Scope & packages
Three packages by tenant size and complexity. You receive a binding fixed-price quote for your scope.
- Intune MDM enrollment (corporate & BYOD)
- Microsoft Defender baseline protection
- Enforced disk encryption (BitLocker)
- Automatic Windows patching (base ring)
- Everything in Essentials
- Complete Intune device configuration & compliance
- Packaging of 5 company-specific Win32 apps
- Automated Windows Update rings (WUfB)
- Everything in Corporate
- Complex Win32 app lifecycle strategies (supersedence)
- Windows LAPS (Local Administrator Password Solution)
- Multilingual deployments & kiosk devices
Technical details
Details for technical validation.
Provisioning (Windows Autopilot & ESP)
Zero-touch deployment architecture. Straight from the OEM to end users, managed through Microsoft Entra ID and Intune.
- Autopilot Deployment Profile Configuration
- Enrollment Status Page (ESP) Tuning (Timeout & Blocker Apps)
- Hardware Hash Management & OEM Integration Guidance
Configuration (Device Baseline & Compliance)
Replacing traditional GPOs with cloud-native MDM policies. I establish a hardened baseline configuration for modern Windows clients.
- BitLocker Encryption Enforcement (Silent)
- OneDrive Known Folder Move (KFM) Automation
- Device Compliance Policies (OS Version, Firewall, Defender)
Applications (Win32 Packaging & Deployment)
I move your critical legacy and fat-client applications to the IntuneWin format, including reliable detection rules and uninstall routines.
- IntuneWin packaging (Corporate: 5 apps / Enterprise: custom)
- Custom Detection Rules & Registry Checks
- App Supersedence & Dependency Mapping
Lifecycle (Windows Update for Business)
No more uncontrolled reboots or outdated systems. I build a multi-stage ring model for OS and feature updates.
- WUfB Update Ring Topology (Pilot, Broad, Fast)
- Feature Update & Quality Update Deferrals
- Deadline & Grace Period Configuration
Benefits for your business
The ROI for management.
Frequently asked questions
What prerequisites must be met before the sprint starts?
The sprint strictly requires M365 Business Premium or equivalent Intune/Microsoft Entra ID P1 licenses. The timebox counter (Day 1) only starts once administrative access (Intune Administrator via PIM) is in place and at least one physical test device with Windows 11 Pro or Enterprise (in OOBE state) is available for validation. Delays stop the project clock.
What happens if we need more than 5 applications?
To keep the scope binding, packaging is strictly limited. However, at handover your IT receives the know-how to package additional apps themselves. Alternatively, you can book me on a time and materials (T&M) basis for further packages.
Do we need new hardware for Autopilot?
No. Existing devices can be imported into the tenant afterwards with a PowerShell script. After a wipe/reset, these older devices then automatically go through the new provisioning process.
How do you validate that everything works correctly?
The “Definition of Done” is strictly binary: the sprint is complete when a defined test client runs through the agreed process in full. In the Essentials package, that means enrollment with baseline protection; from Corporate upward, Autopilot with the quoted core apps and applied update rings.
Read more in the knowledge article: Windows Autopilot: Checklist before rollout