Device enrollment
Windows, iOS, iPadOS and Android devices brought under management, with the enrollment path chosen per platform and per ownership model so nothing arrives unmanaged by accident.
Endpoint management, scoped and fixed-fee
Intune deployment services for small business teams cover the whole endpoint rollout: enrolling Windows laptops and mobile devices, setting up Windows Autopilot, publishing compliance and app protection policies, and requiring a compliant device before company data opens. This is a device rollout, not a settings audit — our Microsoft 365 tenant security assessment owns the tenant review and the findings report; this page owns the devices.
Representative dashboard — sample data
What the rollout covers
Each one is a working configuration in your own tenant at handover, not a recommendation to action later.
Windows, iOS, iPadOS and Android devices brought under management, with the enrollment path chosen per platform and per ownership model so nothing arrives unmanaged by accident.
New laptops ship to the employee and configure themselves on first sign-in: apps, settings, and security baseline applied without an engineer touching the machine or building an image.
A written definition of a healthy device — disk encryption, supported OS version, screen lock, antivirus state — that Intune evaluates continuously instead of once at setup.
Company mail and files stay inside managed apps on staff-owned devices, with copy, paste and save-as controlled — no enrollment, and nothing touching personal photos or messages.
The rule that makes the rest matter: company data opens on a compliant, managed device, and a jailbroken phone or an unencrypted laptop is refused before it ever reaches a file.
Windows update rings staged so patches reach a pilot group first, core apps deployed from Intune, and a written record of every policy so your team can run it without us.
How the engagement runs
A free consultation establishes how many devices you have, which platforms, who owns them, and what your licenses already entitle you to. You approve one written scope and one fixed fee before any configuration starts.
Enrollment, Autopilot profiles, compliance and app protection policies are built and tested against a pilot group of real users. Problems surface on five people rather than on the whole company.
Remaining devices are enrolled in waves, conditional access is switched from report-only to enforcing, and you receive the configuration documentation plus 30 days of hypercare.
Most small businesses that ask about endpoint management already own Intune and have never turned it on. It arrived bundled with Microsoft 365 Business Premium, nobody had a spare fortnight to configure it, and the laptops carried on being set up by hand. The result is a fleet nobody can describe: some machines encrypted, some not, a few still running an operating system that stopped getting security updates, and no way to answer an insurer asking how many devices reach company data.
An Intune rollout replaces that guesswork with a policy. Devices enroll once, get evaluated continuously against a standard you wrote down, and lose access when they drift out of it. Microsoft's own Intune deployment and setup guidance (opens in new tab) lays the sequence out in steps; what a small business usually lacks is not the documentation but the fortnight, the pilot discipline, and someone who has done it before on a fleet this size. That is the whole of what we sell here, on the same fixed-fee scoping model as everything else on this site.
These two engagements are frequently confused, so the boundary is worth stating plainly. A Microsoft 365 tenant security assessment is a one-off, read-only audit: we read identity, sharing, email and configuration settings, write down what we found, hand you a prioritized fix list, and change nothing. This page is the opposite motion. It is an endpoint-management rollout that changes real configuration, and its subject is devices — enrollment, Autopilot, compliance, app protection, and device-based conditional access. The rule of thumb we use internally: tenant settings belong to the assessment, anything about a laptop or a phone belongs here. Plenty of clients do both, usually in that order, because the audit tells you whether unmanaged devices are actually your biggest exposure before you spend anything fixing them.
The scope below is the standard shape of the engagement. Where a platform is not in use — no Android, no company-owned phones — that row is dropped during scoping and the fee reflects it rather than quietly including work that never happens.
| Capability | What we configure | What changes day to day |
|---|---|---|
| Device enrollment | Enrollment methods per platform and ownership model, device categories, and naming so the inventory is readable | You can name every device that touches company data, and see when each one last checked in |
| Windows Autopilot | Deployment profiles, Enrollment Status Page, and the hardware registration process with your supplier or reseller | A replacement laptop is unboxed by the employee and is working the same morning, without an engineer |
| Compliance policies | Disk encryption, minimum OS version, screen lock and password rules, antivirus and firewall state, jailbreak detection | Non-compliant devices are flagged, given a grace period, then blocked — automatically, not by someone noticing |
| App protection policies | Managed-app rules for Outlook, Teams and OneDrive on personal phones: copy and paste limits, save-as restrictions, PIN | Staff use their own phones for work without the company managing the phone, and leavers lose company data only |
| Device-based conditional access | Policies requiring a compliant or hybrid-joined device, built in report-only mode first, with break-glass exclusions | An unmanaged laptop signing in with a correct password still cannot open your files |
| Update rings and app deployment | Staged Windows update rings, deferral windows, and required or available app assignments from Intune | Patching happens on a schedule you set, and new starters get the right apps without a build sheet |
| Reporting and handover | Compliance and enrollment reporting, plus written documentation of every policy, its purpose, and its exclusions | You can answer an insurance or customer security questionnaire from a report instead of from memory |
Each of these is configured against Microsoft's published guidance rather than a house preference: Autopilot against the Windows Autopilot documentation (opens in new tab), device rules against the Intune device compliance documentation (opens in new tab), personal-phone controls against the app protection policy documentation (opens in new tab), and access rules against Microsoft's Conditional Access documentation (opens in new tab). Where a recommendation does not fit how you actually work, we say so and write down the decision instead of silently skipping it.
Intune is bundled into the two plans most small businesses are already on, which is why the licensing conversation is usually shorter than people expect. The figures below are Microsoft's published US list prices for annual-term subscriptions at the time of writing — they are Microsoft's prices, not ours, and they move, so check Microsoft's pricing pages before you buy anything.
| Plan | Intune included? | Microsoft list price | Notes |
|---|---|---|---|
| Microsoft 365 Business Standard | No | — | Office apps and services without the security and device-management stack; an upgrade is required for Intune |
| Microsoft 365 Business Premium | Yes | $22.00 per user/month paid yearly; $26.40 billed monthly | The common starting point under 300 seats — also bundles Entra ID P1 and Defender for Business |
| Microsoft 365 E3 | Yes | $39.00 per user/month paid yearly | No seat cap, plus Windows Enterprise management; the trade-offs are covered in our Business Premium vs E3 comparison |
| Intune Plan 1 (standalone) | Yes | Sold separately — see Microsoft's pricing page | The route when devices need managing but the users do not need a full Microsoft 365 plan |
We confirm what you already own during scoping. If your existing licenses cover the rollout, that is what the consultation will tell you — buying seats you do not need is not something we get paid for.
Pricing is scoped rather than listed because the honest drivers are device count, platform mix, and whether anything is managed today. Fifteen Windows laptops and no mobile is not the same rollout as a hundred devices across three platforms with an old on-premises group policy estate still in play.
| Stage | What happens | Timeline | Fee |
|---|---|---|---|
| Free consultation | A senior engineer confirms device counts, platforms, ownership model and licensing, and says plainly whether a full rollout is the right first step | Before scoping | No charge |
| Build and pilot | Enrollment, Autopilot, compliance, app protection and conditional access configured and proven against a pilot group of real users | Inside our usual 2–4 week delivery window | Fixed fee — scoped after your free consultation |
| Wave rollout and handover | Remaining devices enrolled in waves, policies moved from report-only to enforcing, documentation delivered, hypercare begins | Within the same delivery window | Included in the fixed fee |
| Hypercare | The edge cases that only appear in production — a contractor's device, a legacy application, an exception nobody predicted | 30 days after handover | Included in the fixed fee |
The common fit is a 10–300 person company where one IT generalist or an outsourced provider looks after everything, laptops have always been configured by hand, and staff read work email on their own phones. The trigger is rarely curiosity: it is a cyber-insurance questionnaire asking whether devices are managed and encrypted, a customer security review, a laptop that went missing, or the moment a new starter needs a machine and nobody can remember how the last one was set up.
What follows depends on what the rollout exposes. If device management surfaces broader configuration questions across the tenant, the read-only tenant security assessment is the right next step. If the real issue is that company files live in places nobody can control, that is a structure problem best solved with SharePoint intranet and document management consulting. And if an AI rollout is what prompted the device conversation, managed endpoints are only half the story — the content side is covered in Copilot data governance essentials.
Related services
The read-only audit that covers everything this page does not: identity, sharing, email and admin roles, delivered as a findings report you own.
Managed devices control who reaches your files. Intranets and document management control what those files are and where they live.
A governed Copilot rollout that starts with readiness and permission cleanup, then pilots and adoption training on a fixed fee.
FAQ
Five workstreams: enrolling Windows, iOS and Android devices; Windows Autopilot so a new laptop configures itself out of the box; compliance policies that define what a healthy device looks like; app protection policies for company data on personal phones; and conditional access rules that let only compliant devices reach your data.
The assessment is a one-off, read-only audit of tenant configuration that ends in a written findings report. This engagement changes how devices are managed: we enroll them, build Autopilot profiles, publish compliance and app protection policies, and enforce them. Tenant settings belong to the assessment; anything about devices belongs here.
Usually not. Microsoft 365 Business Premium and Microsoft 365 E3 both include Intune, so most small businesses already own it and have simply never switched it on. Where a plan does not cover it, Intune is sold as a standalone subscription. We confirm your entitlements during scoping, before anything is quoted.
No. Personal phones are handled with app protection policies, which govern company data inside Outlook and Teams without enrolling the device or touching personal photos, apps or messages. When someone leaves, only the company data is removed. Full device management is reserved for hardware the company owns.
One fixed fee, scoped after a free consultation, because the honest driver is how many devices and platforms you run. Delivery falls inside our usual two-to-four-week window, a pilot group always goes first, and thirty days of hypercare follow handover so real-world edge cases land on us.
No. Every policy lives in your own tenant under your own admin accounts, and you receive written documentation of what was configured and why. Your IT lead or your MSP can run it, change it, or hand it to someone else entirely. Nothing here requires a retainer with us.
Book a free consultation
Tell us what you’re trying to fix — a report, an approval process, an intranet, a Copilot rollout. We scope it as a fixed-fee project, you approve, and a senior engineer delivers in 2–4 weeks.
The fastest way to reach us is the form — tell us the task and we’ll reply within one business day.