20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 4 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeServices › Intune and endpoint management

DeploymentIntuneEntra ID

Intune and endpoint management

Enrolment, applications, compliance and Conditional Access — in that order, because reversing it is how a rollout becomes an outage. And in Germany, sequenced around the works council rather than despite it.

Typical timeline2–12 weeks
PriceFixed, after scoping
Licence neededIncluded in BP, E3, E5, F3
Invoiced inYour currency
01 — Overview

What this engagement is

Device enrolment, application deployment, compliance policy and Conditional Access. The technical work is well understood and, on a clean estate, it is not the hard part.

What makes endpoint management projects fail is sequencing. Conditional Access applied before enrolment locks people out. A compliance policy set to enforce before anyone has been told turns Monday morning into a support queue. And in Germany, Austria and the Netherlands, a rollout that has not been agreed with the works council can be stopped after deployment, with the money already spent.

We plan the technical work around those constraints rather than treating them as paperwork at the end. That is most of what this engagement is worth.

02 — Outcomes

What you get out of it

01Devices enrolled and managed, with a policy set that someone wrote down and agreed to
02Applications deployed through Intune rather than by hand or by a login script nobody maintains
03Compliance policy defined, piloted, then enforced — in that order
04Conditional Access applied last, after enrolment, so nobody is locked out of the tenant they were about to be enrolled into
05Entra ID configuration and single sign-on working for the applications that matter
06Where a works council is involved, a technical proposal they can actually evaluate, delivered in parallel with the build rather than after it
07A documented policy baseline, so the next administrator knows why each setting is what it is

“They recently set up Microsoft Intune for asset management across all our remote employees. We can manage, track and reset our computers remotely. They configured it and gave me a step-by-step of what I need to do, and it has been working really well.”

“For about six months we met every other week to go through our security score and look at how to improve it. When we were first looking at partners, our Microsoft representative handed us six companies. IT Partner was by far the most reasonable price, with the highest ratings.”

03 — Deliverables

What you receive

Current-state assessment. Device inventory, existing management, operating system versions, and what is already enrolled where.
Policy design document. Every compliance and configuration policy, with the reason for each setting. This is also the document a works council can read.
Application packaging and deployment plan, with which applications are required, which are available, and which are being retired.
Conditional Access design, including break-glass accounts and the exclusions that stop an administrator locking themselves out.
Pilot report from a small group, before anything is enforced broadly.
Rollout plan in waves, with the enforcement date per wave stated rather than implied.
Works council pack, where relevant: exactly what is collected, who can see it, how long it is kept.
04 — Plan

How the work unfolds

Week 1

Assessment

Device inventory, current management, operating system versions, and what identity looks like today.

Weeks 1–2

Policy design

Compliance and configuration policy written down with reasons. In Germany this document starts the works council conversation, in parallel with everything else.

Week 2

Application packaging

Applications prepared for deployment, with the required and available split agreed.

Week 3

Pilot

A small volunteer group enrolled, policies applied but not enforced. This is where the surprises happen and where they are cheap.

Weeks 3–6

Rollout in waves

Enrolment by department, with communication before each wave rather than after.

After enrolment

Enforcement and Conditional Access

Compliance enforced and Conditional Access applied once devices are actually enrolled. Doing this in the other order is the classic way to lock out a workforce.

How many devices, and where?

Device count, operating systems, and whether a works council is involved. That last one changes the schedule more than anything technical, and it is better raised now than in month two.

Fixed, after scoping · 2–12 weeks
05 — Before we start

What we need from you

Intune licensing — included in Business Premium, Microsoft 365 E3 and E5, and Microsoft 365 F3
Global Administrator or Intune Administrator access
A decision on personal devices: whether bring-your-own is in scope, and on what terms
In Germany, Austria or the Netherlands, works council engagement started at the same time as the design — why it cannot wait
A named owner for each application to be deployed
06 — Working together

Who does what

IT Partner

  • Assess the current estate and identity configuration
  • Design the policy set and write down the reasoning
  • Package and configure application deployment
  • Run the pilot and report what it found
  • Roll out in waves with enforcement dates stated
  • Apply Conditional Access after enrolment, with break-glass accounts
  • Hand over documented policy, not a working system nobody understands

Your team

  • Provide licensing and administrative access
  • Decide the bring-your-own-device position
  • Run the works council conversation, with our technical input
  • Name application owners
  • Approve each wave and its enforcement date
  • Tell users what is being installed and why
07 — Scope

What is not included

×Hardware procurement and imaging. We configure Autopilot; buying and staging devices is yours or your reseller’s.
×Legal drafting of a Betriebsvereinbarung. We provide the technical content it needs; your counsel and works council write it.
×Microsoft Defender for Endpoint deployment at scale where it is a security programme rather than a device-management one — scoped separately.
×macOS, Linux and Android management beyond basic enrolment, unless agreed in scope.
×Ongoing device administration. Available as managed services if you want us to run it.
08 — Fine print

Limitations and technical notes

!Order matters more than anything else. Enrol, then comply, then Conditional Access. Reversing that sequence locks people out, and it is the single commonest failure in Intune projects.
!Break-glass accounts are not optional. Here is what happens without them. At least two accounts excluded from Conditional Access, with credentials stored where a locked-out administrator can reach them.
!German co-determination applies. Under §87(1) No. 6 of the Betriebsverfassungsgesetz a works council has co-determination — not consultation — over systems capable of monitoring behaviour or performance. Intune, Conditional Access and Defender all qualify.
!Existing management has to be removed first. A device managed by two systems behaves unpredictably, and the symptoms look like something else entirely.
!Compliance policy in report-only mode first. Enforcing on day one converts a rollout into an outage.
!Conditional Access policies do not migrate between tenants. If this is part of a consolidation, they are rebuilt in the target rather than moved.
09 — Questions

Asked on almost every first call

Do we need a separate Intune licence?

No, if you have Microsoft 365 Business Premium, Microsoft 365 E3 or E5, or Microsoft 365 F3 — Intune Plan 1 is included. Office 365 E3 and E5 do not include it, which is one of the more expensive surprises in Microsoft licensing.

How long does a rollout take?

Two to four weeks for a small estate, six to twelve weeks for a few hundred devices. In Germany, add the works council timeline, which runs in parallel but can be the longest pole.

Does the works council really have to approve it?

In Germany, where one exists, yes — and it is co-determination rather than consultation, meaning agreement has to be reached. A rollout that ignores it can be required to be switched off after deployment. We plan around the Betriebsvereinbarung rather than assuming it away.

Can you manage personal devices?

Technically yes, but it is a policy question before it is a technical one, and it is the question a works council will ask first. We put the bring-your-own position on the table during design rather than leaving it to be discovered.

What does it cost?

A fixed price, quoted after the assessment. It is driven by device count, the number of applications to package and whether Conditional Access is in scope. Scoping costs nothing.

Will users be locked out during the rollout?

Not if the order is right. Enrolment first, compliance in report-only, enforcement per wave with a stated date, Conditional Access last. Break-glass accounts exist for the case where something is wrong anyway.

10 — Related

Worth reading next

Scoping costs nothing

Tell us the shape of it and we will tell you what it involves

Answer the form or write to us. You get back a written scope, a sequence and a fixed price — usually within one business day, and nobody rings you unless you ask.