Jump to content

Recommended Posts

Posted

To Intune or not to Intune…

 

At the start of this year, we were seriously considering moving away from on-prem AD and going all-in with Intune. After extensive testing, though, the cracks showed very quickly.

Here’s what we ran into:

 

  • Policy application is inconsistent – Some machines apply policies instantly, others take hours (or never). We saw settings half-applied, conflicting, or simply ignored. For a controlled school environment, that’s a nightmare.

  • Reliability with shared devices – Education doesn’t fit neatly into Intune’s “one user, one device” model. We have shared PCs, laptops, and labs. Intune just doesn’t handle multiple user profiles well, and policy inconsistencies multiply.

  • Drive mapping and legacy dependencies – We still rely on mapped drives, and Intune + cloud identity doesn’t play nicely. Scripts for drive mapping are hit-and-miss, and support for legacy infrastructure feels like an afterthought.

  • App deployment is flaky – Some apps push fine, others stall, fail, or report success when they haven’t actually installed. Troubleshooting is opaque compared to SCCM or GPOs.

  • Limited control and visibility – Reporting is basic. Troubleshooting why something didn’t apply often comes down to guesswork. Event logs and error messages are vague at best.

  • Connectivity dependency – Devices that aren’t online regularly don’t update properly, leaving gaps in compliance. On-prem GPOs don’t have that issue.

  • User frustration – Students and staff logging into a freshly built device often hit delays while policies and apps “drip-feed” in. With shared classroom devices, you don’t get the luxury of a single user waiting 30 minutes for their desktop to be usable.

 

To give credit where it’s due, Intune does have strengths. Windows Updates, driver/firmware updates, and general patching were handled really nicely. I also liked the centralized view of compliance.


But overall, the way Intune applies (or doesn’t apply) policies gave me the ick. It’s unreliable, unpredictable, and ultimately not suited to the education space as it stands.

 

Looking ahead to next summer, I can’t justify moving us fully to Intune. I’m instead looking at SCCM with Intune hybrid mode to get the best of both worlds.

 

Has anyone else gone down the hybrid route? Would be interested to hear how it compares in real world education use.

  • Like 1
Posted

Drive mapping can be managed by InTune Policies, we imported custom ADMX files. Works great.

 

The rest I mostly agree with. It works well for 1:1 devices. Education is like this in a lot of the world, but the UK is a bit backwards in this respect. Here in Australia every student has their own laptop and InTune works well.

  • Like 1
Posted

Interesting seeing your views on this, having been full Intune for 3 years in a secondary school with no 1:1 devices.  For context, we don’t use autopilot and assign all policies and devices via group based on device naming convention.

 

Made a few comments that might help;

 

Policy application is inconsistent - If applied to the user - however when applied to the device is works well. When we reviewed what policies student’s vs staff need, there isn't really that much difference anymore, staff and student devices are pretty much the same, bar maybe access to a couple of specific settings menus.

Reliability with shared devices - We're not 1:1 and all students would use a shared Intune device. Apply policies to the device, not the user and we have no issue with them not applying.  

Drive mapping and legacy dependencies - We haven't really had to do this. If you're not moving to a full cloud environment with everything in SaaS then you might experience issues.

App deployment is flaky - We find app deployment quite good, although it can sometimes take a while to populate on the devices. A recent example was our casting software needed an urgent upgrade to fix an issue, we pushed it out at around 7am and by 9, all the devices that were on had been update the others followed when they came online. We push core apps to all staff and student devices and then use Company portal for specific department apps.

Limited control and visibility - I would agree and say there is less visibility, but I’m not sure what more visibility I would need - we don't often have issues with Intune devices that a reimage doesn’t fix.

Connectivity dependency – I do agree on this point, however when the device comes online it should do all it’s update, and the reporting is quite good for windows update/apps.

User frustration - We don't experience this, all our Intune devices are ready to go within 30sec to 1min of being logged into for a new user, for an existing user - it can be as little as 10 seconds before a working desktop.  

 

D

 

 

Posted

With shared devices, Intune policies should only be applied to the device, not the user. We've just had RM do a project for us over the summer to move us over to Intune, and all the apps and configurations were applied to the device (with 2 groups, one for staff devices, one for student devices), rather than the user, and we were encouraged to leave the device on for an hour or two to ensure it picks everything up before the user gets hold of it.

 

Weirdly, there is a "Sync" button in the Settings app, but it clearly doesn't operate like gpupdate does as policies are still outdated even after syncing is supposedly successful.

Posted

I have just started testing Intune and have been having the same issue with assigning configurations via user groups as well i.e they don't apply straight away

 

I did try assigning the configuration to the device but found that it applies these settings for all users including admin users and even the local admin user. Is there a way around this?

 

I like to lock down the system settings so that only the Display and Sound settings are accessible to users. If I do this to the device I won't be able to get to the other system settings when logged in as an admin 

Posted

I was quite anti-Intune a few years ago but after spending time getting everything configured it actually works pretty well. Once I realised that I only really needed standard user types across all devices then things just clicked into place. We've been Intune for about 18 months now and I can confidently say that my workload has drastically reduced.

  • Like 1
Posted (edited)

We do Hybrid and pure Entra Joined and getting rid of Hybrid hopefully, everything is device group based so not sure about the user policies. Once over the initial frantic changes during setup I don't mind the days it takes to gradually change something and Fresh Start is great (apart from Bios TPM reset prompts on some devices where they have to press Yes to continue the process) They can always go to the company portal app and install an app in an emergency, or run a sync

 

Third party antivirus or remote agents saves waiting days for Intune to update to say something has been installed or a device is actually encrypted.

I think hybrid is a dead end and only going to get more difficult to keep working and take more hours to do so, legacy apps the same where the supplier either won't update or won't move to the cloud.

 

 

 

Edited by robintech
Posted
12 hours ago, networkmangler said:

I have just started testing Intune and have been having the same issue with assigning configurations via user groups as well i.e they don't apply straight away

 

I did try assigning the configuration to the device but found that it applies these settings for all users including admin users and even the local admin user. Is there a way around this?

 

I like to lock down the system settings so that only the Display and Sound settings are accessible to users. If I do this to the device I won't be able to get to the other system settings when logged in as an admin 

One of the main issues I encountered during testing was that policies were so inconsistent, they would either take a long time to apply, not apply at all, or only kick in several minutes after the user had logged on.
 

Like you, I want to lock down user accounts, but I can’t risk relying on policies that don’t apply properly. We were fully prepared to move over to Intune, but on the final day of term I pulled the plug after realizing how disruptive it could be come September so went back down the SCCM\MDT route.
 

I’m now reviewing our options again. At this stage, I’m leaning towards SCCM with Intune integration, or possibly another device management tool altogether. I’m not comfortable moving to a full Intune setup just yet.

Posted
On 20/09/2025 at 09:07, DWilson1997 said:

... we don’t use autopilot and assign all policies and devices via group based on device naming convention. ...

 

 

@DWilson1997 Can you say some more ? E.g. if you're not using autopilot how do devices get set up? 

Posted
39 minutes ago, mrstrong said:

 

@DWilson1997 Can you say some more ? E.g. if you're not using autopilot how do devices get set up? 

 

Probably some reason why we shouldn't do it this way - but it works very very well... we are able to ensure all software is on, reporting in correctly and all updates are installed before delivery to the user

  1. New device reimaged with blank Windows 11 image
  2. Log into the device with account with the "Microsoft Entra Joined Device Local Administrator" role
  3. During the OOBE process, set the device name (which corresponds to dynamic groups in Entra ID)
  4. Reboot device - The device then sets itself up with all the correct policies and software, takes about 1 hour.
  5. Run Windows Update manually, to install BIOS, Drivers and Updates then reboot
  6. Device ready to use

 

 

  • Like 2
  • Thanks 1
  • 7 months later...
Posted

finally got round to trying this yesterday! Used a usb prepared with rufus Windows 11 Education 24H2 iso I had.

went through the standard windows setup screens (guess i could skip some with a autounattend.xml ? ).

 

I didn't get asked for machine name though during the OOBE,  any ideas why?

Posted

I am looking into joining our computers to our Welsh govt provided Hwb system, which is Intune,  still getting used to it.

I think I had to set up the computer name via Intune when I imported the computers hash, it then picked the name up when autopilot took over.

I used a standard ISO from Microsoft, problem is it was always defaulting to installing Windows 11 Home, I guess our Lenovo ThinkCentres had a Win 11 home key in their BIOS? Mine was asking me for a computer name and then it was asking me to sign in with a personal MS account before I got the image set up correctly for Enterprise.

 

Am getting a test environment set up as we are currently running on 8+ year old servers, SAN etc; need money to replace projectors, desktops, chromebooks as well; the budget isn't adding up so will see how well this works and how feasible it is to move over totally

  • Like 1
  • Thanks 1
Posted

similar here, old hardware, no money, not enough time in the day :(

 @mikes sounds like you are using the old autopilot v1 there is a new autopilot V2 but @DWilson1997 is not using

autopilot at all, just using the "Microsoft Entra Joined Device Local Administrator" role to join them
to intune, e.g. intune thinks they are "personal devices". I had to allow enroll personal for group with user with this role.

 

Be interested to know if it's still working well for him / any downside to skipping autopilot. I guess if it's in autopilot and lost / stolen

it's tied to your org, bit like ipads in apple school manager.

 

The naming thing is not a biggie obvs. just curious, maybe if you use a home / pro sku it prompts for computer name

and then steps up to Education / Enterprise when you join it ?

 

This is more of a proof of concept thing for me to see how we could move away from very old on-prem server.

Unfortunately I rarely have any spare time to really get stuck into it.

 

Posted

@mrstrong No downsides for skipping autopilot from my side. We block personal device enrolment via enrolment restrictions and they are identified as corporate devices in Intune with our process. All still working well - we have been following this process for 3-4 years.

 

We have found device name in the OOBE can be different depending on what make/model the device is. For example we get it on Surface Pro 8's  but we don't get it on Surface Pro 9's or specific models of Dell laptop but we just change it on the device after enrolment if it does not appear in OOBE.

  • Thanks 1
Posted (edited)

We were hybrid and we now have 70% of the fleet fully autopiloted. It takes time to set it up but there are some good policy templates out there to help you start with.   We are not going back to SCCM, the provisioning time went down and we have about 40% less students complaining over issues with their devices just because we were able to implement newer policies to lock the device down a bit more. 

 

Just the ability to run scripts almost instantly on any devices is the killer feature to be honest. 


***edit - we have about 1700 devices ***

Edited by Langella
Posted

We have about 600-700 devices. As a school that is 95% shared devices, is Intune a worthwhile prospect now? Last time I tried it was woeful (must have been two years ago now)

 

We are hybrid and have dabbled a little bit with getting devices registered in Intune, but all management is still on-prem.

Posted
15 hours ago, ITGuyNW said:

We have about 600-700 devices. As a school that is 95% shared devices, is Intune a worthwhile prospect now? Last time I tried it was woeful (must have been two years ago now)

 

We are hybrid and have dabbled a little bit with getting devices registered in Intune, but all management is still on-prem.


Yes, it is worth it.  Intune has changed a bit the last 2 years.  Start small, create the same rules you have in AD that you really wanted to keep and try on test devices, then slowly grows the number of laptop based on your organization.  You may need to still leave your AD on for other applications or SMB you still use but they work fine with Intune only devices. 

The good thing about shared devices in Intune and Windows 11 is that you have more options to make them safer and improve the turnaround time. 

  • 3 weeks later...
Posted
On 22/05/2026 at 12:28, mikes said:

I am looking into joining our computers to our Welsh govt provided Hwb system, which is Intune,  still getting used to it.

I think I had to set up the computer name via Intune when I imported the computers hash, it then picked the name up when autopilot took over.

I used a standard ISO from Microsoft, problem is it was always defaulting to installing Windows 11 Home, I guess our Lenovo ThinkCentres had a Win 11 home key in their BIOS? Mine was asking me for a computer name and then it was asking me to sign in with a personal MS account before I got the image set up correctly for Enterprise.

 

Am getting a test environment set up as we are currently running on 8+ year old servers, SAN etc; need money to replace projectors, desktops, chromebooks as well; the budget isn't adding up so will see how well this works and how feasible it is to move over totally

Hwb intune is painfully slow

Posted
6 hours ago, techwizard said:

Hwb intune is painfully slow

Do tell more. How do you find it overall? How much control do you have, and what can you get to and manage?

Posted

I find myself thinking about this from time to time and feel like I probably should adopt it—mainly to keep up with new technology and the benefits it brings. However, I then hear about so many negatives that it starts to seem not worth it, especially as I can manage the estate without Intune and in my instance do not see it as a positive but just something that will add issues and problems compared to my current manual processes.

 

There are definite advantages to not using it. Being hands-on with devices allows you to carry out tasks more directly and gives you greater flexibility. I imagine Intune becomes more of a necessity when estates grow larger and there aren’t enough technicians to manage everything manually, so pushing changes remotely makes sense.  That said, I can also see how frustrating it can be for end users when things don’t work as expected, changes take time to apply, or updates don’t push correctly. I consider myself lucky to be able to make changes in real time, test them immediately, and walk away from a PC knowing everything is working properly and confident i can apply that to my estate.

Posted

While not one of the 2030 requirements, moving to the cloud is one of the DfE Standards, with a time frame of "as soon as possible to realise the benefits".

 

For us, our motivation to move from AD to Intune was to reduce manual maintenance and the single point of failure if the server were to fail. An annual fee is easier for us to get budget approval for than buying expensive physical hardware every 7-8 years, as it's there every year, not seemingly random one-offs. Reduces networking equipment that we manage to APs and Switches, simplifying operations.

Posted
2 hours ago, JazzFlute said:

Being hands-on with devices allows you to carry out tasks more directly and gives you greater flexibility. I imagine Intune becomes more of a necessity when estates grow larger and there aren’t enough technicians to manage everything manually, so pushing changes remotely makes sense.

I'd say this isn't the way to think about it.  Unless you are in a sector that needs individual builds every time, consistency is the way to go, which, with all the will in the world, a Tech cannot guarantee to do every time. Being consistent is a massive tick in the security box, as well as being able to say, with confidence, that you can apply settings to all your PCs. It is also a management issue, how do you know that every device has that setting applied, has one been missed?

Now none of this negates Intune being a bit slow sometimes, but I would try and move away from hands on all the time if you can, even if it is moving to GPO or an MDM product like Action1. You will be surprised how much time it frees up for you and your team.

Posted
35 minutes ago, TechMonkey said:

I'd say this isn't the way to think about it.  Unless you are in a sector that needs individual builds every time, consistency is the way to go, which, with all the will in the world, a Tech cannot guarantee to do every time. Being consistent is a massive tick in the security box, as well as being able to say, with confidence, that you can apply settings to all your PCs. It is also a management issue, how do you know that every device has that setting applied, has one been missed?

Now none of this negates Intune being a bit slow sometimes, but I would try and move away from hands on all the time if you can, even if it is moving to GPO or an MDM product like Action1. You will be surprised how much time it frees up for you and your team.

I use BCX Network Management Tools alongside other MDM solutions for non-Windows devices. Touch wood, there’s been little to no downtime—settings apply instantly and packages are pushed out in real time.

 

Day-to-day management is simple, quick, and easy, with full off-site access and control. Everything runs on A1 licenses, so there’s no need for A3, resulting in significant cost savings as well.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...