Jump to content

Recommended Posts

Posted

In my prior job, all our devices were co-managed, joined to Entra ID, and managed with Group Policy and Config Manager.

 

Since taking up my role at my new school, I've been managing a pure Entra/Intune based setup for all our clients. Servers are still on an onsite domain.

 

Now, after 4 months here I am struggling to see what the advantage, for a school, of the fully Entra/Intune based setup.

 

Intune is clunky, slow to implement things. Policies applying are very hit or miss. I shouldn't need to wait a random, indeterminate, amount of time for a change to apply.

 

Sure, there are some advantages - being able to push policy changes for remote workers, for example.

 

But all in all, in a school environment? I'm not really convinced a fully Entra/Intune setup makes sense. Am I alone with this?

Posted

Nope, apart from the "cost savings" that people associate with removing on-site servers etc, everything seems like a worse version of Hybrid (Best of both worlds imho)

 

You get more functionality, reliability, and options using a hybrid setup as you can still do all the off-site bits for any devices that roam

 

Steve

Posted
I'm at the point now where I have given up on Microsoft actually improving it to the extent that we'd all like. We are considering moving to Chromebooks for anything that doesn't rely on win-32 applications.
Posted

We currently do things on prem, using MDT/WDS/PDQ to push out deployments, updates etc and no matter how I look at MECM/Intune/Autopilot for a purely cloud based setup, the process is simply not as streamlined and smooth as I have it now, but I'm being forced to look at these things because Windows 11 is not supported by MDT. The only advantage I can see with having devices enrolled in Intune is so you can then do conditional access policies, that's about it. The actual deployment and update side seem almost antiquated.

 

Depending on a trust move, like @foofighterjim says, we may even go to Chromebooks for that side of things if we truly wanted a cloud device setup.

Posted (edited)

I love intune. I'm in a use case where it does make significantly more sense than something like SCCM. However, it's painfully apparent that it lags far behind SCCM in terms of how many ways it allows you to solve problems. Reporting needs work.

 

I think it's going to replace SCCM at some point and I wouldn't advocate for setting up a new SCCM org at some point... but to someone who has a well specified, well maintained SCCM infrastructure that meets their needs I wouldn't suggest going any further than co-management at this point.

 

... and that's before we even get on to it not being that well suited to schools because they more or less assume 1:1 user to device ratio... which is fine for me now but really not helpful for education.

Edited by Roberto
Posted
I love intune. I'm in a use case where it does make significantly more sense than something like SCCM.

 

Which use-case is that? Curious to know why any school would take InTune over SCCM unless 1:1

 

Steve

Posted (edited)
Which use-case is that? Curious to know why any school would take InTune over SCCM unless 1:1

 

Steve

 

I'm not in edu IT any longer. I work for a global business. We're in... I can't even remember how many countries we have a presence in... and setting up SCCM DPs globally is possible but a massive pain in the backside and when you only have two or three people in a region, it's disproportionate to what we need... so at that point Intune + Autopilot starts to feel pretty groovy actually. I've set up autopilot processes to support people in every continent in the world. Well nearly every continent - not sure if the poles are continents or not!)

 

I think we have a similar architecture to Microsoft themselves. So essentially they're designing their infra with an eye mostly on themselves and businesses like them these days.

Edited by Roberto
Posted
I'm not in edu IT any longer. I work for a global business..

 

That explains why then... :p The OP was asking about school environments, so totally different setup to why InTune may work for that as it's remote users rather than a single site etc.

 

Steve

Posted
That explains why then... :p The OP was asking about school environments, so totally different setup to why InTune may work for that as it's remote users rather than a single site etc.

 

Steve

 

Indeed - I was trying to say I think Microsoft have designed intune to solve my problems, not your problems. It's bad design tbh.

Posted
Indeed - I was trying to say I think Microsoft have designed intune to solve my problems, not your problems. It's bad design tbh.

 

Yep, it's very 1:1/remote-user based in it's logic, especially with the slow updating etc.

 

Steve

Posted

We have both pure Intune/Entra and pure AD/CM managed devices. Horses for courses. We have a fleet of laptop trolleys (I know, 2006 called and wants is strategy back), these work *really* well as intune managed devices - we don't offer printing or any access to legacy apps - its all fully digital web based with 365 auth or nothing. Any device set that requires classic win32 apps is fully AD/CM managed, though we are exploring hybrid for some scenarios.

 

We are all familiar with the classic/legacy set up - and how much of a pain it is trying to make that work via pure intune - my solution: don't bother. The legacy stuff will eventually age out.

 

But I think there has been a shift (again) at Microsoft and they understand that AD/CM (maybe hybrid?) is really here for the long haul for many use cases. CM is pretty mature and workloads only move to intune when it makes sense. Server 2025 has a lot of AD work going on, so for now, hybrid and on prem is here to stay.

 

If we could ditch legacy design (and thinking) and capabilities that AD/CM offers, intune would be fine, but it's Windows and we expect the flexibility that AD/GPO/CM offers.

 

IMHO the key problem is actually fundamental: all MDM's are built from a technology stack that was designed and conceived to manage pre-iPhone smart phones, And Entra (and Google's equivelent) were designed by people operating at a global scale. This does not align well with medium size orgs that expect to shape the core IT service to their needs. Its fine for very small orgs or very large/global orgs but most are in the middle and the limitations are rough.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...