← All writing
2 min read

Modernising endpoint management for a hybrid workforce

IntuneEndpoint SecurityZero TrustMicrosoft 365

A representative engagement — generalised and anonymised across similar endpoint-modernisation work. It describes my approach rather than a specific named client.

When a team goes hybrid, the old way of managing laptops quietly falls apart. Devices that used to sit on a domain in an office are now scattered across home networks, built by hand, patched whenever someone remembers, and trusted purely because they once had the right image on them. That's the setup I'm usually asked to modernise.

The starting point

The symptoms are consistent: no central visibility of what's out there, no enforced disk encryption, inconsistent patching, and access granted to any device that has a valid password — managed or not. It works until a laptop is lost or an unpatched machine gets hit, and then it very much doesn't.

The approach

The goal is a fleet that's managed, measured, and only trusted when it proves it's healthy:

  • Windows Autopilot so a new laptop configures itself from first boot — no imaging, no manual build, shipped straight to the user.
  • Intune policies to standardise configuration, enforce BitLocker encryption, and keep patching on a predictable cadence.
  • Defender for Endpoint for EDR — actual detection and response on the device, not just antivirus.
  • Compliance-gated Conditional Access — the pivot to Zero Trust. A device only reaches corporate data if Intune reports it as encrypted, patched, and healthy.

Rolling it out without the pain

The technical design is rarely what makes these projects fail — the rollout is. So it goes out in rings: a pilot group first, report-only compliance to find what would break before it breaks, then a phased expansion with clear comms so nobody's blindsided. Existing devices are enrolled and brought into compliance rather than wiped, which avoids the dreaded re-image weekend.

The result

The outcome that matters isn't a dashboard — it's that a lost laptop becomes a non-event. It's encrypted, it can be wiped remotely, and it couldn't reach company data unless it was healthy in the first place.

Endpoint modernisation isn't really a device project. It's the moment you stop trusting things because they're familiar and start trusting them because they're verified.

If your team went remote faster than your device management caught up, this is usually the highest-value gap to close.


Have a similar challenge?

I help businesses secure and run their IT. Let's talk.

Start a conversation →