Forum Discussion
Windows 10 Policies: Apply to user or device?
We are slowly working from moving from the PC Agent to MDM. There are still a few issues with MDM for Windows 10 and shared computers, but nevertheless, MDM is going to be where the future is headed.
I know there really isn't a hard and fast rule on whether you should apply a policy to a device or a user, but am wondering how other people out in the field are applying their policies. Has anyone come up with a best practices on which policies should be applied per user/per device? I know that every company has different requirements, but just curious if there is a little better guidance on this.
- sbuccimsft
Microsoft
One of the factors that should be considered how you apply policies is whether or not this will be a shared PC. https://docs.microsoft.com/en-us/intune/shared-user-device-settings-windows- Lynn TowleIron Contributor
sbuccimsftShared devices are my single biggest concern, but also trying to get non shared devices enrolled in MDM also.
We have about 300 Win 10 devices that are shared and hybrid joined. Deciding how we are going to manage those devices with Intune has been an ongoing discussion for the last few years. DEM? Bulk? Unfortunately there isn't an easy answer for that question. Each deployment method has different capabilities when it comes to Intune management, especially when talking about non-admin users and application deployment, configuration and other types of profiles needing to be targeted to those users.
That's why we've stuck with the PC agent for this long, it's simple, doesn't require a ton of management and while doesn't do everything we want, it gives us some fairly important functionality.
- sbuccimsft
Microsoft
Lynn Towle there is definitely a plethora of variables and methods for enrolling. There is a matrix on this 3rd-party blog article that illustrates the options and capabilities (updated towards the end for Intune and enrollment) https://microscott.azurewebsites.net/2018/08/31/managing-windows-10-with-intune-the-many-ways-to-enrol/
This is a scenario where I recommend talking to a Microsoft Partner or Microsoft Consulting Services to go over your companies current scenario and goals so you can go forward with the appropriate solution.