Provision Windows devices from anywhere to support a mobile workforce

%3CLINGO-SUB%20id%3D%22lingo-sub-1289174%22%20slang%3D%22en-US%22%3EProvision%20Windows%20devices%20from%20anywhere%20to%20support%20a%20mobile%20workforce%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1289174%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20this%2C%20our%20second%20chapter%20of%20the%20Enabling%20Remote%20Work%20for%20IT%20Pros%20web%20series%2C%20we%20focus%20on%20practical%20tips%20to%20help%20you%20effectively%20provision%20Windows%20devices%20from%20anywhere.%20We%20walk%20through%20a%20variety%20of%20strategies%2C%20from%20simple%20to%20complex%2C%20to%20help%20you%20better%20understand%20how%20to%20leverage%20Azure%20AD%20Join%20with%20Microsoft%20Intune%2C%20or%20Configuration%20Manager%20co-management%20and%20task%20sequences.%20We%20then%20present%20you%20with%20a%20clear%20list%20of%20the%20steps%20you%20can%20take%20now%2C%20start%20soon%2C%20or%20work%20on%20in%20the%20future.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22enabling-remote-work.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F184867i95686E6CFCC29173%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22enabling-remote-work.png%22%20alt%3D%22enabling-remote-work.png%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CDIV%20style%3D%22position%3A%20relative%3B%20padding-bottom%3A%2056.25%25%3B%20padding-top%3A%2030px%3B%20height%3A%200%3B%20overflow%3A%20hidden%3B%20min-width%3A%20320px%3B%22%3E%3CIFRAME%20src%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fvideoplayer%2Fembed%2FRE4thA0%3Fautoplay%3Dfalse%22%20frameborder%3D%220%22%20allowfullscreen%3D%22allowfullscreen%22%20style%3D%22position%3A%20absolute%3B%20top%3A%200%3B%20left%3A%200%3B%20width%3A%20100%25%3B%20height%3A%20100%25%3B%22%20class%3D%22video-iframe%22%20your%3D%22%22%20video%3D%22%22%20title%3D%22%E2%80%9Dput%22%20here%3D%22%22%3E%3C%2FIFRAME%3E%3C%2FDIV%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20style%3D%22margin-top%3A%2036px%3B%20margin-bottom%3A%2020px%3B%22%20id%3D%22toc-hId--1380178992%22%20id%3D%22toc-hId--1380178992%22%3ELearn%20more%3C%2FH2%3E%0A%3CP%3EHere%20are%20links%20to%20the%20resources%20mentioned%20in%20this%20session%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fwindows-enroll%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EAutomatic%20MDM%20enrollment%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DGfYOyFMc8vA%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3EUsing%20Windows%20Hello%20for%20Business%20to%20Access%20On-Premises%20Resources%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fmniehaus%2Fafraid-of-windows-10-with-azure-ad-join-try-it-out-part-2%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EEnable%20Kerberos%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fconfiguration-manager-blog%2Fmanaging-remote-machines-with-cloud-management-gateway-in%2Fba-p%2F1233895%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EManaging%20remote%20machines%20with%20cloud%20management%20gateway%20in%20Microsoft%20Endpoint%20Configuration%20Manager%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CBR%20%2F%3EWhile%20not%20mentioned%20specifically%20in%20this%20session%2C%20here%20are%20some%20additional%20resources%20you%20might%20find%20helpful%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fnews.microsoft.com%2Fcovid-19-response%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EMicrosoft%20COVID-19%20response%20site%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fenabling-remote-work%2Fct-p%2FRemoteWork%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EEnabling%20Remote%20Work%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fenterprise-mobility-security%2Fhelping-businesses-rapidly-set-up-to-work-securely-from-personal%2Fba-p%2F1239830%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EMicrosoft%20Endpoint%20Manager%20remote%20work%20blog%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2020%2F03%2F12%2Fsupport-working-from-home-securely%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWork%20remotely%2C%20stay%20secure%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fblog%2F2020%2F03%2F18%2Fmaking-the-switch-to-remote-work-5-things-weve-learned%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3E2%20weeks%20in%3A%20what%20we%E2%80%99ve%20learned%20about%20remote%20work%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH2%20style%3D%22margin-top%3A%2036px%3B%20margin-bottom%3A%2020px%3B%22%20id%3D%22toc-hId-1107333841%22%20id%3D%22toc-hId-1107333841%22%3EFrequently%20asked%20questions%3C%2FH2%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20For%20Hybrid%20Azure%20AD%20join%2C%20if%20we%20have%20a%20line%20of%20sight%20with%20the%20domain%20controller%2C%20is%20the%20Intune%20connector%20required%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20Yes%2C%20it%E2%80%99s%20what%20gathers%20an%20offline%20domain%20join%20blob%20from%20your%20domain%20controller.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20Is%20there%20a%20way%20to%20define%20the%20complete%20computer%20name%20for%20devices%20provisioned%20via%20Windows%20Autopilot%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20For%20Azure%20AD%20Join%20devices%2C%20yes%2C%20there%20is%20a%20graph%20API.%20For%20Hybrid%20Azure%20AD%20devices%2C%20no%2C%20there%20is%20only%20the%20ability%20to%20prefix%20something%20onto%20the%20name.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20Is%20there%20a%20list%20of%20supported%20VPN%20clients%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20We%20don%E2%80%99t%20have%20a%20supported%20list%20because%20we%20don%E2%80%99t%20support%20the%20configuration%20of%20third-party%20VPN%20clients.%20Customers%20will%20need%20to%20figure%20out%20if%20your%20VPN%20works%20in%20this%20scenario.%20The%20real%20question%20to%20ask%20is%20%E2%80%98does%20your%20VPN%20support%20pre-logon%2Fstart%20before%20logon%20auth%3F%E2%80%99%20or%20some%20sort%20of%20AOVPN.%26nbsp%3B%20If%20so%2C%20it%20will%20work.%26nbsp%3B%20These%20are%20some%20of%20the%20VPN%20providers%20we%20expect%20to%20work%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20style%3D%22margin-top%3A%2020px%3B%22%3ECisco%20AnyConnect%20(Win32%20client)%3A%20%E2%80%9CStart%20before%20Logon%E2%80%9D%3C%2FLI%3E%0A%3CLI%3EPulse%20Secure%20(Win32%20client)%3A%20%E2%80%9CCredential%20Provider%E2%80%9D%3C%2FLI%3E%0A%3CLI%3EGlobalProtect%20(Win32%20client)%3A%20%E2%80%9CPre-logon%E2%80%9D%3C%2FLI%3E%0A%3CLI%3ECheckpoint%20(Win32%20client)%3A%20%E2%80%9CAuto%20Connect%2FAlways%20Connected%E2%80%9D%3C%2FLI%3E%0A%3CLI%3ECitrix%20NetScaler%20(Win32%20client)%3A%20%E2%80%9CAlways%20on%E2%80%9D%3C%2FLI%3E%0A%3CLI%3ESonicWall%20(Win32%20client)%3A%20%E2%80%9CNetExtender%20on%20Startup%E2%80%9D%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3ENote%3A%20%3C%2FSTRONG%3EWe%20do%20not%20document%20or%20support%20how%20you%20configure%20your%20VPN%20as%20it%20is%20a%20third-party%20configuration.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20Is%20there%20a%20way%20to%20get%20the%20device%20enrolled%20in%20Windows%20Autopilot%20remotely%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20The%20only%20way%20is%20if%20it%E2%80%99s%20currently%20managed%20through%20Intune.%20You%20can%20assign%20a%20Windows%20Autopilot%20profile%20with%20the%20%E2%80%9CConvert%20devices%20to%20Autopilot%E2%80%9D%20option%20enabled%2C%20and%20the%20hardware%20has%20will%20be%20automatically%20harvested%20at%20the%20next%20check%20in.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20Are%20there%20any%20alternatives%20to%20enroll%20multiple%20devices%2C%20already%20deployed%2C%20besides%20Windows%20Autopilot%20and%20Bulk%20enroll%20using%20provisioning%20package%20files%20(PPKG)%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20All%20of%20the%20possibilities%20are%20documented%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-enrollment-methods%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-enrollment-methods%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CU%3E%26nbsp%3B%3C%2FU%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20Is%20there%20a%20way%20to%20use%20White%20Glove%20deployment%20with%20standard%20applications%20without%20pre-assigning%20the%20device%20to%20a%20particular%20user%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20If%20you%20target%20your%20applications%20to%20devices%2C%20then%20you%20don%E2%80%99t%20need%20to.%20If%20the%20apps%20are%20assigned%20to%20users%2C%20then%20you%20need%20to%20assign%20a%20user.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%20Are%20we%20able%20to%20deploy%20the%20provisioning%20package%20files%20through%20Intune%3F%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EA%3A%3C%2FSTRONG%3E%20No%2C%20this%20is%20not%20currently%20supported.%3C%2FP%3E%0A%3CH2%20style%3D%22margin-top%3A%2036px%3B%20margin-bottom%3A%2020px%3B%22%20id%3D%22toc-hId--700120622%22%20id%3D%22toc-hId--700120622%22%3EFeedback%3C%2FH2%3E%0A%3CP%3EWe%20hope%20you%20find%20this%20session%20useful.%20We'd%20love%20your%20feedback%20and%20ideas%20for%20future%20sessions%20so%20please%20%3CSTRONG%3E%3CA%20title%3D%22Share%20your%20feedback!%22%20href%3D%22https%3A%2F%2Fforms.office.com%2FFormsPro%2FPages%2FResponsePage.aspx%3Fid%3Dv4j5cvGGr0GRqy180BHbR6Y3c5FtvxlLgwJNBAvsrFZUREFYOFFYNTNVT1EyQjYzVEY1TjhDNjZESy4u%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Efill%20out%20this%20short%20survey%3C%2FA%3E%3C%2FSTRONG%3E.%20Thank%20you!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1289174%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%20Join%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EConfiguration%20Manager%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDeploy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Endpoint%20Manager%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Intune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eprovision%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Evpn%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Microsoft

In this, our second chapter of the Enabling Remote Work for IT Pros web series, we focus on practical tips to help you effectively provision Windows devices from anywhere. We walk through a variety of strategies, from simple to complex, to help you better understand how to leverage Azure AD Join with Microsoft Intune, or Configuration Manager co-management and task sequences. We then present you with a clear list of the steps you can take now, start soon, or work on in the future.

enabling-remote-work.png

 

Learn more

Here are links to the resources mentioned in this session:


While not mentioned specifically in this session, here are some additional resources you might find helpful:

Frequently asked questions

Q: For Hybrid Azure AD join, if we have a line of sight with the domain controller, is the Intune connector required?

A: Yes, it’s what gathers an offline domain join blob from your domain controller.

 

Q: Is there a way to define the complete computer name for devices provisioned via Windows Autopilot?

A: For Azure AD Join devices, yes, there is a graph API. For Hybrid Azure AD devices, no, there is only the ability to prefix something onto the name.

 

Q: Is there a list of supported VPN clients?

A: We don’t have a supported list because we don’t support the configuration of third-party VPN clients. Customers will need to figure out if your VPN works in this scenario. The real question to ask is ‘does your VPN support pre-logon/start before logon auth?’ or some sort of AOVPN.  If so, it will work.  These are some of the VPN providers we expect to work:

  • Cisco AnyConnect (Win32 client): “Start before Logon”
  • Pulse Secure (Win32 client): “Credential Provider”
  • GlobalProtect (Win32 client): “Pre-logon”
  • Checkpoint (Win32 client): “Auto Connect/Always Connected”
  • Citrix NetScaler (Win32 client): “Always on”
  • SonicWall (Win32 client): “NetExtender on Startup”

Note: We do not document or support how you configure your VPN as it is a third-party configuration.

 

Q: Is there a way to get the device enrolled in Windows Autopilot remotely?

A: The only way is if it’s currently managed through Intune. You can assign a Windows Autopilot profile with the “Convert devices to Autopilot” option enabled, and the hardware has will be automatically harvested at the next check in.

 

Q: Are there any alternatives to enroll multiple devices, already deployed, besides Windows Autopilot and Bulk enroll using provisioning package files (PPKG)?

A: All of the possibilities are documented here: https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-methods

 

Q: Is there a way to use White Glove deployment with standard applications without pre-assigning the device to a particular user?

A: If you target your applications to devices, then you don’t need to. If the apps are assigned to users, then you need to assign a user.

 

Q: Are we able to deploy the provisioning package files through Intune?

A: No, this is not currently supported.

Feedback

We hope you find this session useful. We'd love your feedback and ideas for future sessions so please fill out this short survey. Thank you!

 

 

0 Replies