?
Solved

Advice for Mobile/Cloud Active Directory Services for offsite sales rep computers

Posted on 2014-01-04
3
Medium Priority
?
453 Views
Last Modified: 2014-11-12
I have a situation where I have a customer that has about 30+ offsite employees that are sales rep all over the US.  Currently each laptop is just setup as a workgroup computer with no management.

With no Active Directory or Group Policy they are becoming prohibitive to manage.

I have looked around and see options for Windows Azure, Windows Intune, etc.  

I'm trying to figure out what the best option will be.  What I would like is to have the computers on the domain to be able to utilize group policies, password enforcement, etc.  

Just not sure if there is any way other than using a VPN that would make this work well.

Thanks.
0
Comment
Question by:truth_talker
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 39756935
What does the rest of their environment look like?  

Without knowing that some things I was thinking about was Office 365.  You could also look at Direct Access?

Having said that where I was (starting new job Monday) we were using a traditional VPN  that you talked about.  We have discussed some other methods but we were not there yet.

Thanks

Mike
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 39757052
Do you have existing active directory in place ?

You could ask those users to come in office at least once and then join them to domain
This will set their machine in domain and also enforce password restriction on their machine and also some kind of GPOs also you can set (one time GPOs) such as if you set screen saver and wallpaper on their machine pointing to local path.
In order to above works, you must copy those screen saver and wallpaper files on those machine when they are in network
Those users can logon offline with cached credentials, I think limit is 25 for Win7, you may increase that.
As suggested by Mike, MS direct access is also good option if your company Policy allows that.

Also you may deploy some kind of network access protection (NAP) \ NAC solution in your network so that prior to connect those machines to network through VPN they must prove their eligibility such as updated AV definitions, windows updates etc.
Microsoft provides NAP functionality with VPN OR you can check 3rd party VPN NAP vendors to do that

Mahesh
0
 

Author Comment

by:truth_talker
ID: 39757833
I guess I was hoping for something simple, but I don't think think it is going to be.

My problem with the VPN is training end users and also the VPN wouldn't be enabled on startup so synchronizing group policies may be difficult.  Also if a computer is out in the field and then handed to a new employee.  The new employee wouldn't be able to sign in until they came to the office.

The issue is some computers are so far away, this isn't possible.  The laptop  literally may never come into the office except for the initial setup.

Intune might be the way I have to go, Direct Access looks like it may be too much setup.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft has changed the look and feel of Azure AD and Microsoft account sign-in pages so that you will have a more unified look and feel when moving between the two interfaces.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question