Jump to content

Planehazza

Members
  • Posts

    325
  • Joined

  • Last visited

Everything posted by Planehazza

  1. Ooh interesting. would you be able to share any more on this please? We too are Google primarily, but have an M365 footprint for PowerBI and Intune. Right now, we have no SSO, but passwords sync from AD to Google to make lives a little easier, but full on SSO between Google and AD/Entra would be great. I was originally looking to have Google as the IdP but this might make more sense?
  2. Hi all, We're moving to Intune after I've pushed for it for years. We currently 'manage' (Ha!) roaming laptops by domain joining them and relying on users signing in on site then using cached profiles externally. Yep, I know, let's skip past this... We have a few hundred devices in SCCM, v2309 (will be updating to latest in coming weeks) so I'm thinking co management is probably the best solution. We have Entra ID Sync (on prem agent) in place, and we're a Google site so I'll need some M365 tweaks and Intune configs to prevent access to M365 resources. We literally need to use M365/Entra for sign in and device enrolment, and may look to juts federate against Google in time also (I'd ditch Google in a second if I had the option/power). So, I'm thinking remove laptops from domain join and have Intune handle restritions and app deployment, but I'm a little fuzzy on the best way to tackle this. Should I look to build to handle existing devices in SCCM, or just purge and redeploy them all? We'll not be looking to use autopilot any time soon, so will be relying on (likely a cut down, tweaked) task sequence to image devices and enrol to Intune. Would love any advice and tips please, and apologies for the vagueness... going into this not blind, but perhaps naive. I'm teaching myself as I go. Thanks!
  3. I'm no expert, but I've managed iPads with ASM and several MDMs over the years, and am too am migrating 600 devices to Intune this Summer as we move away from Lightspeed. Any questions, I'll keep an eye out here
  4. Sorry to say that Inventry is no better now, and is even worse now that the support system has been 'revamped'. As soon as we've ran out contracts out (and assuming finance allow it.. hahahaha) I want Sign In App in at all of our sites.
  5. I'm not sure what the scope is; we've just been told they want clocks in the classroom for kids to see. The school has gone down a locked phone pouch route now so their thinking is the kids needs to see the time from some other method. Why the kids "need to see the time", I've no idea... I've presented the RCC option to them with a suggestion we buy only a few to test with for now. Clock aesthetics, size, and price is up to them now.
  6. Thanks, yeah RCC is the way to go I think. Cue "kids can't tell analogue time" comments from teachers.
  7. I know, but it came to us and anyone else would just say go get 70 clocks from Argos and then it would come to IT for a better solution when class A is out causing chaos on the corride 3 mins before class B anyway 😅 Thanks for that. I hadn't heard of that supplier, but one of the products listed is the same as one I've already suggested from a more expensive supplier, so thanks for that heads up
  8. One of our schools wants new analogue clocks for the 70+ classrooms. WIthout going into details of behaviour etc, consistency and having the clocks being correct is importtant so before they've gone and bough 100 or so standard clocks I recommended RCC ones, albeit being more expensive. Can't do anything crazy invasive or overkill like PoE, so thinking RCC battery analogue clock faces is the way to go unless there's a more modern solution? I believe the RCC mast etc is still like and isn't looking to be phased out like RDS etc?
  9. That's how I had it suggested too. Device name tied to an account in Lightspeed and the teacher was supposed to keep track, but it doesn't happen so we can only know which device has triggered an alert and it's usually too late. I think shared iPad is possibly the only way to truly track internet usage per student, but the sluggish, finnicky experience I've seen thus far is not gonig to land well with the classrooms at all... Once the intial login and passcode creation is done, it's not that bad really. It's that getting them signed in and a passcode created that's going to be an issue...
  10. The login process and enforced passcode is going to be a total ballache for primary students. I can't believe Apple haven't thought about this for kids that are 6 years old etc.
  11. I'm back at this topic. We're moving away from Lightspeed and so have had to find a new MDM solution. We've elected to use Intune as we want to implement that for laptops anyway. With this opportunity, I'm testing shared ipads which still seems rather sucky and glitchy. Got it set up nicely yesterday, come to show my line manager proof of concept and it's all gone t**s up 😂 I seem to read a lot about using ASM to set passcode policies and device lock grace periods etc. but I cannot see any settings anywhere. I've got it federated against Google for now, but unsure whether this will be Entra or another third party (QR based etc) system in the future. How are those using shared ipad finding it in schools, particularly primaries where there may not be enough devices for true 1:1? True 1:1 simply is impossible here; I've already had to get my boss to tell Finance and above that 150 of our 600 iPad fleet need to be removed from use being stuck at iOS12.5.7...
  12. Thank you, much appreciated. So far, I've got it set that AD is syncing to Entra via onprem. I went down the path of cloud connect but it felt like onprem was better suited. I've got a meeting with a third party for support on this on Friday, so will discuss options in depth then also. I planned to set up Entra > Google SSO to speed up user experience with Google Drive and Chrome. I understand there (by design) is no way to automatically zero click sign in these apps based on Windows OS login, but I'm wondering if SSO would still speed up the login steps by just having them click their email and allowing SSO to sign in. Still want to trial this, as it's one of the biggest complaints I get still after 4 years of being Google. I've ran ASM > Google as the initial test, thinking it would allow me to select a test OU. Nope, it just went, great, that's on, here's ~4500 user accounts in ASM now. Aye, cheers, mate.. 🤦
  13. ANother question for the masses. As we're moving 450 (150 are too old to go into Intune, yep, thanks education system...) from Lightspeed to Intune, now is a perfect time to also sell Shared iPad. I'm obviously going to federate against Google or Entra here. Question, given above, would it make sense to federate against Entra, or Federate against Google? What will happen if/when we federate Entra and Google? Will Apple send them to Google who then sends them to Entra? Or will it just break?
  14. That's the closest to SSO/automated sign in we have currently is this 😅 Telling people to sign into Chrome first so that Drive is just a click or two.
  15. I gotta admit I can understand why, but it's super frustrating for users. Said frustration is then passed on to me through moaning. At least with password sync and GCDS things are a LOT more consistent than they were.
  16. Still thinking about this one. The main priority is getting Intune and moving away from just domain joining and BitLocking devices and hoping for the best... Ideally I'd love it that users sign into their W11 desktop and through Federated logins and SSO, Google Chrome and Drive just sign in automatically, but I'm thinking that perhaps this is more a risk really? It would make a HUGE difference to our users, many of whom complain about this process daily, but it brings in many a challenge and risk. Understandably, management is very reluctant to undo and change 2FA which is currently Google, but it wouldn't be a total career ending move to have it brought over to Entra instead, but it would be a huge effort and challenge, with a lot of push back. Is my vision sound, or am I being a bit naive? I would love to have AD and Entra handle the source of truth for accounts etc. so that we're (well, the users) not battling yet another account etc for managing devices. Is it possible to have Google apps in Windows just do seamless SSO based on device authenticated against Entra? I don't mind if GCDS is still required for the management of user/OU sync (in fact, even if Entra is provisioning accounts through Google Cloud/G Suite Connector, I still forsee the need for GCDS to maintain Google user OU homing (various policies etc are set per OU etc.). Sanity check needed, please!
  17. Ah gotcha, very similiar to mine currently then. I currently have GCDS as a single instance, but with an XML for each site ran sequentially via task scheduler. Very tempted to consolidate it to a single XML. However, now that I've spotted this https://learn.microsoft.com/en-gb/entra/identity/saas-apps/google-apps-tutorial I'm quite intriqued by this. I sort of picture it as a vertical provision/sync from AD to Entra, then a horizontal sync between Entra and Google using that Enterpirse App as above. Knowing my luck, the MS licensing heathens will intervene. More food for thought and homework, thanks
  18. Thanks, Matt. Apologies I'm a little confused. So you guys are using GCDS to sync AD to Google? Your previous message said Automate, which I took to mean Power Automate?
  19. I haven't directly, but I'm aware of another MAT I'm in contact with that have. So far I've leaned towards Entra Google federation as the preferred method, but that does introduce a 2FA complication that GCPW might alleviate. It's the overall situation with Intune and managing Windows devices that has mainly led me down this path of keeping AD/Entra as the source, with Google basically piggy-backing off of it. Introductions some security implications though, with having multiple accounts all potentially sharing same ID/passwords etc.
  20. Interesting so you're not going AD > 365 > Google, but instead AD > 365 and AD > Google? Have you looked at Google's own GCDS for AD > Google sync? We use Locker for user creation from Bromcom. Works well, but takes a bit of fiddly setup. Not sure we're at a point where we can ditch AD entirely yet. Would have to look at costs of Azure vs licenses and running costs of onPrem. I wanted AD>NET2 also, but above won't pay for the none lite version so we're stuck. Thanks. Already got ASM. Several hundred iPads manually added via AC2 (don't ask... 😅), which are then handed over to a third party MDM for management and app deployment. It works, mostly. Ah so you sync AD > M365 using Entra ID (cloud or connect please? I'm leaning towards onPrem connect agent) and then GCDS for AD > Google for user creation, using the federated SSO for auth? Just been reading up on the former, and it seems GCDS could be replaced with "Google Cloud / G Suite Connector"? Was this something you looked at?
  21. I agree, fully. The biggest problem is user uptake and their willingness to change/learn. The next biggest problem is people using Word, for example, to create documents and then others accessing the same document from Docs. On paper, and for most cases, this should just work, but it always causes issues. People using word prevents all collaborative features, causes incompatibilities and we find time after time people have copies of copies. I've been in this field for for 17 years and I've given up trying to educate teachers on the best way to use files and storage systems. I'm probably setting myself up for a huge future PITA, but this current hybrid setup was a mistake (before my time, and the decision would have been above my paygrade anyway). They were on 365 entirely but Google was sold as cheaper, does all that 365 does, and its better. IMO, none of those are quite true without going deeper. Certainly Windows/Office PCs syncing files up to Google is too much faff for the average user, and it causes much of the frustration felt by them and myself in IT. I would have gone down the 365 route personally, and it's why I'm trying to steer the project as illustrated above. Changing from Google to M365 now would be a huge Uturn so I can see why above doesn't want to entertain it, but unless we fully embrace Google we're setting ourselves up to fail, especially in the eyes of the users, and it's really demotivating. Rightly or wrongly, people are used to Office products.
  22. Hi all, Looking for some advice please, moving forward with a 365 and Google mixed environment... We're a Google Workspace site, but we've never had a functioning system to manage Windows laptops. We have Lightspeed MDM for iPads, and google for ChromeOS. Implementing Intune has been a wish of mine for as long as I've been here, but now that we're changing Internet filter and alerting from one product to another, it has facilitated a more urgently pressing need for another MDM. I've managed to 'sell' Intune because it will do iPads and all of our scary domain joined laptops that cause us nothing but grief. We already have a 365 tenant in place, but it currently service volume licensing and Power BI dashboards and that's it. So, going forward my rough plan is set up Entra ID Connect on an onPrem server to sync AD to Entra ID, and then use that as an IdP for Google. Currently we used Password Sync and GCDS and I've got it set quite nicely and smooth, but both AD and Google are a bit inconsistent. Anyone got a setup like this? What I forsee and want to try and sell to exec, is a seamless integration of the above. I'm thinking we ditch PS and GCDS, have Entra ID Connect syncing AD and Entra ID, which will then present user accounts to Google for drive and mail etc. SSO between the lot. Is this doable and best method? I can't see any obvious reason why we wouldn't do this and employ both Entra ID connect and GCDS? Google currently does 2FA, but again I feel (and believe me, I know this will be a ballache) moving 2FA away from Google to 365 would make more sense? Curious to know what approach you've take in similar situations and any avenues I should go down? THanks!
  23. Good to know, thank you. Thankfully, the school I currently have an order in for is a tiny primary.
  24. Been with Inventry for years, but personally I'm keen to ditch ASAP. We're looking to SignIn App for a proper cloud solution and a simple iPad. We all hate iPads in IT, but chuck an iPad on your MDM, lock it to the app and you're away. Inventry support has gone down the pan too. As others have mentioned, they're crazy expensive and slow to develop. They kind of remind me of SIMS to be honest. I've had a support call in to chase up the migration of ~10 sites from one MIS integration to another, and all are at different states of affairs. You log a support ticket to get an update and they treat it like a fresh ticket and start right from the start again. I've had one email ticket in for 5 weeks and it's just going round in circles.
  25. It's taken a fair bit of emails and calls but Apple are going to delete the existing ASM (thus releasing devices) and allow us to re enrol them to our ASM. Had to provide: - Photo ID - Photo of my work badge - Letter from HR proving my employment - Letter from the school authorising my request to delete the ASM account - Acreditation of the school/trust. I had to ask what they meant by this, but in end I've just put links to school and trust websites and the current DfE page for the school Hope this is helpful for anyone reading this thread.
×
×
  • Create New...