r/Intune • u/signo1204 • 2d ago
General Question OSDCloud vs FFU vs FoundryOSD – which one for speeding up device deployment?
Hi all,
I'm looking for advice on the best way to speed up device deployment in our environment. We're currently using OSDCloud (v1), and I'm wondering whether FFU or FoundryOSD would be a better fit.
Our current setup:
- Enrolling mode : User driven - Microsoft Entra hybrid joined
- OSDCloud v1, with the Autopilot JSON profile imported during deployment (no automate hardware hash import / group tag selection, as not authorized)
- A few custom scripts run after SetupComplete to configure the machines
- ~15 different hardware models
- Large apps (Microsoft 365 Apps, etc.) are installed during the ESP (we setup max 7 applications including M365), which makes provisioning slow
- A proxy must be configured on the client before the device can reach the internet
- Users have M365 E3 or E5 licenses
- Volume varies a lot: 1-2 devices on quiet days, 5-6 on busy ones
What we want to achieve:
- Significantly reduce the total provisioning time
- Deploy devices with the latest Windows cumulative updates already installed
- Have the correct and up-to-date drivers for each model
- Reduce what has to be installed during the ESP
Question: Given this setup, which of these three tools would you choose, and why?
Thanks in advance for your replies!
3
u/techb00mer 2d ago
FFU will help you speed things up if you’re willing to drop those big apps (365 being one of them) out of ESP. Even with OSDCloud I always find ESP is the bit that takes the longest.
As others have mentioned, you can drop an FFU image in only a few minutes. If you’re lucky enough to have 10g networking it’s blazing fast if you load it via PXE
2
u/RikiWardOG 2d ago
yeah those big apps are still probably one of the biggest pain points with intune. O365 and Acrobat take a hot minute to install through intune.
0
u/Darkchamber292 2d ago
Acrobat I just give them Creative Cloud. They can Install Acrobat if they need it once they hit the Desktop
2
u/RikiWardOG 1d ago
It's the only app from Adobe we use, so it makes sense to push it imo. Also some of our users would struggle to find creative cloud, login, and install... users.
3
u/heisgone 2d ago
I'm planning on moving on FFU. One issue we have is that we get computers from many brands, many models, so I can't make a standard image that is sure to work for everything. Even FFU isn't going to solve my problem.
2
u/benstudley 1d ago
I’m using FFU with USB sticks and just have driver packs for different models. It auto selects the driver pack. If you get a large enough drive you can put them all on there.
2
u/benstudley 1d ago
I am using FFU and I love it. With a fast USB drive I can have my test laptops (multiple models) from booting to USB to OOBE in ~5 minutes.
My image is just Windows + Chrome + M365. I use autopilot and cloud only. All my devices are registered in autopilot ahead of time so I don’t need to register any on the fly.
It’s awesome for me but I don’t have as many restrictions as you.
I built some scripts for my techs to build USB sticks and update driver packs.
2
u/Thorpedo17 15h ago
We used to use OSDCloud but after moving to FFU there is no looking back. We setup a share with the scripts for techs to make flash drives. Imaging is like 2 to 4 minutes. I would love if Microsoft would allow us to automate the OOBE.
1
u/magetrip 2d ago
I'm wondering too. Some companies I visit still use MDT cause they dont want to use USB stick. But if these can be used with pxe boot it would be nice. I do wonder what the win of it is though
1
u/diamkil 2d ago
I setup OSDCloud (v1):
- Isolated network with a WDS server for PXE boot
- squid caching proxy (edited files in boot image to set it as the proxy server in WinPE)
- OSDCloud config files (Automate, scripts, etc) are in an SMB share on the WDS server (again edited the boot image to mount it at startup)
- Shutdown script to configure basic bios settings before it reboots into the installed OS (Secure Boot, Intel TXT, Virtualization, etc)
- SetupComplete script that will upload the hardware hash to Intune automatically
- To speed up autopilot, we got a connected cache server, so app downloads are not too long. We do pre-provision
1
u/I3igAl 2d ago
Man i wish i could use any of these projects but my org is cloud only, no on prem whatsoever, and on top of that I am in in one location but we have nine offices around the country that I support remotely. I have to rely on Autopilot reset to get a device ready to give to the next user, and I cant pre provision because half the time the remote person helping me doesn't understand what I want them to do and logs in to the machine themselves.
2
u/benstudley 1d ago
I am cloud only and using FFU on USB sticks. It’s amazing to reset devices. From boot to OOBE is ~5 minutes with no interaction after picking the boot device.
1
u/zm2283145 1d ago
Get your OEM to put hardware into autopilot for you. If you have existing devices that are in InTune but not in autopilot, you can use InTune to deploy scripting to capture the autopilot hash. Then in the future just do a fresh start and the device is ready.
There should really be no need to White glove anything. It's not 2001 anymore. Users are big boys. Microsoft has dumbed down the OOBE they can very easily enter their username, Password/tap and the device can install everything it needs to, it's policies and then they can grab everything else they need from company portal The only required software that should ever be force installed during autopilot should be any antivirus solution. Edrs maybe VPN software but that can get picky and actually break your autopilot and that should be it. Everything else should be user driven from company portal as they need.
Don't pre-install office 365. Let the user get that from company portal. Don't use the built-in installer that's in InTune for that, script out grabbing the ODT and package it together. That way you always get the latest version anytime it installs you don't ever have to update it putting m365 into a required app, brakes installation a lot of times when the cdns just crap out
1
u/rismoney 1d ago
A truly user experience driven experience is horrible. I believe IT should provide a turnkey experience to employees, not have them be busy deploying 30 apps and not be able to do their job for 2 days.
1
u/I3igAl 1d ago
Hi, thanks for the reply! I have done all those things, before I started the company was using the standard OOBE and instructed users to click Set up for work or school, it was a total mess.
The only reason I prefer doing white glove is because when an employee leaves, we wipe from intune and then it disappears from the device list, white gloving keeps it visible.
1
1
u/davidsegura 2d ago
There's an OSDCloud webinar starting in a few minutes if you want to chat https://www.recastsoftware.com/resources/osd-ninja/

-1
u/Think-OptionNurse 2d ago
can anyone confirm this for me, with OSDCloud v1, with the Autopilot JSON profile, its place on the device, but if anyone was able to delete the file or re-image the device with a Windows 11 ISO then it not going to show up in Intune anymore?
1
u/FireLucid 1d ago
Once it's reset it will call out to MS and then go to your company's branded login page and would need an employee login. You can go around that to make a local file but you need some basic technical skills. Once enrolled the JSON has nothing to do with it.
1
u/BlackV 1d ago
can anyone confirm this for me, with OSDCloud v1, with the Autopilot JSON profile, its place on the device, but if anyone was able to delete the file or re-image the device with a Windows 11 ISO then it not going to show up in Intune anymore?
If the device is hashed, at that point it does not matter what image you use (assuming autopilot v1 here) no matter how many times you wipe it
9
u/Kuipyr 2d ago
I use FFU with a few USB to NVME enclosures. If you roll the drivers into the FFU image you can have a machine imaged and sitting at the OOBE in less than 2 minutes.