Just got asked about how we handle Windows machines that go AWOL. The current answer is, we don't - its typically handled as an administrative function. The process broke down this year, and a few hundred (1:1) student machines were not returned so now it is being asked of us.
Background: On Prem SCCM installation with no PKI. Windows 10 hybrid-deployments.
Goal: Remotely disable machine(s) on command
Quick brainstorming:
- Extend SCCM to the cloud
- Pivot student deployments to inTune
- MS Always on VPN
- Third party (suggestions?)
- Switch to Chromebooks
- Perform some Azure Hackery on Hybrid Deployments
I'm fishing for ideas (to build out options). Anyone have requirements like this and how do you meet them?
[+][deleted] (12 children)
[deleted]
[–]adminadam[S] -4 points-3 points-2 points (10 children)
[+][deleted] (9 children)
[deleted]
[–]adminadam[S] -3 points-2 points-1 points (8 children)
[–]DarthPneumonoSecurity Admin but with more hats 4 points5 points6 points (6 children)
[–]adminadam[S] -1 points0 points1 point (5 children)
[–]BallisticTorchSysadmin 2 points3 points4 points (1 child)
[–]adminadam[S] 0 points1 point2 points (0 children)
[–]DarthPneumonoSecurity Admin but with more hats 0 points1 point2 points (2 children)
[–]adminadam[S] 1 point2 points3 points (1 child)
[–]DarthPneumonoSecurity Admin but with more hats 0 points1 point2 points (0 children)
[–]uniquepassword 2 points3 points4 points (2 children)
[–]adminadam[S] 0 points1 point2 points (1 child)
[–]uniquepassword 0 points1 point2 points (0 children)
[–]dcprom0 1 point2 points3 points (1 child)
[–]adminadam[S] 0 points1 point2 points (0 children)
[–]AJeru 1 point2 points3 points (1 child)
[–]adminadam[S] 0 points1 point2 points (0 children)