Skip to content

Service

Device & Asset Management

Every laptop and phone enrolled, encrypted, patched and accounted for — from unboxing to offboarding.

KandjiSureMDMMicrosoft IntuneJamfApple Business ManagerAndroid EnterpriseOktaGoogle Workspace
Zero-touch
Device ships to the user, not to IT
Posture
Compliance state gates production access
Same day
Offboarding revokes access and wipes

Device management is unglamorous and it is where a surprising share of real-world compromise starts. An unencrypted laptop in a taxi. A contractor who left six months ago whose account still works. A fleet two major OS versions behind because updates were “disruptive”.

It is also where IT spend leaks — licences for people who left, hardware nobody can locate, refresh cycles driven by complaints rather than data.

The programme

Enrolment. Devices ship from the vendor directly to the employee. They power on, authenticate against your identity provider, and the device configures itself — encryption, policy, applications, certificates, VPN or zero-trust client. IT never touches the box. Apple Business Manager and Android Enterprise make this possible; Kandji, Jamf, Intune and SureMDM make it maintainable.

Baselines. One compliance definition across platforms: full-disk encryption on, screen lock within policy, OS within N versions of current, firewall enabled, EDR agent reporting, no local administrator for standard users. Devices that drift are reported, then remediated, then blocked.

Applications. A self-service catalogue so people install what they need without a ticket, with licensing tracked against actual assignment rather than against a purchase order from two years ago.

Lifecycle. Procurement, assignment, warranty, refresh eligibility and disposal — one record per asset, reconciled against what the MDM actually sees. The reconciliation is the point: the gap between the asset register and the enrolled fleet is where the missing devices live.

Offboarding. On the leave date: access revoked at the identity provider, device locked or wiped, licences reclaimed, asset marked for return. One workflow, triggered by HR, not by someone remembering.

Posture as an access condition

The reason to do this well is that it makes the security model possible. Once every device is enrolled and reporting, “is this device compliant?” becomes a signal your identity provider can act on.

Production access then requires a managed, encrypted, patched device — not a password and a hope. That single control removes a large class of credential-theft outcomes, and it is only available to organisations that got device management right first.

Who this is for

Companies growing past the point where IT is someone’s side responsibility; distributed and remote-first teams; organisations with field or frontline workforces on shared and rugged devices; and any team facing a security questionnaire that asks how they enforce encryption on endpoints.

Questions

Asked often enough to answer here.

We are a mixed Mac, Windows and Android shop. Does that work?

Yes, and it is the normal case. Kandji or Jamf for Apple, Intune for Windows, SureMDM for Android and rugged or kiosk devices. One compliance definition, enforced per platform, reported in one place.

What about rugged devices, kiosks and shared tablets?

SureMDM is strong here — kiosk lockdown, single-app mode, remote control and location for field fleets. We have run these programmes for distributed non-desk workforces.

Will employees hate it?

They hate badly configured MDM. A good programme means a device that works on day one, software available without a ticket, and no surveillance of personal activity. We draw that line explicitly in policy and configuration, and we publish it to staff.

How does this connect to security?

Device posture becomes a condition of access. An unencrypted or unpatched laptop does not reach production — enforced at the identity layer, not by asking nicely.

Next step

Tell us what breaks at 3am.

A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.