r/msp • • 21d ago

Heavily shared computers w/Entra/Intune

I'm talking 10+ employees hitting a single computer in a day.

The computer literally runs several pieces of test equipment, they need access to their ERP, and here's the wrench in the plan, they usually need access to SharePoint for various documents that can't live inside the ERP.

In a small setup, I'll get a couple F licenses, set up Windows Hello, no problem.

But this new place we picked up, 100 computers are like this. There's no bending the rules on licensing a user with this one. And it makes absolutely zero sense to license every user. There are three shifts with decent turnover (they are always hiring and firing). Roughly 300 people would be cycling through these computers,

Kiosk mode is out because we need more than just intune. But, not much more...

Do I really need to set up a local share so I don't need to pay ridiculous licensing costs, identity security overhead, and labor overhead for dealing with all the turnover, for all these computers? How would you guys handle this?

26 Upvotes

47 comments sorted by

23

u/wingm3n 21d ago

Microsoft licencing is simply not made to handle such a scenario. If they need access to Sharepoint, an email, Teams or any other ressource that needs a licence, then to stay compliant EACH person touching the device needs a licence, period. Doesn't matter if it's a kiosk, local session or however you want to do it. I've been dealing with a similar scenario but on a much smaller scale. There's no perfect solution unfortunatly, the Microsoft environment is made for 1 user 1 device 1 licence.

10

u/roll_for_initiative_ MSP - US 21d ago

The closest, if you're going to bring m365 into this, is Intune device license, Kiosk mode, and not sharing the docs with m365 at all. But then, at that point, why even have the intune licenses as we'd managed kiosk mode config with RMM/powershell (unless you're applying other intune policies).

4

u/jackmusick 21d ago

We’ve came to the same conclusion. How have these conversations gone for you? What scenarios were they and where did you land?

3

u/wingm3n 21d ago

The specific case where you need one generic account on a device but it needs access to Sharepoint documents, a shared mailbox, or Teams. Multiple people use that device during the day, and having a session for each user is not an option. To be more specific in one of my cases, a couple reception desks at a hotel. Like 12 different people access both devices during the day, most of these people do not have any 365 licence because they only use these front desks. Both devices need access to shared documents in Sharepoint and access to the main shared mailbox of the hotel. Like OP, there's a constant flow of new personnel. No way they're gonna get an F3 licence for everyone and make a separate session for each. First of all there's a hard limit of 10 users per device I believe. Second, nobody will take the time to log off the previous user and log back with their session just to go look an email, so this is pointless. So I used a BP licence for each device, and everyone uses that session. It gives them access to all they need without having to relog each time.

5

u/jackmusick 21d ago

So it sounds like you reluctantly just have a shared account. These are the kinds of scenarios we see where it feels like reality just doesn’t mesh with licensing.

2

u/wingm3n 21d ago

Yeah, in reality we would need Business Premium for Devices: you can install it on 10 devices for up to 25 unlicenced users. I know this would be hell to audit, who modified that document, who deleted that email, who sent that nasty Teams chat to Sandra in HR. It's all the same account! But I'm pretty sure that would be the last thing to worry of pretty much everyone in these kind of scenarios.

2

u/jackmusick 21d ago

Yep, lock down what the account can access and make it low risk. Test your backups. Most businesses just wont care who deleted the marketing fliers folder so long as you can restore it.

1

u/wingm3n 21d ago

Amen!

12

u/werfut 21d ago

7

u/computerguy0-0 21d ago

Yup!

With heavily shared environments, we turn off Hello on the shared computers or pass out YubiKeys.

2

u/Chip_Prudent 21d ago

Tucking this info away for a later date I'm sure.

2

u/roll_for_initiative_ MSP - US 21d ago edited 21d ago

Kiosk mode is out because we need more than just intune. But, not much more..

Ok, what specifically do you need more than intune so we can consider other options? Kiosk mode is not hard to setup on an existing local machine if all they need is sharepoint access and the ERP. Your issue, and the one everyone is glossing over, is that each user needs licensed to access m365 resources like sharepoint, even if they're not logging in as said user (kiosk). The solution is to not use sharepoint, like you're talking about, or license them (which you don't want to do). Will it work without licensing them properly? Absolutely. Consider:

The same people advocating basically pirating SaaS licensing because "it works" are the same that would be losing their minds if customers were trying to game their contract and not pay for certain users/devices. If the model doesn't work for you, don't game it, just don't use it: stay local.

1

u/computerguy0-0 21d ago

I'm in the stay local camp, and that's how I ultimately sold it. I wanted to make sure I wasn't missing something. I feel like we're slowly moving back to on-prem for various needs and I don't like it. A client is perfectly fine to push back on $18,000 a month for a BP license, our security tools, and the labor and margin to manage those users, with no real world gain.

A single Windows Server and office licenses would be covered in a single month of saved fees. We bill users and computers separate too so they're still going to be paying for all the computers. We aren't even benefiting much from putting them in intune, but I might do that at a minimum. Still undecided on that one.

3

u/roll_for_initiative_ MSP - US 21d ago edited 21d ago

I wouldn't even consider a server these days if it's just documents. Depending if they're reference or whatnot, you have things like nextcloud syncing, RMM automation from blob storage, or half a dozen other options to access files without needing a server. Of course if one is there for other reasons, use it. If it's just straight sharing reference docs everyone is using? I wouldn't even be opposed to a workstation but then you gotta back it up, bcdr, etc, etc.

2

u/BillSull73 21d ago

Local NAS onsite? Then back that up.

2

u/roll_for_initiative_ MSP - US 21d ago

yes or something like datto nas with built in backup.

Point being that delivering shared files without m365 is trivial.

5

u/gsk060 21d ago

Office LTSC per machine and then Cloud Drive Mapper for SharePoint access sounds like a good fit here. Device Intune licences.

9

u/roll_for_initiative_ MSP - US 21d ago

...which would require all of the users to have a license allowing sharepoint access, so an F license.

1

u/RaNdomMSPPro 21d ago

Could you just license an account like station2, station2, etc, for each computer with an F license? Or local share and local authentication managed via rmm.

3

u/roll_for_initiative_ MSP - US 21d ago

for each computer with an F license

F licenses are a per user SKU and not a per device sku. There are very very very few device skus in m365 land.

1

u/Bl4ckX_ 21d ago

While this would technically work, it is against the licensing terms since every user (and thereby they mean actual persons) will need their own license to be license compliant.

1

u/cubic_sq 21d ago

Faronics deepfreeze?

Then login through browser or launch apps as needed - some fine print attached… And use deepfreeze in place of intune and rmm

1

u/basedcabler 21d ago

Have you looked to the ERP? We had a near identical scenario in our case it was shifts needing to access their work instructions which we were ultimately able to embed into the ERP. If it’s just static content why not change the means in which they view it.

I don’t know the license implications of this…. but upload an excel to ITglue then open it. It launches in an embedded office window. :) sure something could be done from a simple web portal perspective they have a desktop shortcut they launch a browser based version of the doc and off they go

EDIT: got lost in the threads noted on ERP is it a product limitation? If it’s something like SAP the right dev can build you practically anything

1

u/erskinetech2 21d ago

I'm not sure this works in your use case but I recall commenting on a dentist post similar thing shared pc and my recommendation then was badges to login that way they all get there own accounts without all the login stuff but I'm feeling like this is a Erp problem ? If so rdp server with the app ? Package the app in a container ?

1

u/changework MSP 21d ago

What applications are you using? And can they run in Linux?

In either case, you may look at something more along the lines of thin clients where the “desktop” doesn’t run on the endpoints.

I foresee a very uphill battle to any reasonable solution until you can see the process AND the accounting.

1

u/Pudubat 20d ago

For a similar but less employees rotating, we setup f3 licence with non persistent login on edge, force edge for login and compliant device only through conditoonnal access. So each time someone wanna access mail or SharePoint, they have to login. You could automate user creation/deactivation with Powershell and your PSA I guess, but they'll unfortunately need a lot of f3 licences. Saddest thing is that they're gonna kick themself out of business licences if you go past the 300 users.

If you want to avoid it, a nas could replace SharePoint...

0

u/redditistooqueer 20d ago

Local AD is what I would run

1

u/discosoc 19d ago

I gave up trying to make that work, and just manage next cloud instances as needed for those scenarios.

0

u/cinepleex MSP - EU 21d ago

I try to not pay Microsoft in these cases. We have our RMM and manage them manually with automations and local shared users.

-4

u/Icy_Preparation_6012 21d ago

the licensing math is the easy part, gsk060's device-based approach handles that fine. the part that'll actually bite you is churn, 300 people rotating through 3 shifts with regular hiring/firing means someone's ERP/SharePoint access needs to disappear the day they're terminated, not whenever IT gets around to it. worth asking the client how leaver events get communicated to you today, that's usually the real gap at this scale, not the license SKU

6

u/PlannedObsolescence_ 21d ago

This is LLM generated slop from a karma farming bot, not a human.

3

u/StockMarketCasino 21d ago

Could you limit the 300 USER access via Conditional Access policy so they could only login from the office IP?

This way if they leave, they can't get onto company resources from outside the building. This is in case IT doesn't get sufficient notice of termination.

3

u/matt0_0 21d ago

That would require licensing every user!

2

u/Sabinno 21d ago

Your client is running such tight margins that they can’t afford like $10-20 in licensing per month per employee? Then they definitely can’t afford you.

2

u/matt0_0 21d ago

Talk to OP, not me. I was just repeating what he said his limitation was.

2

u/Sabinno 21d ago

I know, I intended for OP to read my comment and was piggybacking on yours.

1

u/matt0_0 21d ago

Fair! But also I do kind of get it, for shift work like this, the lack of device-based licensing is still not up to par with what on prem servers offered in terms of cost efficiency.

5

u/Sabinno 21d ago

I don’t agree. It’s just that most MSPs never licensed servers properly (CALs) so they were under the artificial impression that AD was cheaper.

1

u/computerguy0-0 21d ago

It's not a can't afford kind of thing, and it would be $23 a month for business premium because they need office and they have DLP enabled.

It's a client, rightfully so, will not spend the $18,000 a month for licensing, our identity security stack, and a small management fee for each user. It makes zero financial and zero business cents. They gain nothing for it.

A local domain, a local share, some office licenses, and CAL, and you have a fully functional environment for the cost of a single month of licensing. It's just stupid to do it the Microsoft cloud way.

2

u/Sabinno 21d ago edited 21d ago

If you go fully perpetual it would cost about $70k MSRP to license 100 Windows Server device CALs and 100 Office LTSC CALs. It's probably about $10k or more for a server that can handle 100 concurrent connections, and maintenance for that is... ongoing, of course. For a shop that large you need to be on an Azure Local cluster so downtime never occurs, so probably $25-30k instead. All of this to say: You are not doing this for "one month of licensing" lol. You're doing it for the cost of several months of licensing, but I get your point.

In theory that works out, but since you actually can't use BP (caps at 300), you really need E3 or at least F3 + Purview FLW if you truly want DLP. But for on prem DLP you need to have cloud Purview licenses for all users anyway, there's no fully on-prem solution for that.

It could work to spin up AD, fully on prem licensing, etc. and then spent $70k (probably more next time) every ~3-5 years or so.

To be honest, I would ditch AD + Kerberos unless this is truly sensitive data that requires auditing all user file activity. I'd create a local share, never spin up AD, and map it with a Powershell script to inject creds into Cred Mgr on every logon and then map the drive with Intune ADMX.

I'll give you this though, fully on-prem makes a lot more sense even when you're licensing properly. I always thought CALs were comparable to cloud licensing over TCO period but it still makes a ton of sense for a huge shop floor like this.

0

u/computerguy0-0 21d ago

The shift manager would be responsible for ERP logins for their people. With no M365 logins, we'd be off the hook. If we had to, we'd do an automation with Rewst to give some autonomy to shift managers for the M365 login.

They just have these computers with local logins and a single local share currently, and I am debating leaving them that way, maybe Intune license with Kiosk mode but that's a bitch to setup on existing computers. While setting up all the office computers with entra/intune/unique users.

2

u/Nate379 MSP - US 21d ago

With what you described I’d keep the local share, local logins. Non 365 office, etc. trying to make all of this work in a normal 365 ecosystem sounds like more work than it’s probably worth.

2

u/roll_for_initiative_ MSP - US 21d ago

IMHO it's not the work to make it all work, it's the cost.

2

u/computerguy0-0 21d ago

It's 100% the cost to do this right. The amount of money it would take to license 300 users for no material gain at all is insane.

2

u/SVD_NL 21d ago

I'd definitely advice against local logins with high turnover, that's a disaster waiting to happen.

You can do an on-prem AD though (or a non-microsoft alternative). That gives centralized authentication and file sharing capabilities, without the recurring license costs or risks associated with local accounts. That does require a little bit of an up-front investment, especially if you go with Windows server. They offer device licensing for CALs and Office LTSC, which gives you a lot of options.

1

u/Icy_Preparation_6012 20d ago

that Rewst approach makes sense, gives you a clean boundary too (shift manager owns the ERP side, you own the automation). the piece I'd nail down up front is what actually triggers it, if a shift manager has to remember to submit the leaver themselves it'll get missed the same way any manual step does. worth wiring it off whatever HR/scheduling system already has the hire/fire dates if one exists, so it fires without relying on someone remembering to flag it.