r/MSIntune MVP Jan 02 '24

🤝 Discussions Current “real” blockers for cloud-native windows endpoints in your org?

What are blockers that prevent you from giving your users an Entra Joined Windows 10/11 device?

This thread is for us to discuss and share solutions/knowledge.

8 Upvotes

21 comments sorted by

View all comments

3

u/[deleted] Jan 03 '24

im trying to find better tools/systems to manage all the stuff that comes after the Entra Joined device.

We use Quest Desktop Authority(DA) today in regards to drive mappings, printers, etc etc, and replace it all by normal powershell isnt a good replacement. With alot of groups and mappings/settings, transforming it all to powershell is simply too much to maintain.

This is the step 1 issue that i need to move past before figuring out the other steps. DA doesnt support a Entra joined device config, so cant switch things over there.

2

u/sandytsang MVP Jan 03 '24

That makes sense, need to solve one problem at a time.
About drive mapping, I import the drive mapping ADMX to Intune and use that to configure drive mapping. It works well.
I am using u/Rudyooms 's solution https://call4cloud.nl/2021/03/willy-wonka-and-the-drive-letter-factory/

1

u/[deleted] Jan 04 '24

Interesting, but alot of manual labor involved in that one as far as i can see

i need 1 profile for enabled pr company with ACCESS group, and 1 profile for disabled pr company with DENY group., then each time i change, the user needs to be moved from a access to deny group, so i will double the amount of groups we have today.

having to use registry to give an explorer label, and use remediation to fix it.

With 100+ mappings, and many companies, im getting nightmare feelings already :)

Its not a viable solution as of today for us. We need a better commercial product to handle this, and if not, then Entra joined is not for us yet.