Hoyt Posted February 18 Posted February 18 Howdy all, I work in a small rural school district that has been AD only until just recently. We don't have anyone on staff familiar with Intune so se have contracted with an outside source to guide us. I myself am not involved with Intune at the moment because we are just now starting to use it. One thing one of the techs working with it told me was that Intune could not map a network share to a specific user login like AD does. He said it can only be mapped to a machine name, and anyone who logs into that machine will see that mapped drive regardless of their security level in AD. To me this just doesn't sound right. Seems like it would be a huge security hole, but I admit lately Microsoft doesn't seem to concerned with security. What do you Intune gurus say? Thanks for your time.
DavR Posted February 18 Posted February 18 Gotta admit that I haven't played with mapped drives in InTune per se, but, this does sound like expected behaviour. The problem with InTune is that the policies don't change nicely when the user changes like they do with Group Policy or AD with login scripts, so a user can switch on the device, and the policies won't change for an hour. Thus it would be difficult to ensure that the correct user is getting the correct drive mappings. Sounds like you're trying to achieve a user home drive mapped drive, is that the case? Is there a reason you're still mapping that to an onsite server, rather than migrating to cloud? With InTune, the expectation for home drives is you'd map these in OneDrive, that mapping does change nicely when users change. It's a folder, not a mapped drive though. If it had to be an InTune mapped drive, you could try mapping to the root of your home folders directory, and letting users browse to their own folder from there. Not ideal but it's a workaround. We're using IAM Cloud Drive Mapper to achieve this, which works well under InTune, but that's because all of our data is in SharePoint.
Hoyt Posted February 18 Author Posted February 18 Quote Is there a reason you're still mapping that to an onsite server, rather than migrating to cloud? We are just starting out with Intune, so these new machines need to be able to exist in our current structure. Just my opinion, but there are tons of reasons folks would not want to store their data on someone else's computer (cloud), but I know Microsoft wants to force it so they can browse through their data. Just nosing around I wonder if something like this would work: https://call4cloud.nl/intune-drive-mappings-admx-drive-letters/
DavR Posted February 18 Posted February 18 So am I right in thinking you've got an existing AD infrastructure, and you're now adding new machines as full Entra joined InTune managed devices, with a view to going over to full Entra/InTune with the rest in future? I get the reluctance to move your data to cloud, but, you'll not really get the benefit of going cloud if you still need to maintain those on site file servers. Your call of course. 7 minutes ago, Hoyt said: Just nosing around I wonder if something like this would work: https://call4cloud.nl/intune-drive-mappings-admx-drive-letters/ Yeah, I had a quick nose around too, that looks to be close to the definitive guide if you're wanting to do drive mappings via InTune. I'm not sure how it would behave with changing users, though, so you'd have to test that. In a 1-2-1 scenario it would probably be fine, but like I say, with InTune there's always that time lag when switching users and waiting for policy settings to catch up.
Hoyt Posted February 18 Author Posted February 18 Quote So am I right in thinking you've got an existing AD infrastructure, and you're now adding new machines as full Entra joined InTune managed devices Correct. From what we have seen so far we are less than impressed with Intune. We just don't need all that fancy stuff they are pushing. Some school systems in our area have abandoned Windows completely. I guess they figured if they had to migrate their data to the cloud, they'd pick what they thought was the lesser of two evils. Most schools are already using chromebooks so it sounded like a simpler transition.
DavR Posted February 18 Posted February 18 Yeah, Intune is OK, but it's nowhere near as comprehensive or responsive as Group Policy. You have to switch to a much more relaxed attitude to systems management. I'd have a serious think about what you want the future of your network to look like, before you go much beyond trialling a lot of these technologies. If you're going to keep onsite servers, and you're not fussed about putting data in the cloud, or taking devices outside of the school boundary, I'd question whether Intune is really what you want. Might as well stick with on prem AD and GP a bit longer. Full Entra and Intune are definitely the direction of travel, but they're really based on a post-AD model where you've little or no on prem hardware, data in the cloud, and you'd benefit from allowing devices to travel off site. We have a hybrid model at our place, where our on site stuff is still using AD and GP, but our data is in the cloud, and we have Intune based laptops that staff can take offsite. Best of both worlds IMO.
Sylv3r Posted February 18 Posted February 18 I think fully embracing the cloud with InTune does tend to work well including cloud printing, trying to run it alongside an AD domain whilst mapping drives, expecting it to mirror the exact setup of GPO's is unfortunatly going to end up failing quite spectacuarly - as has been posted above, it does have it's massive flaws and limitations but once you get over the speedhump - it does work well as a setup and forget type scenario. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now