Jump to content

Recommended Posts

Posted (edited)

Hi there,

 

Just putting some feelers out there as to best practice when using Intune. :hat:

 

Currently for our cloud tenancy (no hybrid), I have our Windows 11 systems named based on their Asset ID... just makes it easier to pinpoint a system as they all have visible stickers on the sides of them.

Then, I created a few core Security Groups:

  • Admin Computers
  • SLT Computers
  • Curriculum Computers

 

I then place the respective systems in their group.

 

 

But, over time I have found I need further but some overlap. ICT suites for example. They are curriculum so the systems belong in "Curriculum Computers" group, but sometimes, they need specific apps that other "Curriclum Computers" need.

To get around this, I have made further Security Groups:

  • ICT Room 1
  • ICT Room 2
  • Medical Room Computers - computers which would be part of Admin, but again, have specific app requirements.

 

 

The beauty of Intune is a device can be part of more than one group which makes it easier to customise what a system gets in terms of apps and config policies.

I really hope there may be functionality in the near future that would allow me to affect bulk action changes to an entire group. E.g. restart ICT Room 1. So I can reboot all systems in that group at the same time, rather than having to manually.

 

Does this sound like the best way to do this? I would be grateful of any other ideas, words of wisdom or criticism! :mullet:

 

And lastly, before I forget. What do you Intune users do about Windows updates? I have always used WSUS, but now use the update rings on Intune. This is fine, but takes some time to download and install to client stations. Does anyone still use WSUS and if so, how best do you config the systems to look for a local WSUS server?

 

Thanks as always :nerd:

Edited by talksr
  • 1 month later...
Posted

We've not gone down the route of setting up multiple groups for devices for apps/settings, but instead have setup filters do basically do the same thing.

 

That was we can create say a "2D Design App" filter that has the criteria for the computer names we want in it, then apply that to all devices so we know that as long as we've named it correctly it will get it without having to go back in and update any group membership.

 

It also appeared to be a faster method than using a dynamic group especially when first building the device as we push some apps out during the initial join.

  • Thanks 1
Posted
On 25/03/2025 at 10:14, Boredguy said:

We've not gone down the route of setting up multiple groups for devices for apps/settings, but instead have setup filters do basically do the same thing.

 

That was we can create say a "2D Design App" filter that has the criteria for the computer names we want in it, then apply that to all devices so we know that as long as we've named it correctly it will get it without having to go back in and update any group membership.

 

It also appeared to be a faster method than using a dynamic group especially when first building the device as we push some apps out during the initial join.

 

That's an interesting approach. I had never really looked at filters, but the way I always do things is the hostname is the device asset ID. Just makes things easier for me. Never seen that approach anywhere else I have worked, but it is helpful for identifying devices quickly and also if an auditor is wanting to check. 

 

On 25/03/2025 at 09:57, Alis_Klar said:

<RANT>

I've got so used to using AD and GPOs in OUs over the years that InTune and EntraID seem a big step back in terms of organisational structure.

 

Google Workspace kept the OU based model.

 

There are third party solutions such as CoreView aimed at global corporations who must struggle with this.

 

https://www.coreview.com/blog/azure-ad-administrative-units

 

</RANT>

 

Glad I am not the only one!!
Wasn't aware of the 3rd party solutions. Thanks, I will have a look at that.

 

Not sure if this would help you, but I used Powerpoint to create the following for my office wall. It helps visualise what groups we have to easily differntiate. There are other graphics I have done which show what apps are assigned to each respective group. I also deploy our printers as apps so it is handy for ascertaining what printers a device in a given group would pick up. 

 

 

Screenshot2025-03-26133144.thumb.png.3648a36fa1ac3bc5a3bfda93cde59ad7.png

In addition to the assigned sec groups, I also have two device categories which are just "Admin Computer Systems" or "Curriculum Computer Systems".

I have my network segmented, so admin systems are totally seperate to the curriculum ones. 

 

  • Like 1
  • Thanks 1
Posted

Thanks for the tips.  Are there any online guides you would recommend for the 365 novice? 

 

If you are a ANME member there is a great resource here from a meeting i did not attend.

 

https://www.anme-portal.co.uk/member/meetings/meeting/?meetingid=73873&documentid=58325

PPTX https://www.anme-portal.co.uk/member/securefile/?id=157929

DOCX list of links https://www.anme-portal.co.uk/member/securefile/?id=157945

 

I need to look through all these over Easter!

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...