Warwick_Tech Posted February 26 Posted February 26 Ok, so poll and discussion time; Traditionally we've always been a Windows school; however, with the crunch of finances and the need for more and more mobile devices we are now looking at 1-to-1 or bulk buying laptops/tablets As we all know, MS Surfaces are ok for Intune, along with cheapish laptops, but Intune really isn't the 'safeguarding compliant' solution we would like it to be, so now we're looking at Chrome Books. Does anyone else run this sort of mixed environment? Do you prefer one over the other? What's the best way to deal with the massive influx of pupils needing laptops, and the mixed policies around personal devices? I've been referring to this spreadsheet recently and the lovely 'grey area' in-between. My major concern is Intune has no real native way to prevent users joining personal devices and then picking up licences, BitLocker etc. - We've already had one instance of a parent trying to claim money back from us for taking their personal laptop to a repair place and being charged £100 for a factory reset. I can only assume through chrome books have the same? If we open those doors of allowing joining chrome books; what happens when they inevitably leave school? It seems this needs some real involvement from the DfE as to an actual solid plan that keeps the school, parents, kids and the DSL happy! What're your thoughts?
ZeroHour Posted February 26 Posted February 26 36 minutes ago, Warwick_Tech said: My major concern is Intune has no real native way to prevent users joining personal devices and then picking up licences, BitLocker etc. - We've already had one instance of a parent trying to claim money back from us for taking their personal laptop to a repair place and being charged £100 for a factory reset. Can you use a mix of device enrolment restrictions and Conditional Access to prevent them being fully Intune enrolled potentially?
Warwick_Tech Posted February 26 Author Posted February 26 1 minute ago, ZeroHour said: Can you use a mix of device enrolment restrictions and Conditional Access to prevent them being fully Intune enrolled potentially? Yes - So I found that method where you can create a 'trusted IP zone' and then only allow the Intune service to run from there (conditional access) but this does mean if someone uses the school WIFI even if it's a personal device it gets added so it's not 100% foolproof -- My thought was to seperate out the external IP's for guest and LAN traffic, which we do; but then we can't add Intune devices to the main system as easily because they are OOBE when given to the staff. I fear this will all come down to cost and chromebooks really are dirt cheap for what we need...
DWilson1997 Posted February 26 Posted February 26 Sorry, can't comment on the Google vs Microsoft - but you can prevent users joining personal devices to the tenant via a simple enrolment restriction. 1
TheHyperTechie Posted February 26 Posted February 26 Google/Chromebooks are the winner for me. Especially for students, cheaper, quick to setup, easy to manage, long update expiry, can repair in house (depending on model), policies also apply much quicker in my own opinion (and a lot of others the way it is discussed here vs intune). We are 1:1 for KS2 here, and wouldn't ever swap to a different device (iPads, Windows devices) etc. 1
ZeroHour Posted February 26 Posted February 26 46 minutes ago, Warwick_Tech said: Yes - So I found that method where you can create a 'trusted IP zone' and then only allow the Intune service to run from there (conditional access) but this does mean if someone uses the school WIFI even if it's a personal device it gets added so it's not 100% foolproof -- My thought was to seperate out the external IP's for guest and LAN traffic, which we do; but then we can't add Intune devices to the main system as easily because they are OOBE when given to the staff. Limit MDM scope with a group? using:
Warwick_Tech Posted February 26 Author Posted February 26 1 minute ago, ZeroHour said: Limit MDM scope with a group? using: I think this still causes the pitfall as it works via 'user' rather than 'device' - an exteme scenario is to upload all our device #'s and only allow them, but it's not really a great solution...
ZeroHour Posted February 26 Posted February 26 So the toggle that is brand new might help: https://blog.admindroid.com/disable-allow-my-organization-to-manage-my-device-prompt/ 1
DavR Posted February 26 Posted February 26 8 hours ago, Warwick_Tech said: My major concern is Intune has no real native way to prevent users joining personal devices and then picking up licences, BitLocker etc. - We've already had one instance of a parent trying to claim money back from us for taking their personal laptop to a repair place and being charged £100 for a factory reset. For us, we've prevented devices recognised as Personal from being allowed to be added to InTune by turning off the Personal device category under Enrollment Restrictions - https://learn.microsoft.com/en-us/intune/intune-service/enrollment/enrollment-restrictions-set. This means only devices recognised as Corporate get added to our InTune. The side effect is, though, that "Enrol in MDM only" if run directly from the Windows device doesn't work from random devices if they're recognised as a Personal device. Is there any reason why you wouldn't just lock InTune down as the above? Or do you need users to self-register BYOD devices into InTune for the basics like WiFi configs etc? If it is the case you are going to allow BYOD devices into your InTune, then security groups and/or tags would be the way to differentiate the policies and software they recieve, although this may involve an amount of manual work grouping/tagging new devices as they appear.
TwistedHelixis Posted February 26 Posted February 26 (edited) Chromebooks for pupils at all the schools I manage, I would never want to go back. On a side quest, I now have 2 server-less schools. Both have staff still using Windows devices, but they authenticate against Google accounts, not intune or Microsft. It so nice not to have to worry about server updates, domain migrations, or purchasing new servers etc Edited February 26 by TwistedHelixis 1
TheHyperTechie Posted February 27 Posted February 27 12 hours ago, TwistedHelixis said: Chromebooks for pupils at all the schools I manage, I would never want to go back. On a side quest, I now have 2 server-less schools. Both have staff still using Windows devices, but they authenticate against Google accounts, not intune or Microsft. It so nice not to have to worry about server updates, domain migrations, or purchasing new servers etc Couldn't agree more 💯 1
Alis_Klar Posted February 27 Posted February 27 M365 is such a complex product compared to Google Workspace. I think the biggest issue with M365 is the massive learning curve with "going serverless" over Google Workspace. Google workspace doesn't have as much functionality as M365 but has 80% of what you need. The simplicity is actually a benefit in Education though and the speed of deployment just beats MS hands down. Plus I really hate the slow logins on shared windows devices. Updates are a breeze on ChromeOS too. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now