BigFix, now supported by HCL Technologies since the acquisition of BigFix from IBM in 2018, is an endpoint management solution providing endpoint visibility and IT asset discovery, automated endpoint patching (BigFix Lifecycle and BigFix Patch) policy enforcement (BigFix Compliance), and software asset discovery for licensed and unlicensed software (BigFix Inventory).
N/A
Microsoft Intune
Score 8.4 out of 10
N/A
Microsoft Intune (formerly Microsoft Endpoint Manager), combining the capabilities of the former Microsoft System Center Configuration Manager, SCCM or ConfigMgr, is presented as a unified endpoint management option. Microsoft Intune is an endpoint management solution for mobile devices, an MDM solution that allows the user to securely manage iOS, Android, Windows, and macOS devices with a single endpoint management solution. The component Endpoint Configuration Manager (the…
BigFix is well suited for patch review and deployment, but there are key features that can definitely be improved. An example is that if a specific patch is deployed, but a cumulative update that contains that patch is not deployed, the system still shows the patch as outstanding or not implemented. Another area for improvement is the customization of BigFix. The tool has many uses and can be extremely helpful, but the amount of knowledge required to customize the solution is significant and customized scripts or "fixlets" need to be created. If common things could be pre-packaged and provided to the customer community, it would allow for an easier deployment and use of the tool.
Windows Autopilot makes provisioning user Windows PC laptops a breeze. A user only needs to turn on the laptop, join it to their local WiFi, login with their O365 account then sit back and let Windows Autopilot handle the app installations required for work, configure the laptop settings to meet my organization requirements. I have seen this all completed in less than 30 minutes depending on how fast the internet connection is. Where Microsoft Intune needs to improve I think is the part where it can push out software updates to 3rd party apps. Right now I have to use Automox to fill in this gap.
[Microsoft Endpoint Manager (Microsoft Intune + SCCM)] helps to speed up the deployment of patches/software throughout our environment. I can easily build a package and then deploy across all endpoints.
The ability to supercede software is also quite handy. This automates the removal of old versions and replacing them with newer versions.
The Intune Autopilot option is very useful if you want to deploy software to devices straight out of the box. You can configure them to download software when a user opens a new PC and turns it on for the first time.
Installation is very laborious and complicated. The number of things to manually configure during the installation is incredible.
OS deployment is hard to configure and troubleshoot. The Microsoft article on deploying Windows 10 via System Center Configuration Manager in a test environment takes 44 minutes to read (Microsoft's estimate, not mine -- check here: https://docs.microsoft.com/en-us/windows/deployment/windows-10-poc-sc-config-mgr). If something goes wrong, there are multiple log locations to check on both the server and client, making troubleshooting difficult.
The management console looks old, and its performance isn't great. It is often hard to find settings in the console, and it refreshes slowly. The old name for System Center Configuration Manager, SMS, comes to mind often. "Slowly Moving Software."
Mascom Wireless is a Microsoft shop and SCCM has proved to be helpful in keeping our Microsoft products up to date every month without fail. We also have a Microsoft Enterprise Agreement which we renewed for three years ending 2022. The remote access utility works wonders for the organisation and have saved travel bills including subsistance allowance. We have been able to fulfill security audits both internal and external. We have been able to keep a robust inventory of our computer assets and nothing falls of the cracks
Overall, Microsoft Intune is very usable. While help documentation can be lacking, once setup and configured, Intune does all the work that used to be manual. There is a lot of automation and advanced features and manufacturer integrations you don't get anywhere else. These are absolutely game changers when managing IT workloads.
It's a 'heavy' system, which demands a lot of resources form the datacenter perspective. So, make sure you followed the requirements to avoid frustration in the future. From the 'client' perspective, it's fine. I've never had any issue with that.
While some support calls are quickly responded to, many times our engineers have been pointed to collaborative web sites such as Bigfix.me for solutions or the option of engaging professional services has been proposed. While this may seem like a good way to drive business, it is not seen as efficient a support process as could be provided to the customer base.
Being a Microsoft product, support was good. Out interaction was limited to our in-house IT team which was installing the Intune app in our mobile device. The installation was smooth and we haven't faced any difficulties with the app while using it. Provides a smooth and secure access to all Office 365 apps in mobile while separating the personal and professional data.
Work with a "test group" of users who you have a good relationship with so that when things don't work properly they understand! Work with your partner nicely without forcing things especially timelines as you are bound to make mistakes and create oversights in the project Management can also interfere with the implementation (which can cause delays) if you make too many mistakes which takes me back to having a "test group" where you have good relations
We have significantly enhanced our ability to patch desktops, including laptops, desktop, cloud, virtual machines and other mobile devices used by end-users. BigFix's endpoint management functionality allows us to seamlessly patch a wide range of operating systems, such as Windows, MacOS, ChromeOS, and Linux systems, ensuring comprehensive patch management across IT infrastructures. We have established a track record of delivering secure and hassle-free patching solutions to our clients
Microsoft Intune is more robust as far as fine-tuning security controls. It also allows for software installs, folder access controls, updating PCs, and other features simply not found in previous products we have used. Because it is rolled into MS 365 it's very cost effective. It's also a single pane of glass for managing user PCs and personal devices
The positive impact it's had was it has been really beneficial in having an all-in-one Systems Management solution to be able to manage all endpoints across the organization. This has saved both time and costs from having to search/setup/manage other System Management applications and also have saved money from having to purchase a license for other commercial products.
Another positive impact it has had was in being able to easily remote into computers/endpoints, and also being able to provide remote assistance to end-users.
The negative impact has been it is not being fully utilized by most of the IT staff, as it is a more complicated platform to learn/master. This would require funding for IT staff to take training in learning the product, or require time to consult the documentation in the use of the product. As a result, this may hurt productivity in being able to have to work on other things.