Field notes on enterprise endpoint management — Jamf Pro, Microsoft Intune, Windows Autopilot, Apple Business Manager, zero-touch deployment, Conditional Access and compliance. Written from work on real 1,000+ device fleets in regulated environments, not lab setups.
Conditional Access is where device compliance turns into real access control. How to build device-based policies in Entra ID that keep non-compliant machines out — without locking out your admins.
An encrypted disk with no retrievable key is a data-loss incident with a delay timer. How to enforce FileVault and BitLocker across a mixed fleet and keep every recovery key escrowed.
Zero-touch Mac deployment starts below the MDM. How to set up Apple Business Manager, wire in your reseller and MDM tokens, and avoid the enrollment gaps that bite later.
You can run a Mac fleet entirely from Microsoft Intune — enrollment, compliance, configuration, scripts and apps. Here is how to set it up properly, and the limits worth knowing before you…