Microsoft Intune — BYOD Endpoint Management
A client needed Microsoft Intune configured end to end so personal Windows and macOS devices could enroll without exposing corporate data. We delivered enrollment profiles, compliance and security baselines, Conditional Access tied to device health, and App Protection policies that keep company data inside managed containers — production-ready in one week, followed by three months of support for new device onboarding and policy changes.
The situation
The client had no mobile device management layer at all — staff were signing in to company mail and SaaS apps from personal Windows laptops and Macs with nothing verifying disk encryption, patch level, or screen lock. Because the model was BYOD rather than corporate-owned, the usual answer of full device wipe and total device control was off the table: the tenant had to enforce a security posture on machines the company does not own, without reaching into personal data. Both platforms had to be covered, and the client's own team had to be able to run the tenant afterwards.
Windows and macOS BYOD enrollment live in one week, with every corporate app behind a device-health check.
How we worked
Stabilise delivery early, then build the foundation that keeps it stable once we hand it back.
Configured the Intune tenant with client branding, then built both enrollment paths: Windows Autopilot with a user-driven Entra ID join profile and Enrollment Status Page, and macOS enrollment through Company Portal with an automated device-enrollment profile. Enrollment restrictions were scoped by platform and device type so only intended hardware could join.
Authored compliance policies per platform covering password complexity and lock timeout, BitLocker on Windows and FileVault on macOS, minimum OS version, and an update cadence with defined deferral and deadline windows. Applied the Microsoft security baselines, then tuned each deviating setting against the client's environment rather than accepting defaults that would have broken working software.
Built Conditional Access policies in Entra ID that require a compliant, managed device for access to Microsoft 365 and the connected SaaS apps, with MFA on every sign-in and legacy authentication blocked outright. Every policy was staged in report-only mode against a pilot group, reviewed in the sign-in logs, then promoted — with a break-glass account excluded from all of them.
Deployed App Protection policies so corporate data stays inside managed apps: cut-copy-paste restricted to the managed container, save-as to personal storage blocked, app PIN and encryption enforced at rest, and selective wipe available to remove company data without touching anything personal on the device.
Documented every profile, policy, and assignment — what it does, who it targets, and why each value was chosen — alongside enrollment walkthroughs for end users and a troubleshooting runbook. Closed with a live hand-over session covering policy changes, assignment scoping, and reading compliance reports, then stayed on for three months onboarding new devices and making changes as the estate grew.
Handover
Stack
Afterwards
Measured after handover, once the client's own team was running the system without us.
Tell us what you are trying to move, migrate or automate and we will reply within one business day with an honest read on the work — including the parts we think you should not do.
More engagements
The platform runs on AWS under a managed support agreement, with {{TODO: headline outcome — e.g. defined RPO/RTO and a monthly patch cycle}}.
Read the case study Series B B2B SaaSRelease lead time reduced by ~50% with fewer failed deploys.
Read the case study