-
Posts
2,187 -
Joined
-
Last visited
-
Anyone seen this issue before, Outlook\OneDrive not connecting\signing in with error AAD Cloud AP plugin call GenericCallPkg returned error: 0xC0048512 in event viewer: We have this on a handful of users
-
meh - intune, I pulled the intune project at my new place as shared devices was a nightmare!
-
Desktop and Patch Management
-
Looking for Alternatives to Intune\SCCM - any decent recommendations?
-
Hi all, We’ve been chasing down a really odd issue and finally pinned it down to the Impero Client. On our Windows 11 (24H2, latest cumulative update) machines, when a anyone logs in and uses Word (M365 Apps), dropdown menus (e.g. font selector) disappear as soon as you try to scroll, This makes Word basically unusable for those users. After a lot of testing we confirmed: If we disable the Impero services (Impero Service Starter, ImperoClientSVC, ImperoGuardianSvc) → issue immediately disappears. If we start the impero services, boom the issue comes back! So this is 100% tied to Impero injecting itself into the session. Has anyone else seen this on Windows 11 24H2? If so, did you manage to get a fix or hotfix from Impero? We’re planning to escalate to their support, but I’d be keen to know if this is widespread. See video! Video(1).mov
-
One of the main issues I encountered during testing was that policies were so inconsistent, they would either take a long time to apply, not apply at all, or only kick in several minutes after the user had logged on. Like you, I want to lock down user accounts, but I can’t risk relying on policies that don’t apply properly. We were fully prepared to move over to Intune, but on the final day of term I pulled the plug after realizing how disruptive it could be come September so went back down the SCCM\MDT route. I’m now reviewing our options again. At this stage, I’m leaning towards SCCM with Intune integration, or possibly another device management tool altogether. I’m not comfortable moving to a full Intune setup just yet.
-
To Intune or not to Intune… At the start of this year, we were seriously considering moving away from on-prem AD and going all-in with Intune. After extensive testing, though, the cracks showed very quickly. Here’s what we ran into: Policy application is inconsistent – Some machines apply policies instantly, others take hours (or never). We saw settings half-applied, conflicting, or simply ignored. For a controlled school environment, that’s a nightmare. Reliability with shared devices – Education doesn’t fit neatly into Intune’s “one user, one device” model. We have shared PCs, laptops, and labs. Intune just doesn’t handle multiple user profiles well, and policy inconsistencies multiply. Drive mapping and legacy dependencies – We still rely on mapped drives, and Intune + cloud identity doesn’t play nicely. Scripts for drive mapping are hit-and-miss, and support for legacy infrastructure feels like an afterthought. App deployment is flaky – Some apps push fine, others stall, fail, or report success when they haven’t actually installed. Troubleshooting is opaque compared to SCCM or GPOs. Limited control and visibility – Reporting is basic. Troubleshooting why something didn’t apply often comes down to guesswork. Event logs and error messages are vague at best. Connectivity dependency – Devices that aren’t online regularly don’t update properly, leaving gaps in compliance. On-prem GPOs don’t have that issue. User frustration – Students and staff logging into a freshly built device often hit delays while policies and apps “drip-feed” in. With shared classroom devices, you don’t get the luxury of a single user waiting 30 minutes for their desktop to be usable. To give credit where it’s due, Intune does have strengths. Windows Updates, driver/firmware updates, and general patching were handled really nicely. I also liked the centralized view of compliance. But overall, the way Intune applies (or doesn’t apply) policies gave me the ick. It’s unreliable, unpredictable, and ultimately not suited to the education space as it stands. Looking ahead to next summer, I can’t justify moving us fully to Intune. I’m instead looking at SCCM with Intune hybrid mode to get the best of both worlds. Has anyone else gone down the hybrid route? Would be interested to hear how it compares in real world education use.
-
Slow User Policies Applying via Intune – Anyone Else Experiencing This?
IanT replied to IanT's topic in Cloud Services
I made the decision on Friday to halt the Intune project. While it's suitable for 1:1 device deployments, it's proven to be a nightmare for shared devices. I'm not willing to implement a compromised solution or rely on hope for stability, it needs to be done properly or not at all. -
Slow User Policies Applying via Intune – Anyone Else Experiencing This?
IanT replied to IanT's topic in Cloud Services
yeah, it’s honestly becoming a bit of a joke now. We’ve literally just applied some settings to our student policy — they applied fine on first login. Thought "brilliant, finally!" Logged out, logged back in… nope. Gone. Not applied. What the hell is going on? It's genuinely ridiculous. One minute it behaves, the next it forgets it even exists. I get that Microsoft thinks every device is a shiny 1:1 business laptop sitting idle waiting patiently for cloud magic to happen, but come on, this is a school. Kids aren’t waiting 10 minutes for policies to catch up. They’re launching Roblox, opening CMD, and trying to bypass everything before the poor IME even gets out of bed. We're at the start of our rollout and already seeing how shaky this setup is for shared environments. It just doesn’t feel production-ready for education — at least not without a lot of duct tape and swearing. -
Slow User Policies Applying via Intune – Anyone Else Experiencing This?
IanT replied to IanT's topic in Cloud Services
I'm just seeing so much inconsistency - we have a configuration policy which restricts the like of control panel etc.............you log on, it doesnt apply so the kids can start changing stuff.............10 minutes later its applied, this cannot be right surely with how slow it is?! -
I’m currently in the early stages of deploying Windows 11 devices using Microsoft Intune (Entra joined), and I’ve started to notice some frustrating behavior around user policies applying very slowly or inconsistently. When a user logs into a freshly deployed device for the first time (especially shared/student machines), the device itself is enrolled, apps install fine, and configurations eventually apply. However, the user policies – things like restricting PowerShell/CMD access, locking down settings, hiding control panel etc – either: Take several minutes to apply Or don’t apply until after a log out and log back in And in some cases, they don’t seem to apply at all on first use This delay poses a concern, especially in an education setting, where a student could easily access critical system tools before the policy has kicked in. We’re deploying mapped drives using ADMX-backed configuration profiles. These too sometimes don’t appear until a second logon, despite the config being correct and devices/users in scope. Anyone has this?
-
Yeah, that’s exactly my thinking too, using MDT with a TS for the latest Windows 11 build. I’m getting seriously fed up with waiting around for apps to come down from the cloud. Even with forced syncs and ESP tweaks, you’re still at the mercy of Microsoft’s timing. I’d much rather preload the core apps in the image via MDT, that way I’ve got more control over the process and can actually get machines ready in a sensible timeframe. Autopilot’s great once it’s rolling, but for existing domain devices it just feels too sluggish without a bit of prep work up front.
-
I've been experimenting with Intune and onboarding devices, and we have a few hundred existing Windows 11-compliant machines that we're planning to AutoPilot over the summer. I'm curious, how do you typically handle imaging for existing devices? Do you wipe them with a vanilla Windows 11 OS and then run the AutoPilot scripts, or take a different approach?
-
Assistant Network Manager - Collingwood College - £34,420 - £38,002
IanT replied to IanT's topic in Educational IT Jobs
BUMP!!! - Re-advertised -
Does anyone still have Physical Domain Controllers on-site which still hold all FSMO roles?

