Jump to content

intense_username

Members
  • Posts

    9
  • Joined

  • Last visited

Reputation

10 Good

About intense_username

  1. Hi all. We're a district of just over 3000 student devices. About a third are iPads and have been in Intune for a few years. This year we're looking to begin moving our Windows devices to Intune. I essentially have a completed setup and we're ready to start a pilot and, barring all goes well, lean into an actual deployment this summer. This project is only focusing on student devices (no staff devices yet). I'm really hung up on User Driven or Self Deploy mode and I'm honestly not sure why. I just see benefits to both and it's a bit of push-pull in both directions. For what it's worth we also have A3 licensing. User Driven (with preprovisioning - I wouldn't consider this for students if not for preprovisioning). This process is slightly more involved for us during setup. Not much, but, it's not as "just boot and let it rip" like Self Deploy mode is. It populates the primary user in the device listing within Intune which is neat, would be helpful for sure, but I'm not sure it's mandatory for our use case. When students first fire up the device there would be a slightly longer time they have to wait than Self Deploy as the device seems to need to check in again for any last minute app installs before realizing nothing is needed and then moving on to finish up the login process. Not a big deal, but an observation nonetheless. Self Deploy mode just feels more like SCCM imaging. You tell the thing to run, it does, and it drops you off at the login screen with your branded background, etc. It feels like it leaves less guesswork out of the mix since you can SEE it's done, whereas with User Driven when you hit reseal and it shuts down, you're just kind of hoping it's good to go (though I haven't had it backfire in testing to really warrant any legit concern yet, so, there's that). Even though we're 1 to 1, students do rotate devices now and then due to damages, repairs, loaners, etc. Sure, we don't get the username in the Intune device listing, but again I'm not sure it's a big deal for us. I spoke to an IT Director in a district twice our size in another state. He was a big User Driven fanboy, but later transitioned to Self Deploy and seems to like it more so he's sticking to it. I question how good devices will behave if we preprovision them with User Driven, reseal them/shut them down, and let them sit for the summer. It's hard to pinpoint it other than a "mild preference driven by a gut feeling" that Self Deploy may be a better fit for student devices. It's also worth mentioning that I plan to make core apps required on all devices, however, I plan to make a good number of apps available within Company Portal that students can self-service-install on their own accord. I've read a few instances that suggest Company Portal behaves better with User Driven, but based on more recent reading + my own experience, Self Deploy seems to work just fine. In fact, one user cited that Company Portal allows any user that logs in to use it, whereas User Driven is limited to the primary user alone (which would require wiping the device each time it changes hands - not a big deal, but food for thought). Has anybody had this ridiculous internal mental battle, or just me? What are you using? What's your vote?
  2. You definitely raise some valid points there. I have been ferociously on the fence about Self Deploy vs User Driven to the point it's almost driven me bonkers. One day I'm in one camp, the next day I've 180'd and I'm swearing by the other option. I think as it stands (for now?) I'm leaning more towards User Driven. See, I want to put some agency (and responsibility) on end users/students to download the apps they feel they need (or simply want to poke at for sake of learning/curiosity). We use Intune to manage apps for our iPads which we use for our younger grades and honestly... it was a sustainability nightmare at first. This isn't a fault of Intune at all, but rather the nature of the beast. One group wants one app, the next wants another, and we go in circles trying to figure out how to apply them. So what we did there is we created grade-level groups, so all 1st grade iPads get the same apps regardless, same with 2nd grade, etc etc. This seems to work well and tends to boost "app awareness" when apps magically show up on iPads because school A requested it but school D had no idea, but now, school D sees it on their screen and get curious and that leads to more use. That functionality has worked well. But I really didn't want to get into it with laptops. We start laptops at 4th grade. Some folks may disagree with me on this and that's fine, but we live in an app store driven world anymore, so I felt we should acknowledge that and lean into it a bit. So starting with our Windows Intune laptops (e.g. 4th grade moving forward), I want students to be able to go into Company Portal to download any additional apps necessary. All *core* apps are blasted to every single laptop regardless of grade. That includes things like our testing software, Office 365, and other critical apps. This way the discoverability is still kind of there thanks to Company Portal, but we're not carpet bombing all of our laptops with apps that the students may never need or use. The reason I share that mindset is because I was hardcore in the boat of Self Deploy. There's something so satisfying about getting to our branded login screen and shutting the laptop down and having confidence "it's ready to go!" But the thing is I ran into a few select cases where a Self Deploy laptop wasn't seeing all available apps in Company Portal. It would see some, but not all. The apps had no restrictions, scope settings, anything like that. It didn't matter if it was applied to All Devices or All Users (or both). I couldn't make sense of it, but buried somewhere in Microsoft's documentation was this little FYI box that explicitly said something about Company Portal apps and Self Deploy might have issues. That read to me as though I can either give up on Self Deploy and double-down on my "students should be able to download what apps they want in Company Portal" by embracing User Driven mode, or... give up on the Company Portal/students download idea and set apps as required installs. As a result, this is where I landed, with leaning more towards User Driven. Yeah - we do have a 1:1 setup, so perhaps it would be more fitting for us. I think as some of our labs of desktop systems make their way to Intune we'll simply stage them as Self Deploy and put those systems in their own group, and then mark apps needed for that lab as required, thereby skipping over the need for Company Portal/available app installs anyway (I mean, we're talking about CADD labs and video editing labs - they're kind of single-purpose anyway so hitting them with only required app installs doesn't strike me as terrible). Who knows, maybe I'll rethink this years down the road and think "what on earth was I thinking..." but for now I think this might be the plan. The User Driven mode originally struck me as a nightmare until I realized pre-provisioning pulls some serious weight here. It's still weird to me to hit "reseal" and power off the device without seeing our branded login screen, but maybe I'll get more used to that over time. You mentioned TPM issues - I originally ran into a lot of TPM issues as well, but that only ever seemed to happen with Self Deploy mode for the most part. Somewhere in a YouTube tutorial guide it was mentioned that a lot of recent updates took place to make TPM less terrible to deal with. I have no idea what video that was but I recall it being dated fall 2023, so it was pretty recent. Stands to reason that this should be less of a headache into the future. In response to you addressing the "if the licensing isn't in good standing activation issues" comment, I inadvertently left a key factor out of that on accident. You see, originally I was USB wiping my test systems with Windows 10 Education and that's where I would get the license error. I was doing that thinking Education is the final goal, so why not USB install (takes just under 5 mins, so it's quick) and since Edu is the end goal I'll use Edu on the USB install. But therein lies the issue - OEM license for the device was Pro/Pro Edu, not Edu proper, so it would error out and I would never get the A3 subscription license. If I USB'd with Pro (or Pro Edu rather), then after an A3 user logs in it would step up to Edu. Shot myself in the foot during testing without even realizing it. (pardon the length of this post - part of me feels the need to share these details somewhere in case someone in the future stumbles on this)
  3. You know what's kind of funny about all of this? In my tenant, if I go to our license products, it literally says verbatim "Windows 10/11 Enterprise A3 for students". So right there in the name it even name-drops Enterprise. Not that it means anything, I just find it saying Enterprise with us being an Educational institution and a lot of my test devices activating as Education (likely from the Win 10 Pro Edu batch from the one order) as a bit of a "huh, imagine that" kind of thing. But yeah, I can definitely see that Pro Edu needs to be our focus going forward for any new orders as far as OEM licensing goes.
  4. Are you using the Windows Edition and Mode Switcher policy? I have that set up, but right now it's not applying to any systems. I began to question if that policy even has a point to it... (??). See I was having issues getting Windows Activation with A3 subscription working until I started using a script to apply the embedded key as the Windows key. The A3 subscription doesn't seemingly kick in unless your "local" licensing of the machine is in good standing, and since mine was erroring out the A3 subscription never kicked in. So with that script, that problem seemingly went away, and my systems would step up to A3 subscription (excluding the few that went to Enterprise instead which lead to me making this post of course). Reason I share all of this is before using the script to apply the embedded key I was using the Windows Edition and Mode Switcher policy, but it didn't seem to really... do anything? It seemed far more consistent to use the script to apply the OEM key then let the user logged in as a licensed A3 user to step up the license from there. /shrug PS - you're a big Intune shop? Students I assume? Side question - User Driven or Self Deploy for students? I've been on the fence but leaning more towards User Driven with techs running pre-provision then resealing the device. I originally wanted to do Self Deploy but I'm having some issues with the Company Portal (I want to make apps available for students to self-service-install but that acts a little weird on Self Deploy, unfortunately...)
  5. Thanks for the info! I wonder if this varied a little bit depending on which Dell rep we had at the time. See the reality is the Windows that came with our student laptops back then didn't really matter, seeing as though we had Edu licensing with MAK keys. I know Pro was the focus but I believe that one Dell rep vs the others may have built the quotes differently. For example, one quote contains this line "Win10 Pro 64bit Nat'l Aca NTRY" and another quote from a year earlier has this line "Windows 10 Pro Natl Aca Strategic EDU CARE K12 and HIGHER EDU only." So maybe that bounced between Pro and Pro Edu with those different Dell reps, and the reality is, we would have never noticed because first time we booted them up it was off to a PXE boot with SCCM they went and the OEM image was pulverized by our SCCM image. Do you think these will upgrade and step up to Windows 11 Education/Enterprise without issue? I'm hopeful (and would think) they would... we're on the brink of putting 11 on these systems to test further and see how things go. I also question if this is reason for concern. I mean, we all know Enterprise and Education is quite similar to one another, so feature wise I think it'd be fine. I'm more concerned about "licensing compliance" or anything like that regarding our A3 license access. I would hope that one student being on A3 Enterprise and the next being on A3 Education wouldn't set off any alarms on the Microsoft side to cause a hurdle. Appreciate your response! Especially given I'm on the brink of building our summer quote out... Windows 11 Pro Education will be one of those "ensure you don't forget this" things moving forward.
  6. Hi all. Truly not sure where I should post this cause I feel like there are multiple potential cooks in the kitchen. I'm testing Intune, we have A3 license subscription, and Windows 10/11 Enterprise is tagged with the student group so they should have the ability for Windows to automatically "step up". With our test machines, we're starting wtih Win 10 Pro (device has an OEM license for this), and upon logging in to a test student account which has the A3 Win 10/11 license, it should activate. On two machines in particular, it comes up as Windows 10 Enterprise. All others I've tested (so far) come up as Windows 10 Education. The ones that say Windows 10 Education specifically say "Windows 10 Education A3 subscription is active", whereas the two problematic machines simply say "Windows 10 Enterprise subscription is active". These laptops have the exact same configuration. Both managed by Intune using Self Deploying profiles. I really can't find a reason as to why these two machines are getting picked up as Enterprise. Has anyone seen this before? While one could argue that there's minimal difference between Enterprise and Education, I worry about how this will act at scale. Are these 2 Enterprise machines a sign of more to come once we get into the mode of mass setups? Likewise, I stumbled on a Reddit post with someone who had this same exact issue and they mentioned after quite some time the handful of systems they had coming up as Enterprise began to drop their Windows activation... kind of my worst nightmare... Would appreciate any and all insight! EDIT - Just a random thought hit me. I'm using some old laptops to test. I wonder if I just got luck of the draw and these two problematic laptops actually had motherboard swaps in the past, and perhaps the OEM key on it happens to be Enterprise from who-knows-what box Dell pulled it from... I can dig up the OEM key via wmic. Any suggestions on how to identify what edition this key is attached to? slmgr /dli returns Windows Professional edition, RETAIL channel, and ends in 3V66T. Huh...
  7. Hi all. We're a Windows shop, 1:1 program, and looking to move to Intune for management on all devices going forward. I have a pretty good Intune setup going which is arguably mostly done. At the moment I'm pretty much just wiping the same set of test systems over and over getting a solid/more consistent feel for everything with a small pilot tentatively planned coming up. If things go well I may be interested in making more of a push towards Intune come summer time. For what it's worth, I'm looking at using a User Driven deployment profile. I plan to preprovision devices, seal them, power them down, and let them sit until they get handed over to the student for school use. I read somewhere a suggestion to "preprovision devices as close to roll-out as possible to avoid any headaches with certificates expiring." Which... horrified me... because the majority of our laptops sit powered off over summer. Secondly, what new laptops we buy we start work on *immediately* when summer starts so those batches could be sitting on the shelf for essentially the full span of summer as well. Does anybody have any documentation, personal experience, anything like that to suggest that systems sitting powered off for 3-ish months aren't a concern in an Intune world? I'd love to find out some concrete info on these certificates, their life span, and perhaps any other potential gotchas before I get too deep in this. Appreciate any insight!
  8. Interesting... thank you for this info! I think I'm going to build this out and test it, but the more I think about this the more I feel I may position this as a backup plan. In other words, push Edge as the default/only browser for students, but say that knowing I have confidence in a backup plan should Chrome be absolutely required for some reason I have yet to discover. I can always roll that out after the fact... but it just puts my mind at ease that there's a method to lean into should it come to that. Appreciate the info! I'm going to whip this up and see how it all works out. Appreciate it!
  9. Hi all. We're a Windows based district -- currently on-prem joined systems using Securly with SmartPAC/certificate GPOs. It's worked well for us. As time progresses, we're focusing on Intune for Windows management in the future. In general, testing has gone well, but I keep revisiting one last item: managing and enforcing a Securly+Chrome combo via Intune management. Based on my conversations with Securly, there's no approachable way to go about the SmartPAC method with Intune. I can push the extension to the managed Chrome install via Intune, but it doesn't seem to filter anything. I found the behaviors kind of odd. For example, the Chrome policy enforces student login with a Google account (to the browser itself) to continue -- I punch in my test student account and I'm in the default Chrome window. I check extensions within Chrome and I can see Securly listed there, but nothing is filtered as I check random blocked sites. If I go to Google Drive and finish the sign-in there, suddenly all of my search results return a non-secure website (sort of like if you push the SmartPAC to on-prem systems but don't have the cert installed). I have a separate policy in Intune which contains the Securly certificate and puts it in the local computer store -- now websites work without the non-secure warning, but yet, no filtering seems to be active. Okay... so it's as if I have some of the puzzle pieces, but not all of them. While I continue to try and troubleshoot this, part of me keeps looking back at Edge and wondering if we should put our focus on Edge as the official (and only) browser for student devices. I mean, it auto logs in, auto installs the Securly extension in Edge, and everything seems to work seamlessly. Edge and Chrome sharing the same technical base via Chromium admittedly helps with compatibility concerns as well. Being a Microsoft shop, maybe there's an argument to be had there... If anybody has any suggestions for the Chrome piece I would greatly appreciate it (or, if perhaps you could offer your 2c about the Edge-sanity-check I certainly wouldn't turn it down). Thank you all!
×
×
  • Create New...