Locking down devices can be a difficult task. Even when we take administrator permissions away, our users still find ways to defeat our best intentions. When we restrict things too much, we run the risk of making the device unusable. One way we could prevent configuration drift is by reverting the device to a known-good state at every reboot. There are many solutions that take this approach, but often times they fall short with ConfigMgr managed devices. When combining ConfigMgr with state reset software, administrators need to take extra precautions to ensure their devices are patched, have the latest malware definitions, and maintain healthy ConfigMgr clients. Often ConfigMgr administrators are forced to schedule unlock intervals to allow their workstations to receive these updates.
Continue reading “StateLocker: Configuring the Unified Write Filter from within ConfigMgr”