Skip to content

    New devices that simply work on day one

    Unbox, sign in and work: Autopilot and Intune deliver apps, policies and compliance without an IT appointment. Management and offboarding stay centrally visible.

    Windows Autopilot diagnostics showing network, enrolment, policy and app status.
    Windows AutopilotFirst-run diagnostics make enrolment, policies and app deployment reviewable.

    From box to compliant.

    The flow shows what happens at first start, during daily operation and when a device is returned.

    Sign in instead of installing by hand.

    Autopilot assigns the device to the organisation; Intune loads the intended apps, settings and policies.

    Windows Autopilot diagnostics showing network, enrolment, policy and app status.
    Windows AutopilotFirst-run diagnostics make enrolment, policies and app deployment reviewable.
    Bring personal devices in without intruding

    On private phones (BYOD) we protect only the company area via app management (MAM). On exit we selectively wipe business data, while the employee's photos and private content stay untouched.

    Loss is no longer an emergency

    If a device goes missing, we lock or wipe it remotely, fully or just the company container. Data is gone before it becomes a problem.

    Devices cost time before they create value

    Every new laptop means hours of manual setup, every lost phone is a data risk, and nobody quite knows which device is on which state. In an SME without a large IT team, this lands on a few individuals, or it simply doesn't get done. Updates slip, and old devices leave the building without proper offboarding.

    A visible change, not another tool rollout.

    Before: manual setupIndividual installations, inconsistent settings and limited visibility.
    After: policy-basedDefined profiles, central status and a documented lifecycle.
    Deliverables
    Project handoverEndpoint Baseline

    Autopilot · Intune · Compliance · Offboarding

    1. 01Zero-touch provisioningSetup via Microsoft Intune and Windows Autopilot so devices are ready without manual installation, including predefined apps and settings.
    2. 02Security baselineEnabled by default: BitLocker encryption, Secure Boot, firewall, antivirus and a password requirement of at least 14 characters, tuned to SME reality.
    3. 03Compliance and Conditional AccessPolicies check every device (validity typically 30 days) and govern access: notify, lock or reset, depending on status.
    4. 04Defender for BusinessThreat detection and response directly on the device, integrated into the central view, with no separate console for day-to-day work.

    Your endpoint baseline.

    The documented foundation for deployment, security, compliance and offboarding.

    • Zero-touch provisioningSetup via Microsoft Intune and Windows Autopilot so devices are ready without manual installation, including predefined apps and settings.
    • Security baselineEnabled by default: BitLocker encryption, Secure Boot, firewall, antivirus and a password requirement of at least 14 characters, tuned to SME reality.
    • Compliance and Conditional AccessPolicies check every device (validity typically 30 days) and govern access: notify, lock or reset, depending on status.
    • Defender for BusinessThreat detection and response directly on the device, integrated into the central view, with no separate console for day-to-day work.
    • Mobile and BYOD managementManagement of company and personal devices via MDM and MAM, with a clear separation between full device management and protecting only the company container.
    • Lifecycle to retirementA clean process from first boot through Windows 11 to offboarding, including selective or full wipe on device return or departure.

    What the new working model should achieve.

    Day 1
    productive from first sign-in
    No server
    cloud-native, lower running costs
    Minutes
    remote lock instead of data risk

    Corporate and personal devices use separate management models with a clearly documented scope.

    Frequently asked questions

    Does our device data stay in Switzerland?

    Management runs on Microsoft 365 with data residency in Switzerland or the EU, aligned with revDSG and GDPR. We configure storage location and policies so your data protection requirements are demonstrably met.

    Do we need our own server for this?

    No. We deliberately favour cloud-native Entra join over hybrid, unless legacy systems genuinely require otherwise. That removes a local server, lowers cost and noticeably simplifies operations.

    Which licence do we need?

    For most SMEs Microsoft 365 Business Premium is the right basis, it includes Intune (Plan 1) and Defender for Business. We tell you upfront and transparently what you actually need, rather than selling more than necessary.

    What happens to a personal phone when someone leaves?

    With BYOD we manage only the company area via app management. On exit we selectively wipe business data, while everything private to the employee stays intact and untouched.

    Let's talk about your workplace.

    Whether it's migrating to Microsoft 365, zero-trust security or a Copilot rollout — together we'll find the right path.

    We use cookies and external services (e.g. Google Maps) to provide you with the best experience on our website. For more information, see our Privacy Policy.