Home

Windows 10 Policies: Apply to user or device?

%3CLINGO-SUB%20id%3D%22lingo-sub-389505%22%20slang%3D%22en-US%22%3EWindows%2010%20Policies%3A%20Apply%20to%20user%20or%20device%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389505%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20slowly%20working%20from%20moving%20from%20the%20PC%20Agent%20to%20MDM.%20There%20are%20still%20a%20few%20issues%20with%20MDM%20for%20Windows%2010%20and%20shared%20computers%2C%20but%20nevertheless%2C%20MDM%20is%20going%20to%20be%20where%20the%20future%20is%20headed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20there%20really%20isn't%20a%20hard%20and%20fast%20rule%20on%20whether%20you%20should%20apply%20a%20policy%20to%20a%20device%20or%20a%20user%2C%20but%20am%20wondering%20how%20other%20people%20out%20in%20the%20field%20are%20applying%20their%20policies.%20Has%20anyone%20come%20up%20with%20a%20best%20practices%20on%20which%20policies%20should%20be%20applied%20per%20user%2Fper%20device%3F%20I%20know%20that%20every%20company%20has%20different%20requirements%2C%20but%20just%20curious%20if%20there%20is%20a%20little%20better%20guidance%20on%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-389505%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390341%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Policies%3A%20Apply%20to%20user%20or%20device%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390341%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F51768%22%20target%3D%22_blank%22%3E%40Lynn%20Towle%3C%2FA%3Ebe%20aware%20of%20the%20move%20away%20from%20Hybrid%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FIntune-Customer-Success%2FMove-from-Hybrid-Mobile-Device-Management-to-Intune-on-Azure%2Fba-p%2F280150%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FIntune-Customer-Success%2FMove-from-Hybrid-Mobile-Device-Management-to-Intune-on-Azure%2Fba-p%2F280150%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYes%2C%20yay%20for%20complexity!%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20sounds%20like%20you%20are%20aware%20of%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fdevice-enrollment-manager-enroll%23limitations-of-devices-that-are-enrolled-with-a-dem-account%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Elimitations%20of%20DEM%3C%2FA%3E%2C%20but%20linking%20just%20in%20case.%20In%20general%2C%20for%20the%20DEM%20situation%2C%20apply%20the%20device%20restriction%20profiles%20to%20the%20device.%26nbsp%3B%20For%20Apps%2C%20assign%20those%20to%20the%20users.%20I%20would%20assign%20apps%20as%20required%20that%20you%20know%20certain%20groups%20needs.%20For%20additional%20UWP%20(store)%20apps%2C%20you%20can%20have%20a%20Private%20Store%20in%20the%20Store%20app%2C%20that%20also%20syncs%20with%20Intune%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-store%2Fsign-up-microsoft-store-for-business%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-store%2Fsign-up-microsoft-store-for-business%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20Power%20Users%2C%20sounds%20like%20you%20can%20just%20do%20the%20straight%20shot%20of%20enrolling%20them%20directly%20either%20with%20auto-enrollment%20set%20up%20in%20Azure%20AD%20for%20OOBE%20or%20going%20into%20settings%20and%20Add%20Work%20or%20School%20Account.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESCCM%20if%20you%20don't%20already%20have%20it%20in%20your%20environment%2C%20you're%20just%20adding%20another%20level%20of%20administrative%20complexity%20over%20Intune%20Standalone.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPlease%20don't%20take%20my%20responses%20as%20a%20%22do%20it%20this%20way%22%20advice.%26nbsp%3B%20I'm%20break-fix%20support%2C%20not%20the%20setup%20and%20architecture%20that%20a%20Partner%20or%20MCS%20would%20provide.%20And%20as%20you%20have%20seen%2C%20there%20is%20more%20than%20one%20way%20to%20do%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390241%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Policies%3A%20Apply%20to%20user%20or%20device%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390241%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F172380%22%20target%3D%22_blank%22%3E%40Steve%20Bucci%3C%2FA%3E%26nbsp%3BI'm%20about%20to%20talk%20your%20ear%20off%2C%20but%20I'm%20not%20expecting%20a%20reply.%20I'm%20just%20passionate%20about%20this%2C%20and%20knowing%20how%20different%20companies%20environments%20are%20setup%20would%20seem%20useful%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20a%20smaller%20mid-sized%20business%2C%20in%20the%20real%20estate%20sector%2C%20and%20have%20about%20600%20devices%20that%20we%20manage.%20Almost%20half%20of%20those%20devices%20are%20shared%20Win%2010%20desktops.%20We%20have%20a%20hybrid%20environment%20and%20will%20have%20one%20until%20certain%20things%20are%20changed%20on%20the%20Azure%20Active%20Directory%20Services%20side.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe've%20spoken%20to%20a%20few%20partners%2C%20but%20unfortunately%2C%20there%20isn't%20a%20%22single%22%20deployment%20method%20that%20would%20work%20in%20our%20environment.%20We%20will%20most%20likely%20use%20DEM%2C%20but%20we%20are%20still%20working%20out%20all%20the%20particulars%20on%20that%20model%2C%20but%20DEM%20will%20get%20us%20to%20about%2085%25%20of%20where%20we%20need%20to%20be.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E85%25%20of%20the%20users%20in%20our%20environment%20are%20what%20many%20businesses%20would%20call%20%22first%20line%22%20workers%2C%20but%20their%20jobs%20are%20a%20bit%20more%20complex%20than%20that%2C%20technologically%20speaking.%20Our%20leasing%20offices%20are%20an%20open%20floor%20plan%2C%20and%20users%20bounce%20from%20one%20desktop%20to%20another%20depending%20on%20the%20day%2C%20who%20is%20working%2C%20and%20other%20various%20factors.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDEM%20deployment%20for%20those%20users%20is%20a%20no%20brainer%2C%20they%20will%20never%20need%20to%20be%20an%20admin%20on%20the%20desktop%20and%20their%20application%2C%20configuration%2C%20and%20permission%20sets%20are%20standardized%20throughout%20the%20company.%20The%20other%2015%25%20of%20users%20is%20where%20we%20run%20into%20our%20headaches.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThose%20users%20are%20what%20would%20have%20historically%20been%20called%20our%20%22Power%20Users%22%2C%20and%20they%20require%20slightly%20different%20%3CSPAN%3Eapplication%2C%20configuration%2C%20and%20permission%20sets%20than%20the%20standard%20users.%20These%20users%20try%20to%20use%20the%20same%20computer%20every%20day%2C%20but%20in%20cases%20such%20as%20a%20break%2Ffix%20situation%2C%20or%20office%20to%20office%20movements%20for%20coverage%2C%20they%20may%20sign%20into%20a%20totally%20different%20computer%20in%20order%20to%20work.%20SCCM%20handles%20that%20situation%20fairly%20well%3B%20Intune%2C%20especially%20in%20a%20DEM%20deployment%2C%20does%20not.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20computers%20the%20%22Power%20Users%22%20log%20into%20are%20also%20available%20for%20the%20%22Standard%20Users%22%20to%20log%20into%2C%20again%2C%20break%2Ffix%2C%20or%20movement%20for%20coverage%2C%20are%20the%20biggest%20contributing%20factors%20to%20this.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI've%20considered%20setting%20up%20an%20SCCM%20server%2C%20but%20for%20our%20environment%2C%20SCCM%20is%20fairly%20complex%20and%20requires%20a%20significant%20portion%20of%20resources%20to%20manage%20and%20maintain%20properly.%20We%20are%20also%20trying%20very%20hard%20to%20decommission%20our%20on-prem%20environment%2C%20but%20can't%20at%20this%20moment%20for%20various%20reasons.%20I've%20admin'd%20SCCM%20environments%20before%2C%20it%20is%20an%20awesome%20tool%2C%20but%20a%20bit%20too%20much%20for%20our%20current%20environment%2C%20and%20am%20trying%20not%20to%20install%20another%20on-prem%20service%20to%20manage%20our%20fleet.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ESo%2C%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EYay!%20Complexity!%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe'll%20get%20there%2C%20it's%20just%20taking%20some%20extra%20time%20to%20fully%20realize%20our%20dreams%20of%20being%20able%20to%20be%20fully%20managed%20by%20Intune.%20%3A)%3C%2Fimg%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390123%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Policies%3A%20Apply%20to%20user%20or%20device%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390123%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F51768%22%20target%3D%22_blank%22%3E%40Lynn%20Towle%3C%2FA%3Ethere%20is%20definitely%20a%20plethora%20of%20variables%20and%20methods%20for%20enrolling.%26nbsp%3B%20There%20is%20a%20matrix%20on%20this%203rd-party%20blog%20article%20that%20illustrates%20the%20options%20and%20capabilities%20(updated%20towards%20the%20end%20for%20Intune%20and%20enrollment)%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fmicroscott.azurewebsites.net%2F2018%2F08%2F31%2Fmanaging-windows-10-with-intune-the-many-ways-to-enrol%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fmicroscott.azurewebsites.net%2F2018%2F08%2F31%2Fmanaging-windows-10-with-intune-the-many-ways-to-enrol%2F%3C%2FA%3E%3C%2FFONT%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20is%20a%20scenario%20where%20I%20recommend%20talking%20to%20a%20Microsoft%20Partner%20or%20Microsoft%20Consulting%20Services%20to%20go%20over%20your%20companies%20current%20scenario%20and%20goals%20so%20you%20can%20go%20forward%20with%20the%20appropriate%20solution.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-389597%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Policies%3A%20Apply%20to%20user%20or%20device%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389597%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F172380%22%20target%3D%22_blank%22%3E%40Steve%20Bucci%3C%2FA%3EShared%20devices%20are%20my%20single%20biggest%20concern%2C%20but%20also%20trying%20to%20get%20non%20shared%20devices%20enrolled%20in%20MDM%20also.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20about%20300%20Win%2010%20devices%20that%20are%20shared%20and%20hybrid%20joined.%20Deciding%20how%20we%20are%20going%20to%20manage%20those%20devices%20with%20Intune%20has%20been%20an%20ongoing%20discussion%20for%20the%20last%20few%20years.%20DEM%3F%20Bulk%3F%20Unfortunately%20there%20isn't%20an%20easy%20answer%20for%20that%20question.%20Each%20deployment%20method%20has%20different%20capabilities%20when%20it%20comes%20to%20Intune%20management%2C%20especially%20when%20talking%20about%20non-admin%20users%20and%20application%20deployment%2C%20configuration%20and%20other%20types%20of%20profiles%20needing%20to%20be%20targeted%20to%20those%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat's%20why%20we've%20stuck%20with%20the%20PC%20agent%20for%20this%20long%2C%20it's%20simple%2C%20doesn't%20require%20a%20ton%20of%20management%20and%20while%20doesn't%20do%20everything%20we%20want%2C%20it%20gives%20us%20some%20fairly%20important%20functionality.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-389566%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Policies%3A%20Apply%20to%20user%20or%20device%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389566%22%20slang%3D%22en-US%22%3EOne%20of%20the%20factors%20that%20should%20be%20considered%20how%20you%20apply%20policies%20is%20whether%20or%20not%20this%20will%20be%20a%20shared%20PC.%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fshared-user-device-settings-windows%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fshared-user-device-settings-windows%3C%2FA%3E%3C%2FLINGO-BODY%3E
Lynn Towle
Contributor

We are slowly working from moving from the PC Agent to MDM. There are still a few issues with MDM for Windows 10 and shared computers, but nevertheless, MDM is going to be where the future is headed.

 

I know there really isn't a hard and fast rule on whether you should apply a policy to a device or a user, but am wondering how other people out in the field are applying their policies. Has anyone come up with a best practices on which policies should be applied per user/per device? I know that every company has different requirements, but just curious if there is a little better guidance on this.

5 Replies
One of the factors that should be considered how you apply policies is whether or not this will be a shared PC. https://docs.microsoft.com/en-us/intune/shared-user-device-settings-windows

@Steve BucciShared devices are my single biggest concern, but also trying to get non shared devices enrolled in MDM also.

 

We have about 300 Win 10 devices that are shared and hybrid joined. Deciding how we are going to manage those devices with Intune has been an ongoing discussion for the last few years. DEM? Bulk? Unfortunately there isn't an easy answer for that question. Each deployment method has different capabilities when it comes to Intune management, especially when talking about non-admin users and application deployment, configuration and other types of profiles needing to be targeted to those users.

 

That's why we've stuck with the PC agent for this long, it's simple, doesn't require a ton of management and while doesn't do everything we want, it gives us some fairly important functionality.

@Lynn Towle there is definitely a plethora of variables and methods for enrolling.  There is a matrix on this 3rd-party blog article that illustrates the options and capabilities (updated towards the end for Intune and enrollment) https://microscott.azurewebsites.net/2018/08/31/managing-windows-10-with-intune-the-many-ways-to-enr... 

This is a scenario where I recommend talking to a Microsoft Partner or Microsoft Consulting Services to go over your companies current scenario and goals so you can go forward with the appropriate solution.

@Steve Bucci I'm about to talk your ear off, but I'm not expecting a reply. I'm just passionate about this, and knowing how different companies environments are setup would seem useful :)

 

We are a smaller mid-sized business, in the real estate sector, and have about 600 devices that we manage. Almost half of those devices are shared Win 10 desktops. We have a hybrid environment and will have one until certain things are changed on the Azure Active Directory Services side.

 

We've spoken to a few partners, but unfortunately, there isn't a "single" deployment method that would work in our environment. We will most likely use DEM, but we are still working out all the particulars on that model, but DEM will get us to about 85% of where we need to be.

 

85% of the users in our environment are what many businesses would call "first line" workers, but their jobs are a bit more complex than that, technologically speaking. Our leasing offices are an open floor plan, and users bounce from one desktop to another depending on the day, who is working, and other various factors.

 

DEM deployment for those users is a no brainer, they will never need to be an admin on the desktop and their application, configuration, and permission sets are standardized throughout the company. The other 15% of users is where we run into our headaches.

 

Those users are what would have historically been called our "Power Users", and they require slightly different application, configuration, and permission sets than the standard users. These users try to use the same computer every day, but in cases such as a break/fix situation, or office to office movements for coverage, they may sign into a totally different computer in order to work. SCCM handles that situation fairly well; Intune, especially in a DEM deployment, does not.

 

The computers the "Power Users" log into are also available for the "Standard Users" to log into, again, break/fix, or movement for coverage, are the biggest contributing factors to this.

 

I've considered setting up an SCCM server, but for our environment, SCCM is fairly complex and requires a significant portion of resources to manage and maintain properly. We are also trying very hard to decommission our on-prem environment, but can't at this moment for various reasons. I've admin'd SCCM environments before, it is an awesome tool, but a bit too much for our current environment, and am trying not to install another on-prem service to manage our fleet.

 

So, Yay! Complexity!

 

We'll get there, it's just taking some extra time to fully realize our dreams of being able to be fully managed by Intune. :)

@Lynn Towle be aware of the move away from Hybrid https://techcommunity.microsoft.com/t5/Intune-Customer-Success/Move-from-Hybrid-Mobile-Device-Manage...

 

Yes, yay for complexity!

It sounds like you are aware of limitations of DEM, but linking just in case. In general, for the DEM situation, apply the device restriction profiles to the device.  For Apps, assign those to the users. I would assign apps as required that you know certain groups needs. For additional UWP (store) apps, you can have a Private Store in the Store app, that also syncs with Intune https://docs.microsoft.com/en-us/microsoft-store/sign-up-microsoft-store-for-business

 

The Power Users, sounds like you can just do the straight shot of enrolling them directly either with auto-enrollment set up in Azure AD for OOBE or going into settings and Add Work or School Account.

 

SCCM if you don't already have it in your environment, you're just adding another level of administrative complexity over Intune Standalone.

 

Please don't take my responses as a "do it this way" advice.  I'm break-fix support, not the setup and architecture that a Partner or MCS would provide. And as you have seen, there is more than one way to do it.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies