Skip to content
All case studies

GeekyAnts IT

Zero-touch device management across a distributed workforce

Mac, Windows and Android fleets on Kandji, Intune and SureMDM — one compliance definition, three platforms, device posture gating production access.

KandjiSureMDMMicrosoft IntuneApple Business ManagerAndroid EnterpriseOktaGoogle Workspace

A few hundred engineers across three countries, a mixed fleet, and an onboarding process that involved a laptop being physically handed to someone in an office at least one of the parties did not work from.

The tell was the asset register. It disagreed with reality, and nobody could say by how much.

Reconciliation first

Before configuring anything, we answered one question: what devices actually exist, and which of them are enrolled?

The gap between the procurement records, the identity provider’s device list and the MDM inventory is where the problem lives. Devices bought and never enrolled. Devices enrolled for people who left. Devices in the register that nobody could locate.

That reconciliation is unglamorous, takes a couple of weeks, and is the only honest starting point. Everything after it is configuration.

One compliance definition, three implementations

The policy is platform-agnostic and written once:

  • Full-disk encryption enabled, recovery key escrowed
  • Screen lock within policy, enforced not suggested
  • OS within a defined window of current
  • Firewall on, endpoint protection reporting
  • No standing local administrator for standard users

Then it is implemented per platform. Kandji for macOS, where the blueprint model and the library-item approach made the baseline straightforward to express and audit. Intune for Windows. SureMDM for Android, including shared and rugged devices where kiosk lockdown and remote control matter.

Three consoles, one definition, one compliance report. The reporting consolidation mattered more than we expected — before it, “are we compliant?” required three answers and a judgement call.

Zero-touch enrolment

Devices are purchased through channels that feed Apple Business Manager and Android Enterprise, so a new machine is already associated with the organisation before it is unboxed.

The employee powers it on, authenticates against the identity provider, and the device configures itself: policy, encryption, certificates, zero-trust client, and the application set for their role. IT never touches the hardware.

The first-day experience is the point. A working machine with the right software and no ticket queue is the difference between a programme people tolerate and one they resent.

Posture as an access condition

This is why the programme was worth doing. Once every device is enrolled and reporting state, compliance becomes a signal the identity provider can act on.

Production access now requires a managed, encrypted, patched device. Not a password. Not a password plus a second factor on the same compromised machine. A device the organisation can attest to.

That control is only available to organisations that got device management right first, which is why the device management and security practices are usually sold together.

Offboarding

Triggered by HR, not by memory. On the leave date: identity provider access revoked, device locked or wiped depending on ownership, licences reclaimed, asset flagged for return and tracked until it arrives.

Before this, offboarding was a checklist someone worked through when they got to it. The gap between “left the company” and “lost access” was measured in days. It is now measured in minutes, and it is logged — which is the form an auditor wants it in.

What we would do differently

We rolled the compliance baseline out broadly and quickly, and spent the following fortnight handling exceptions we could have predicted — design and video workstations with software that disliked the hardening, and field devices with intermittent connectivity that failed check-in thresholds.

Staging the rollout by device class, with the awkward classes first and smallest, would have cost a week and saved two.

3 platforms
macOS, Windows and Android under one policy
Zero-touch
Devices ship direct to the employee
Posture
Compliance state gates production access
Same day
Offboarding revokes and wipes

Next step

Tell us what breaks at 3am.

A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.