On private phones (BYOD) we protect only the company area via app management (MAM). On exit we selectively wipe business data, while the employee's photos and private content stay untouched.
New devices that simply work on day one
Unbox, sign in and work: Autopilot and Intune deliver apps, policies and compliance without an IT appointment. Management and offboarding stay centrally visible.

From box to compliant.
The flow shows what happens at first start, during daily operation and when a device is returned.
Sign in instead of installing by hand.
Autopilot assigns the device to the organisation; Intune loads the intended apps, settings and policies.

If a device goes missing, we lock or wipe it remotely, fully or just the company container. Data is gone before it becomes a problem.
Devices cost time before they create value
Every new laptop means hours of manual setup, every lost phone is a data risk, and nobody quite knows which device is on which state. In an SME without a large IT team, this lands on a few individuals, or it simply doesn't get done. Updates slip, and old devices leave the building without proper offboarding.
A visible change, not another tool rollout.
Autopilot · Intune · Compliance · Offboarding
- 01Zero-touch provisioningSetup via Microsoft Intune and Windows Autopilot so devices are ready without manual installation, including predefined apps and settings.
- 02Security baselineEnabled by default: BitLocker encryption, Secure Boot, firewall, antivirus and a password requirement of at least 14 characters, tuned to SME reality.
- 03Compliance and Conditional AccessPolicies check every device (validity typically 30 days) and govern access: notify, lock or reset, depending on status.
- 04Defender for BusinessThreat detection and response directly on the device, integrated into the central view, with no separate console for day-to-day work.
Your endpoint baseline.
The documented foundation for deployment, security, compliance and offboarding.
- Zero-touch provisioningSetup via Microsoft Intune and Windows Autopilot so devices are ready without manual installation, including predefined apps and settings.
- Security baselineEnabled by default: BitLocker encryption, Secure Boot, firewall, antivirus and a password requirement of at least 14 characters, tuned to SME reality.
- Compliance and Conditional AccessPolicies check every device (validity typically 30 days) and govern access: notify, lock or reset, depending on status.
- Defender for BusinessThreat detection and response directly on the device, integrated into the central view, with no separate console for day-to-day work.
- Mobile and BYOD managementManagement of company and personal devices via MDM and MAM, with a clear separation between full device management and protecting only the company container.
- Lifecycle to retirementA clean process from first boot through Windows 11 to offboarding, including selective or full wipe on device return or departure.
What the new working model should achieve.
- Day 1
- productive from first sign-in
- No server
- cloud-native, lower running costs
- Minutes
- remote lock instead of data risk
Corporate and personal devices use separate management models with a clearly documented scope.
Frequently asked questions
Does our device data stay in Switzerland?
Management runs on Microsoft 365 with data residency in Switzerland or the EU, aligned with revDSG and GDPR. We configure storage location and policies so your data protection requirements are demonstrably met.
Do we need our own server for this?
No. We deliberately favour cloud-native Entra join over hybrid, unless legacy systems genuinely require otherwise. That removes a local server, lowers cost and noticeably simplifies operations.
Which licence do we need?
For most SMEs Microsoft 365 Business Premium is the right basis, it includes Intune (Plan 1) and Defender for Business. We tell you upfront and transparently what you actually need, rather than selling more than necessary.
What happens to a personal phone when someone leaves?
With BYOD we manage only the company area via app management. On exit we selectively wipe business data, while everything private to the employee stays intact and untouched.
Let's talk about your workplace.
Whether it's migrating to Microsoft 365, zero-trust security or a Copilot rollout — together we'll find the right path.