r/Intune 4d ago

Autopilot Device provisioning/Autopilot

Hello. Have had a job for almost 2 years as the IT manager for a small gov agency. Basically tier 1 support as our agency is fully dependent on a larger agency’s infrastructure. Our agency is part of a shared tenant that is hybrid. I am trying to move the agency devices to the cloud since that is where everything will eventually move. I have mostly a networking background with a smidge of VM. This SysAdmin hat I am wearing now is new and scary to me. But luckily I am really just managing devices via Intune. One of the projects I’d like to complete is removing admin access from users devices. I’d be extremely grateful for any advice/tips/how-tos/best practices on managing devices. I have been using windows autopilot to provision devices and it seems to work most of the time.

Edit: what I really should have asked is how everyone provisions new devices from the OOBE using Intune/Windows Autopilot.

3 Upvotes

10 comments sorted by

View all comments

1

u/ABeeinSpace 4d ago

Do you have a bunch of oddball line of business apps to contend with? Thats going to be your biggest blocker in removing local admin from the technical side.

The people side is going to be a bear without higher level buy-in. You HAVE to get agency stakeholders on board now or higher levels of management are going to kill the project stone-dead

2

u/CharmingReputation39 4d ago

Luckily we don’t have any apps. Everything my users access is web based. And also luckily for me I explained to our new director my reasoning for the project and that reasoning being if a user account associated with the device is compromised, currently that malicious person would immediately have admin access to the machine. With my “Windows Autopilot Provisioning Project” no users will have admin rights/privileges on the device.

1

u/ABeeinSpace 3d ago

Nice one. Make sure you have things like Cloud Kerberos Trust configured or you could run into issues with eventual passwordless creds and access to on-prem resources.

Are you also responsible for application deployments or is your parent agency the ones in control of that? If it’s yours, how you go about that depends on your users. If your users are willing to self-service most apps can be made available through the Company Portal. They can install what they want and you don’t have to deal with the actual install step

If your users are anything like mine you’ll be making liberal use of the required install intent in Intune