Skip to content
15 years of IT experience
CybexsoftConsultancy Services
← Back to case studies

Microsoft Intune — BYOD Endpoint Management

Production Intune tenant for Windows and macOS BYOD in one week

A client needed Microsoft Intune configured end to end so personal Windows and macOS devices could enroll without exposing corporate data. We delivered enrollment profiles, compliance and security baselines, Conditional Access tied to device health, and App Protection policies that keep company data inside managed containers — production-ready in one week, followed by three months of support for new device onboarding and policy changes.

Platforms
Windows + macOS BYOD
Engagement
1-week build
Support
3 months post-delivery
Focus
Intune, Entra ID, Conditional Access

The situation

What was wrong

The client had no mobile device management layer at all — staff were signing in to company mail and SaaS apps from personal Windows laptops and Macs with nothing verifying disk encryption, patch level, or screen lock. Because the model was BYOD rather than corporate-owned, the usual answer of full device wipe and total device control was off the table: the tenant had to enforce a security posture on machines the company does not own, without reaching into personal data. Both platforms had to be covered, and the client's own team had to be able to run the tenant afterwards.

  • No enrollment path for either platform — devices reached company resources with zero health verification.
  • BYOD constraints ruled out full-device control, so protection had to be scoped to corporate apps and data only.
  • Sign-in was authenticated but not device-aware: a compliant identity on a compromised laptop still got in.
  • The in-house team had no Intune experience and needed to own the tenant once the engagement ended.
Engagement focus
Microsoft IntuneEntra IDConditional AccessBYODEndpoint Security
Outcome

Windows and macOS BYOD enrollment live in one week, with every corporate app behind a device-health check.

How we worked

The approach, step by step

Stabilise delivery early, then build the foundation that keeps it stable once we hand it back.

    1

    Tenant and enrollment setup

    Configured the Intune tenant with client branding, then built both enrollment paths: Windows Autopilot with a user-driven Entra ID join profile and Enrollment Status Page, and macOS enrollment through Company Portal with an automated device-enrollment profile. Enrollment restrictions were scoped by platform and device type so only intended hardware could join.

    2

    Compliance and security baselines

    Authored compliance policies per platform covering password complexity and lock timeout, BitLocker on Windows and FileVault on macOS, minimum OS version, and an update cadence with defined deferral and deadline windows. Applied the Microsoft security baselines, then tuned each deviating setting against the client's environment rather than accepting defaults that would have broken working software.

    3

    Conditional Access gating

    Built Conditional Access policies in Entra ID that require a compliant, managed device for access to Microsoft 365 and the connected SaaS apps, with MFA on every sign-in and legacy authentication blocked outright. Every policy was staged in report-only mode against a pilot group, reviewed in the sign-in logs, then promoted — with a break-glass account excluded from all of them.

    4

    App Protection for personal devices

    Deployed App Protection policies so corporate data stays inside managed apps: cut-copy-paste restricted to the managed container, save-as to personal storage blocked, app PIN and encryption enforced at rest, and selective wipe available to remove company data without touching anything personal on the device.

    5

    Documentation and hand-over

    Documented every profile, policy, and assignment — what it does, who it targets, and why each value was chosen — alongside enrollment walkthroughs for end users and a troubleshooting runbook. Closed with a live hand-over session covering policy changes, assignment scoping, and reading compliance reports, then stayed on for three months onboarding new devices and making changes as the estate grew.

Handover

What we delivered

  • Windows Autopilot deployment profile with Entra ID join and Enrollment Status Page
  • macOS Company Portal and automated device-enrollment profiles
  • Per-platform compliance policies: password, BitLocker/FileVault, minimum OS, update cadence
  • Tuned Windows and macOS security baselines with every deviation documented
  • Conditional Access policy set requiring device compliance and MFA, with break-glass exclusions
  • App Protection policies enforcing managed containers, app PIN, and selective wipe
  • Configuration document covering every profile, policy, and assignment
  • End-user enrollment guides, admin troubleshooting runbook, and recorded hand-over session

Stack

What it runs on

Microsoft IntuneMicrosoft Entra IDConditional AccessWindows AutopilotCompany PortalEndpoint Security BaselinesApp Protection PoliciesBitLockerFileVaultMicrosoft 365

Afterwards

What changed

Measured after handover, once the client's own team was running the system without us.

1 wk
Tenant to production-ready
3 mo
Post-delivery support
2
Platforms under BYOD management

Planning something like this?

Tell us what you are trying to move, migrate or automate and we will reply within one business day with an honest read on the work — including the parts we think you should not do.

More engagements