Device enrolment, application deployment, compliance policy and Conditional Access. The technical work is well understood and, on a clean estate, it is not the hard part.
What makes endpoint management projects fail is sequencing. Conditional Access applied before enrolment locks people out. A compliance policy set to enforce before anyone has been told turns Monday morning into a support queue. And in Germany, Austria and the Netherlands, a rollout that has not been agreed with the works council can be stopped after deployment, with the money already spent.
We plan the technical work around those constraints rather than treating them as paperwork at the end. That is most of what this engagement is worth.
“They recently set up Microsoft Intune for asset management across all our remote employees. We can manage, track and reset our computers remotely. They configured it and gave me a step-by-step of what I need to do, and it has been working really well.”
“For about six months we met every other week to go through our security score and look at how to improve it. When we were first looking at partners, our Microsoft representative handed us six companies. IT Partner was by far the most reasonable price, with the highest ratings.”
Device inventory, current management, operating system versions, and what identity looks like today.
Compliance and configuration policy written down with reasons. In Germany this document starts the works council conversation, in parallel with everything else.
Applications prepared for deployment, with the required and available split agreed.
A small volunteer group enrolled, policies applied but not enforced. This is where the surprises happen and where they are cheap.
Enrolment by department, with communication before each wave rather than after.
Compliance enforced and Conditional Access applied once devices are actually enrolled. Doing this in the other order is the classic way to lock out a workforce.
Device count, operating systems, and whether a works council is involved. That last one changes the schedule more than anything technical, and it is better raised now than in month two.
Fixed, after scoping · 2–12 weeksNo, if you have Microsoft 365 Business Premium, Microsoft 365 E3 or E5, or Microsoft 365 F3 — Intune Plan 1 is included. Office 365 E3 and E5 do not include it, which is one of the more expensive surprises in Microsoft licensing.
Two to four weeks for a small estate, six to twelve weeks for a few hundred devices. In Germany, add the works council timeline, which runs in parallel but can be the longest pole.
In Germany, where one exists, yes — and it is co-determination rather than consultation, meaning agreement has to be reached. A rollout that ignores it can be required to be switched off after deployment. We plan around the Betriebsvereinbarung rather than assuming it away.
Technically yes, but it is a policy question before it is a technical one, and it is the question a works council will ask first. We put the bring-your-own position on the table during design rather than leaving it to be discovered.
A fixed price, quoted after the assessment. It is driven by device count, the number of applications to package and whether Conditional Access is in scope. Scoping costs nothing.
Not if the order is right. Enrolment first, compliance in report-only, enforcement per wave with a stated date, Conditional Access last. Break-glass accounts exist for the case where something is wrong anyway.
Scoping costs nothing
Answer the form or write to us. You get back a written scope, a sequence and a fixed price — usually within one business day, and nobody rings you unless you ask.