Jump to content

Westie1010

Members
  • Posts

    8
  • Joined

  • Last visited

Everything posted by Westie1010

  1. Thanks for all the information, greatly appreciated! Interesting how you went the script route, funny enough I was actually thinking the same, my concern though was CMD and Powershell popups to the end user. I was also unsure how it would handle registry changes as I assume the script runs from the logged in user and not SYSTEM right? If CMD and Powershell are disabled to the user surely these scripts couldn't run either? Again, I'm still early stages of Intune so really not sure. I think my plan for now is going the Hybrid route. I'll be looking into AD Sync to get devices atleast hybrid joined and then I need to have a play with how Intune policies and GPO interact. Hopefully I can piece something together without breaking everything! I'll take a look into the logging stuff. I've heard about the GUIDs and Identifiers but never bothered looking for myself. When you say policies are cached for alternative logons, surely that would be my student user policies should apply to each student right, assuming they have the same groups and what not? Wonder why I'm not seeing that in my environment...
  2. Super thanks for the mass amount of information regarding Intune. It’s our first deployment of many so still trying to iron out the creases. This is the first bit of assist I’ve managed to get! We’re familiar with Azure AD as far as AD Sync for users goes but devices is a whole different ballpark. Will look to update my original post with the final setup so future Googler’s can use the knowledge. How do you handle users if you don’t mind me asking? Do you keep all users within local AD and sync over to cloud? Do you have some cloud? Are you able to login to local AD using Azure AD accounts? As for groups do you handle those in AD or do you make use of M365 Groups so you can have Teams/SharePoint/Mailing List built in? Not sure if you can have Local AD Groups be 365 Groups? I know we could probably use Dynamic groups but we’d be having duplicates then.
  3. Thanks for following this up, sounds like you're doing exactly what I thought would be the best solution. Is there a specific configuration you had to do in order to be able to use Local AD alongside Intune? I assume just installing MS Entra Connect on the Domain Controller and configuring devices to join both Azure AD and Local AD through there? How does this work with Autopilot? If at all. Sorry for all the questions. You're my only hope at the minute haha
  4. LAPS already in place and working great! Device restrictions has a good few start menu and control panel settings I've been looking for. Man I really do need to avoid Administrative Templates as much as possible. Sadly it looks like there's still plenty of other stuff I'm not able to control like restricting MMC, Registry and Command Prompt, maybe this is something I can do elsewhere. Doesn't look like I can apply JSON to the Start Menu either. Win some, lose some I guess. Thanks for your help on this.
  5. So this is a similar setup to what I suggested in the OP? Applying some GPO settings using local AD or do you mean automating local Group Policy on the device?
  6. How are you handling user policies such as Start Menu/Taskbar, Desktop Wallpapers, Control Panel / Settings at a device level? Scripts or anything like that?
  7. Hi All, Not sure where else to post, but I think I'm going to get the 'welcome to the club' reply as I think this is just the nature of Intune. Whilst I love the concept of being able to cloud manage devices, I've noticed User Policies are inconsistent at best. Some will apply immediately, some will apply after 15 minutes and a second logon. For teachers and admin staff this is less of a concern, typically their devices will be 1:1 and once they have their policies they're sorted, assigning a primary user (I believe) will preconfigure that user to that device. My concern is student machines, with shared suites (no 1:1 scheme) it's rare students will login to the same machine twice so it's safe to assume a fresh login each time. Whilst they're standard users I'm still concerned with their ability to essentially run rampant on machines until policies are applied. What could be some potential resolutions? I've considered looking into co-management but I'd like to steer away from SCCM where possible (That's a beast too intimidating to tame haha). Is it possible to have an AD Hybrid-joined environment where I could potentially use GPOs for user policies? Or am I asking for trouble? Maybe it's best to stick with On Premise after all....
  8. @LeMarchand Could you potentially send me an installer too? Currently trying to migrate our MLS over to a new PC but we're stuck with the same issue :S
×
×
  • Create New...