothing being applied! My device CSPs are all working fine!

[ATTACH=CONFIG]71947[/ATTACH]

[ATTACH=CONFIG]71948[/ATTACH]

 

Is the user you are testing this with licensed for Intune? What are a few of the settings you are trying to set differently for Staff vs Students? I can see if I can make them work in my environment. For us we don't really assign different user policies if a staff member uses a computer in a lab, they will get the same policies as the students get. This way we avoid any delays in waiting for Intune to sync when a different user logs in.

Posted
Is the user you are testing this with licensed for Intune? What are a few of the settings you are trying to set differently for Staff vs Students? I can see if I can make them work in my environment. For us we don't really assign different user policies if a staff member uses a computer in a lab, they will get the same policies as the students get. This way we avoid any delays in waiting for Intune to sync when a different user logs in.

 

As this is for a Primary school we tighten down the Pupil logins as much as we can - just stop them messing around and to stay "on task" :)

 

So hide drives A-D etc, hide the MS Store app, remove all settings/control panel from the Start Menu, remove the right click on a file, remove Task Manager from the "Ctrl Alt Delete" screen etc etc.

 

However the more I think about this the more it "could" be a licensing issue. Basically for one more year the school are stuck in a multi-year deal on Office365 A3 deal. So what they did was to buy "Enterprise Mobility + Security E3" so that we could transistion the staff over to fully Entra (God I hate that name what was wrong with Azure AD!!!). However the Business manager got a deal for a few hundred Windows SE devices - which has just fallen through. However because of this the plan was to setup those new Windows SE devices (close to 200) for the children to use and we would also take the best 100 exisiting laptops and reimage those and join direct into AAD. All of this was going fairly well - had been hoping to use MDT to speed up process - but gave up and have been testing with just a standard Windows 11 iso with a deployment package to do the rest - about 20 minutes plus all the additional time to sign in and download apps from the cloud :(

 

If however you are saying that we need an EMM license for EVERY pupil then it would seem that we will have to wait until next year when they can buy the full Microsoft 365 A3. As it appears that we dont get the "ratioed" student use benefit if we have Office 365 A + Enterprise Mobility + Security A3 that we would get if had Microsoft 365 A3???

Untitled3EMM].png

God I hate Microsoft licensing

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...