A specialty contractor supported office teams, estimators, and project staff across eleven locations. Laptop setup depended on a technician, a local image, and a working path back to the domain. Policies varied by device age, encryption reporting was incomplete, and remote replacements routinely turned into overnight shipping plus a long support call.
- ~280Windows devices in scope
- 11Offices and field locations
- 4Deployment and update rings
- 12 weeksBaseline through handoff
What success meant here: a standard laptop could ship directly to an employee, configure itself through Windows Autopilot, report its security state in Intune, and receive policy without depending on the corporate network.
The situation
The company’s hybrid Active Directory design had been reasonable when most employees worked from an office. Growth changed the operating model. Devices spent less time on the LAN, new offices inherited different practices, and Group Policy applied inconsistently over VPN.
Leadership wanted a modern endpoint baseline, but a mass reimage would have disrupted active projects. The path needed to improve new and replacement devices immediately while moving the installed base in controlled waves.
Baseline findings
- Standard device builds required roughly two hours of hands-on technician time
- BitLocker was enabled unevenly and recovery-key escrow was not consistent
- Windows update behavior differed across locations and device generations
- Local administrator access had accumulated without a recurring review
- Several business applications lacked documented silent-install behavior
- Conditional Access could not rely on a complete, trustworthy compliance signal
How we worked
Established the identity and enrollment path
New and reprovisioned standard laptops moved to Entra join with Windows Autopilot. Existing devices followed a documented enrollment path based on age, role, and replacement timing. Hybrid dependencies were identified before any policy assumed a cloud-only device.
Built a minimum viable baseline first
The first baseline covered encryption, Defender, firewall, local password management, update rings, device restrictions, and compliance. Policies were split by purpose so the team could identify conflicts and roll back a specific control without removing the whole baseline.
Packaged the applications that mattered on day one
Microsoft 365 Apps, security tooling, remote support, PDF software, and core line-of-business applications were packaged and tested. Optional software moved to Company Portal, reducing the number of applications that delayed first sign-in.
Used rings instead of a company-wide switch
IT devices came first, followed by a cross-section of office and field users. Deployment and update rings widened only after enrollment, application, and support data looked stable. Conditional Access began in report-only mode before requiring compliant devices for selected applications.
Made support part of the design
The internal team received enrollment decision trees, Autopilot reset guidance, application troubleshooting steps, exception handling, and a dashboard for devices that stopped checking in. Ownership was assigned for every production policy and application package.
Rollout sequence
| Ring | Population | Validation focus |
|---|---|---|
| 0 · Lab | Test hardware and virtual devices | Enrollment, policy conflicts, and reset paths |
| 1 · IT | Technology team devices | Administration, support, and application packaging |
| 2 · Pilot | Office and field representatives | Real networks, job roles, and peripherals |
| 3 · Broad | New, replacement, then eligible existing devices | Compliance, helpdesk volume, and exceptions |
| Operate | All enrolled endpoints | Update health, stale devices, and policy drift |
Results
- Standard laptops could ship directly from the supplier and enroll through Windows Autopilot
- Hands-on IT setup for the standard build fell from roughly two hours to under 30 minutes
- More than 95% of enrolled Windows devices reported compliant at handoff, with documented exceptions for the remainder
- BitLocker recovery keys, Defender state, update health, and device ownership became visible in one management plane
- Baseline policy no longer depended on a device reaching the corporate network or VPN
- The company gained a phased path away from legacy device practices instead of a disruptive one-weekend rebuild
What this engagement was not
It was not a forced cloud-only redesign of every workstation. Specialty devices and application dependencies stayed on the path that fit them. The project standardized the broad Windows fleet first, documented exceptions, and gave the company a practical transition model for the rest.
Ready to make endpoint setup repeatable?
We can assess your identity, applications, policies, and device estate, then build an Intune rollout that respects how your teams actually work.
Plan an Intune rollout