• Recent
  • Popular
  • Unsolved
  • Categories
  • Tags
  • Chat
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
SysAdmins Zone Logo

New device prep

Scheduled Pinned Locked Moved General
windowssecurity
6 Posts 2 Posters 37 Views
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • katosK Offline
    katosK Offline
    katos Admin
    wrote on last edited by
    #1

    Hi team!

    What do you guys do when you get a new device, either for home or for work purposes? 🙂

    1 Reply Last reply
    0
  • katosK Offline
    katosK Offline
    katos Admin
    wrote on last edited by katos
    #2

    Personal:

    1. Remove bloatware
    2. Install applications (usually stored on a Portable Hard Drive) and update as required. (Incl. Windows Updates)
    3. Run Windows 10 Powershell to remove unwanted applications and change registry for tracking etc.
    4. Update Drivers / Firmware
    5. Install device-specific applications (depending on the role of the device)

    Business:

    1. Install from image.
    2. Run powershell to ready the device to our pre-approved stage.
    3. Install Office, antivirus and business applications that are not dished by GPO.
    4. Disable power settings on the network adapters
    5. Update as far as possible.
    6. Add device to domain and run GPO.
    7. Configure for end user (department-specific).
    8. Full disk encrypt the device if portable or in specific departments.
    9. Run Windows updates.
    10. Test all applications.
    11. Peer-review device, and prep additional equipment (keyboard / mouse / bag / etc)
    12. Arrange installation.
    1 Reply Last reply
    0
  • tankerkiller125T Offline
    tankerkiller125T Offline
    tankerkiller125 Admin
    wrote on last edited by
    #3

    Personal:

    1. Remove windows, replace with the latest Ubuntu (usually LTS, but not always)
    2. Install the apps I need/want
    3. Install Steam Proton (notably the GE version)

    Business:

    1. Ship laptop to employee
    2. When it's a new employee, email their personal account with their new company email and password 24 hours before start date.
    3. Employee signs in with work account
    4. Intune/Autopilot take care of installing core apps, running PowerShell scripts to remove bloatware, and apply policies.
    5. Use FleetDM 24 hours after deployment to make sure that all the policies are being met (notably full disk encryption)

    Working for a small company, and using Intune makes deploying laptops stupid easy, and so far we haven't had any issues despite technically being in a hybrid environment (a lot of our VMs are still on-prem domain joined)

    katosK 1 Reply Last reply
    0
  • katosK Offline
    katosK Offline
    katos Admin
    replied to tankerkiller125 on last edited by
    #4

    tankerkiller125 said in New device prep:

    Intune/Autopilot take care of installing core apps, running PowerShell scripts to remove bloatware, and apply policies.
    Use FleetDM 24 hours after deployment to make sure that all the policies are being met (notably full disk encryption)

    Curious - Why are you using FleetDM and not an Intune Compliance policy?
    If you wanted, you could then leverage a conditional access policy to lock out the device UNTIL it was compliant with the disk encryption, AV, etc?

    tankerkiller125T 1 Reply Last reply
    0
  • tankerkiller125T Offline
    tankerkiller125T Offline
    tankerkiller125 Admin
    replied to katos on last edited by
    #5

    katos We do use FleetDM because I can run realtime queries, we do have a compliance policy in intune as well, but we find that it's very slow to update if something changes.

    katosK 1 Reply Last reply
    1
  • katosK Offline
    katosK Offline
    katos Admin
    replied to tankerkiller125 on last edited by
    #6

    tankerkiller125 said in New device prep:

    katos We do use FleetDM because I can run realtime queries, we do have a compliance policy in intune as well, but we find that it's very slow to update if something changes.

    Ahh that's very fair, InTune can indeed be slow to do things - one of the things that annoys me about it!

    1 Reply Last reply
    0

© Copyright 2023, SysAdmins Zone.
Terms of Service | Privacy Policy
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Recent
  • Popular
  • Unsolved
  • Categories
  • Tags
  • Chat
  • Login

  • Don't have an account? Register

  • Login or register to search.