From fragmented endpoint delivery to governed workplace platforms
Bringing consistent Windows and macOS engineering to a complex international estate without stopping the business or flattening every local requirement.
The pattern
Scale and growth had produced endpoint processes that worked locally but were difficult to govern as one service. Windows deployment varied by location and hardware type. The Mac estate began outside formal management. Acquisitions introduced devices without consistent VPN, domain or MDM foundations. Security controls depended on identity data that did not line up cleanly across platforms.
The answer was not to impose one blunt configuration everywhere. It was to establish a common operating model, keep the necessary exceptions explicit and remove accidental variation.
Windows: consolidate first, then modernise
I inherited deployment across six locations with 11 location- and device-specific SCCM task sequences and six separate HP driver repositories. I replaced them with one centrally managed, hardware-aware workflow that selected the correct laptop or desktop path and removed the local repository dependency.
For Windows 11, I designed the modern-management model around Intune and Autopilot: hardware-hash registration, migration from Group Policy into configuration profiles, CIS Level 1 baselines, Patch My PC application delivery, PowerShell automation and distinct QA and production controls. Workloads moved deliberately from SCCM to Intune so the estate did not split into two competing management models.
Windows 11 became the standard build before Windows 10 end of support. OneDrive replaced the dependency on VPN-connected home drives, allowing a device to be wiped and rebuilt in place. Regional support needed roughly five minutes to prepare the device; the user could complete the governed Autopilot build.
macOS: build the service from the ground up
A requirement arrived to encrypt approximately 450 unmanaged Macs within six to seven months. I built the Jamf tenant and its operating model, created a retrospective enrolment path for the existing estate and established annual OS readiness, Self Service, third-party patching, automated remediation, CIS controls and Apple Business Manager-led deployment.
The managed Apple estate grew to approximately 1,500 devices. Blanket local administrator rights and a shared administrator account were replaced by just-in-time elevation. More than 100 software restrictions and a controlled removal workflow supported application governance without turning the platform into a permanent support queue.
Acquisitions: create a temporary bridge to the target state
More than 500 acquired Windows devices arrived without a reliable common management foundation. I introduced a temporary Endpoint Central channel and built a PowerShell utility that collected hardware hashes and registered devices with Intune and Autopilot through a controlled application identity.
That avoided an estimated 125 to 167 hours of manual hash collection and enabled in-place Windows 11 rebuilds with automatic corporate enrolment. Devices that could not meet the Windows 11 hardware baseline were identified as explicit replacement exceptions rather than quietly weakening the target standard.
Security: solve the identity problem, not just the deployment
Endpoint Protector DLP could be deployed to macOS, but local usernames did not align with Entra identities. That prevented Security from assigning policy by the user and group model it actually needed. I challenged the initial view that the mismatch could not be resolved and worked with Jamf Professional Services on a tested account-alignment path across a 3,000-plus-device population.
The result enabled targeted DLP controls without a wholesale rebuild or broad exclusions. Once the endpoint policy layer was stable, ongoing ownership could move to the security team with a supportable platform underneath it.
The outcome
Across Windows, macOS, virtual desktops, security and acquisition work, the repeated move was the same: understand the inherited constraints, define the target service, automate the repeatable path and leave a platform that could be operated by a team rather than remembered by one engineer.
I also line-managed up to four endpoint engineers, combining autonomy with shared ownership of quality. The technical work mattered, but the durable result was an engineering operating model able to keep improving after each programme completed.
If your workplace technology has grown into overlapping tools, local exceptions and unclear ownership, the fractional IT leadership offer starts by establishing what should be standard, what genuinely needs to vary and who owns the outcome.
Start a conversation