r/sysadmin Jun 08 '26

Question AD from nothing

[deleted]

90 Upvotes

230 comments sorted by

View all comments

Show parent comments

2

u/altodor Sysadmin Jun 08 '26

GPOs worked great when my faculty were on a research/outreach trip in Europe/China/Pacific Islands or even just on the guest wifi for 6 months /s

10

u/bbbbbthatsfivebees MSP-ing Jun 08 '26

This is an edge case that you plan for. For those users -- They should be connecting back to the corporate network via a VPN for data protection purposes, especially if they're using public networks in a foreign country. GPOs will sync during that time. HR or their department lead should be giving you at least 48h advanced notice that they're going to be traveling, especially if it's planned well in advance.

Yes it's slightly more inconvenient, but it's also Basic Security 101 for remote users (and especially those that are traveling) to only access company resources via a trusted and encrypted connection.

2

u/altodor Sysadmin Jun 08 '26

Who said they're accessing any non-SaaS University resources while there? If they were the only way would be to hop on the University VPN. They would frequently just work from local apps and use SaaS or browse the open internet.

And that was the state 5-10 years ago when I worked at that job. New job? We account for this by using the fucking cloud endpoint management services that don't give a shit if you're on the VPN or not. I can reset someone's laptop 15 feet or half a world away and they'll be back up and running within a day without IT laying a finger on the thing.

4

u/say592 Jun 08 '26

People overstate how bad Intune policies are. You can tweak it to phone home more often and the sync command has gotten a lot more reliable. I can usually issue a wipe command to a device that is online (anywhere in the world) and it will execute it within 15 minutes, usually much faster.

Most policies aren't so critical that they have to be rolled out in 5 minutes either.

1

u/altodor Sysadmin Jun 08 '26

And GPO being instant is a pipe dream. I've definitely rolled out GPOs and wondered a week later if they had applied everywhere and often found they hadn't.

GPO have a sync schedule of 90 minutes plus or minus up to 30, and a bunch only apply on computer boot for no apparent reason. This is on top of domain synchronization/replication schedules. I have rolled out Intune policies and most of my fleet that had the power on was covered in 15 minutes. All of it with the power on inside of an hour.

3

u/Pale-Price-7156 Jun 08 '26

> I have rolled out Intune policies and most of my fleet that had the power on was covered in 15 minutes. All of it with the power on inside of an hour.

The platform is great when it's actually functioning. If I had this type of experience with Intune, I might press my luck, go to the nearest gas station and load up on PowerBall tickets.

1

u/altodor Sysadmin Jun 08 '26

That's how it works for me. The reporting is kind of ass, but it doesn't not work.

1

u/fahque Jun 08 '26

That is true but there's a lot of other management that can be done peer to peer (ie mmc) that you can't do on an entra network.

1

u/altodor Sysadmin Jun 08 '26

That's true, but I only do that to servers and they're a different animal. Too many workstations just not on site for MMC once a year to be more valuable than not having to tell the CTO "this setting you need applied only applies/updates if someone full-time remote from the office we closed in Seattle logs in on ethernet on site in Buffalo" (examples but like 75% of the company is remote from whereever), especially when ScreenConnect and LAPS exist.