Link to home
Start Free TrialLog in
Avatar of truth_talker
truth_talker

asked on

Advice for Mobile/Cloud Active Directory Services for offsite sales rep computers

I have a situation where I have a customer that has about 30+ offsite employees that are sales rep all over the US.  Currently each laptop is just setup as a workgroup computer with no management.

With no Active Directory or Group Policy they are becoming prohibitive to manage.

I have looked around and see options for Windows Azure, Windows Intune, etc.  

I'm trying to figure out what the best option will be.  What I would like is to have the computers on the domain to be able to utilize group policies, password enforcement, etc.  

Just not sure if there is any way other than using a VPN that would make this work well.

Thanks.
ASKER CERTIFIED SOLUTION
Avatar of Mike Kline
Mike Kline
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Do you have existing active directory in place ?

You could ask those users to come in office at least once and then join them to domain
This will set their machine in domain and also enforce password restriction on their machine and also some kind of GPOs also you can set (one time GPOs) such as if you set screen saver and wallpaper on their machine pointing to local path.
In order to above works, you must copy those screen saver and wallpaper files on those machine when they are in network
Those users can logon offline with cached credentials, I think limit is 25 for Win7, you may increase that.
As suggested by Mike, MS direct access is also good option if your company Policy allows that.

Also you may deploy some kind of network access protection (NAP) \ NAC solution in your network so that prior to connect those machines to network through VPN they must prove their eligibility such as updated AV definitions, windows updates etc.
Microsoft provides NAP functionality with VPN OR you can check 3rd party VPN NAP vendors to do that

Mahesh
Avatar of truth_talker
truth_talker

ASKER

I guess I was hoping for something simple, but I don't think think it is going to be.

My problem with the VPN is training end users and also the VPN wouldn't be enabled on startup so synchronizing group policies may be difficult.  Also if a computer is out in the field and then handed to a new employee.  The new employee wouldn't be able to sign in until they came to the office.

The issue is some computers are so far away, this isn't possible.  The laptop  literally may never come into the office except for the initial setup.

Intune might be the way I have to go, Direct Access looks like it may be too much setup.