Jump to content

Recommended Posts

Posted

Schools who use Google Workspace for Education Fundamentals have any of you purchased one (or more) of the above licences to manage other devices?

 

I'm specifically looking at Windows devices and if by purchasing the above you can manage them? Documentation seems to be directed towards Android and IOS devices with limited mention of Windows.

 

Alternatively does anyone use a 'higher tier' of Google Workspace and manage Windows devices? How do you find Google Management of Windows Devices?

Posted

Hi, yes, the licenses you have mentioned would allow you to manage Windows devices with their "enhanced desktop protection." However, you're better off just upgrading your licensing to Education Standard or Plus, as Windows device management is included in those licensing tiers anyway.

 

We have Education Standard, which allowed me to set up GCPW and enroll our Windows devices into Googles Windows device management setup. It does have its quirks and annoyances, but Intune wasn't a good fit for us at the time, and to be honest, no platform tends to be perfect.

 

Each staff laptop/desktop is assigned to their Google account, which in turn has settings applied to it. I manage the updates, user access level, BitLocker at the top level, and then apply custom settings (OMA-URIs, similar to Intune) to the individual OUs. This can include things like hiding settings, blocking unenrollment, disabling OneDrive, and setting a wallpaper.

 

Hope this helps, and please let me know if you have any more questions!

  • Thanks 2
Posted

Thanks for the replies guys.

I'm not looking to upgrade our environment just yet, just looking to possibly purchase a few licences and have a play around managing Windows via Google rather than having multiple platforms as we do now.

  • Thanks 1
Posted
Thanks for the replies guys.

I'm not looking to upgrade our environment just yet, just looking to possibly purchase a few licences and have a play around managing Windows via Google rather than having multiple platforms as we do now.

No worries, one thing I will add - if you choose to go with one of education licensing tiers (standard or plus) you have to license all of the users in your tenant. You can't just license staff for example...!

Posted (edited)
No worries, one thing I will add - if you choose to go with one of education licensing tiers (standard or plus) you have to license all of the users in your tenant. You can't just license staff for example...!

 

Yep, that's why I wanted to know about the Endpoint Upgrade licence, so that I can 'play around'.

 

That and a lot of our users never touch Windows anymore so this may be just as cost effective.

Edited by ThatBoringBloke
  • Thanks 1
Posted
Its users. So the person enrolling the device as a minimum needs a licence. Ideally you want to go Plus these - then its everyone + loads of security tools and features + other bells and whistles - well worth it.
  • 2 weeks later...
Posted
hmmm, does google device management work with Ipads as well? we tryting to get some monitoring software for Ipads maybe google will do
  • Thanks 1
Posted
hmmm, does google device management work with Ipads as well? we tryting to get some monitoring software for Ipads maybe google will do

 

Yes, you can use it to manage iPads within the Google console. But my advice would be... don't. There are many better options out there such as Jamf, or Mosyle which is free, albeit slightly limited. But I would look there first :)

  • Thanks 1
  • 1 year later...
Posted

Yes you can purchase the user based endpoint upgrade but my reseller is having difficulty sourcing the device based variant. Every reference to it on google still states coming soon all the way back to Feb 2024...

Posted

Ohh, I see what you mean now.

 

Google recently refreshed all the licences and separated out Endpoint Education Upgrade licenses for education, but these are only assigned to a user not a device. If they didn't add that as a feature when they refreshed their licenses, I dont think they will.

Posted (edited)

For us, all pupils are using ChromeOS, so its only the teachers that need an Endpoint Education Upgrade license.

 

If you also needed all pupils to have a licence, then you would probably need the Standard licence upgrade.

Edited by TwistedHelixis
Posted

We only need the fundamental level as we are a primarily MS environment. The fact that Google insist on having to upgrade the whole cohort to the standard licence instead of a few makes it financially nonviable. I do have a few tablets and some android phones I want to lock down via google at a device level as opposed to user level though. They are shared and only a few select people have google accounts set up. Hence the hope with the device endpoint education upgrade path...

Posted

 

54 minutes ago, Spookyville said:

We only need the fundamental level as we are a primarily MS environment. The fact that Google insist on having to upgrade the whole cohort to the standard licence instead of a few makes it financially nonviable. I do have a few tablets and some android phones I want to lock down via google at a device level as opposed to user level though. They are shared and only a few select people have google accounts set up. Hence the hope with the device endpoint education upgrade path...

I have discovered that I can pretty much lock down the Windows device using Device GPO's if it is joined to the Domain. Then use GCPW to authenticate the user.

This works if you have different Staff and Student devices.

 

Doesn't solve your issue for tablets and phones though.

Posted
13 minutes ago, ThatBoringBloke said:

 

I have discovered that I can pretty much lock down the Windows device using Device GPO's if it is joined to the Domain. Then use GCPW to authenticate the user.

This works if you have different Staff and Student devices.

 

Doesn't solve your issue for tablets and phones though.

Also, don't forget that GPO's are just registry changes at the end of the day. I have used an RMM to deploy scrips to endpoints that do exactly the same as the domain GPOs would have done. Things like account lockouts, time servers, proxy settings, printer deployments, mapped drives, all the security lockdown settings etc, can all be done using powershell and without an onsite DC.

 

I think the free version of GCPW comes with making sure end users are all only standard acounts.

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...