Endpoint management

Intune and endpoint management

Set up and run devices, apps and policies in Microsoft Intune the tidy way.

  • Rollout or migration to Intune, including co-management with Configuration Manager
  • Windows Autopilot, configuration profiles, compliance policies and Conditional Access
  • Win32 apps with PSAppDeployToolkit, update rings and day-to-day maintenance

Intune is quick to switch on and slow to tidy up. The environments we see rarely have too few policies; they have too many that nobody can attribute any more. That is why our work starts with an inventory: which device classes exist, which security and compliance requirements are real, and which legacy from Group Policy or Configuration Manager has to come along.

Rollout and migration

We build Intune tenants from scratch or move existing management over step by step. For organisations running Configuration Manager we set up co-management and shift workloads at a pace operations can absorb. We analyse Group Policy with the aim of replacing it with settings catalogue profiles, security baselines and compliance policies, not copying it one to one.

  • Device provisioning with Windows Autopilot, including the enrollment status page and device preparation for rollouts
  • Configuration profiles from the settings catalogue, security baselines for Windows, Edge and Defender
  • Compliance policies as the basis for Conditional Access in Microsoft Entra ID
  • An assignment concept with device filters and groups that is still understandable after the tenth profile

App deployment

Applications are the part of endpoint management that consumes the most time. We package Win32 applications with the PSAppDeployToolkit, define detection rules, dependencies and supersedence, and document install and uninstall commands so that a colleague can still follow them a year later. For applications from the WinGet catalogue we use our own product, AppCloud365.

  • Win32 apps, Microsoft 365 Apps, Store apps and line-of-business packages
  • Detection rules, return codes, restart behaviour and assignment strategies
  • Available and required installations through the Company Portal

Operations and updates

After the rollout, reliability is what counts: update rings and feature update policies for Windows, driver and firmware updates, reports on compliance and deployment status, and a change procedure for policies that surfaces side effects before they happen. On request we take over ongoing operations or support your team with regular reviews.

How we work

We document every setting with its purpose and reasoning, test changes in pilot groups and hand over a configuration your team can carry on with. If we think something is not a good idea, we say so before it is implemented.

Talk to us about this

Tell us what it is about. A person will reply.

German office (sales and engineering)

Berlin, Germany