Microsoft 365

Devices you actually control

Enrolment, encryption, updates and application deployment through Intune, and new machines that configure themselves through Autopilot instead of being built by hand.

Device management is the difference between owning a laptop and controlling it. Enrolled devices can be checked, configured, updated and, when one goes missing, locked or wiped. Unenrolled devices are trusted on the strength of whoever set them up.

The question worth asking is not whether you want managed devices. It is what you would do tonight if a laptop with a signed in mailbox and a synced OneDrive folder did not come home.

,

What gets set up

  • Enrolment. Devices joined to the tenant so they are visible, with a policy that applies rather than a spreadsheet that lists them.
  • Disk encryption. BitLocker on Windows, with the recovery keys held by the business rather than by whoever built the machine.
  • Configuration and compliance policy. What a device must have to be considered healthy, and what happens when it is not.
  • Update rings. Updates that install on a schedule the business chose, rather than whenever somebody clicks "remind me later" for the eleventh time.
  • Application deployment. The applications people need arriving on the device instead of being installed by hand and forgotten on the next machine.
  • Autopilot enrolment. A new laptop that arrives at the person and configures itself when they sign in.
  • Mobile application protection. Company mail and files contained on personal phones, removable without touching anything personal.
  • Retirement and wipe. A defined way to remove company data from a device, which is the step people find they need at the worst possible moment.
,

Where this usually starts

Almost nobody arrives asking for Intune. They arrive with one of these.

A laptop went missing

And the honest answer to "can we wipe it" turned out to be no. This is the most common trigger and the most expensive lesson.

An insurance questionnaire

Asking whether devices are managed and encrypted. The technical controls behind those questions are covered on the controls insurers ask about.

Somebody left with a company laptop

And it is still syncing. That is the device half of former employee access.

New starters take half a day each

Because every machine is built by hand, slightly differently, and the differences turn into support calls for the next two years.

,

How the work runs

  1. Find out what exists

    How many devices, who owns them, what is already enrolled, and which are personal.

  2. Agree what should be enforced

    This is a business decision, not a technical one. Policy that fights how people work gets worked around.

  3. Pilot on a few machines

    Including at least one belonging to somebody who will tell you honestly if it is annoying.

  4. Roll out in waves

    Not everybody on the same afternoon.

  5. Document it and hand it over

    Including where the encryption recovery keys live, which is the detail people wish they had written down.

,

Who this is for

  • Company laptops that were handed out but never managed.
  • A business that has to answer questions about encryption or device control.
  • New starters where setting up a machine is a half day job.
  • Company mail on personal phones with no way to remove it.

When this is not the right fit

  • A business with two laptops and no plans to grow. The overhead may exceed the benefit and we will say so.
  • Anyone wanting to monitor what staff do on their personal phones. That is not what this is and we would not set it up.
  • Environments that need a full desktop management platform beyond Microsoft 365.
,
,

What Tech True Point can help with

Usually part of a bigger piece:

  • The device half of a tenant review, where enrolment status is one of the twelve areas.
  • Joiner and leaver handling, so a device is issued and recovered as part of a process.
  • Identity work, because device policy and Conditional Access are more useful together.
,

Common questions

Do we need Intune if everyone already has a work laptop?

Handing somebody a laptop is not the same as managing it. Without enrolment you cannot confirm the disk is encrypted, cannot push an update, and cannot do anything at all if it is left in a taxi.

Whether that matters depends on what is on the laptop. For a business handling customer records or payment details, it usually matters more than the owner expects.

What does Autopilot actually change?

A new laptop arrives at the person, not at you. They sign in with their work account and the device configures itself: policies, applications, encryption, printers.

The alternative is somebody spending half a day setting it up by hand, differently each time, which is where the inconsistencies that cause support calls come from.

Can you manage personal phones without taking them over?

Yes, and this is usually the right answer. Company data on a personal phone can be contained so that work mail and files are protected and can be removed, without the business touching photos, messages or apps.

People are far more willing to accept that arrangement when it is explained properly, so it is worth explaining rather than announcing.

We have a mix of Windows and Mac. Does that work?

Both can be enrolled and managed. What differs is which controls are available on each, and that gap is worth knowing about before you promise a uniform policy to an auditor or an insurer.

We would rather tell you where the differences are than pretend the two are identical.

,
Get a Quote

Work out what is worth managing

Tell us how many laptops and phones there are and who owns them. Not everything needs enrolling, and we will say which parts do not.

Call now Request a quote