Skip to main content
Service

Intune — every device enrolled, compliant, and wipeable

Company laptops and staff phones under one policy. New devices self-configure on first sign-in, and a lost one is remotely wiped in minutes rather than worried about.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Intune device management — Autopilot enrolment, compliance policy, application deployment and remote wipe across company and personal devices.

What Intune is for

Two questions that used to be answered by a domain controller and a locked office, and are not any more:

Which devices are allowed to reach our data? When everything lived on the network, the answer was “the ones plugged into it”. Now your data is in Microsoft 365, reachable from any device with valid credentials — including an unpatched personal laptop with no screen lock and a browser full of extensions.

How do we get company data off a device we do not control? A laptop in the back of a taxi, a phone sold on marketplace, a contractor at the end of an engagement.

Intune answers both. Compliance policy decides what may connect; enrolment and app protection decide what can be removed.

Managed devices and protected apps

The distinction matters and is worth getting right, because applying the wrong one causes genuine friction.

Full enrolment for company-owned hardware. The organisation manages the device: configuration, applications, updates, encryption, and remote wipe of the whole thing.

App protection for personal phones. No device enrolment. Company data is controlled inside company applications — a PIN required to open Outlook, copy-paste into personal apps blocked, company data removable on demand — while the device itself, and everything personal on it, remains untouched and invisible to you.

Attempting full enrolment on staff-owned phones is where BYOD programmes get resisted, usually correctly. People do not want their employer managing their personal phone, and they are right not to.

Autopilot changes onboarding

Traditional device provisioning meant a technician imaging a machine, installing software, and either delivering it or shipping it. For a business hiring someone in another state, that meant couriering hardware to head office first.

With Autopilot, the device identity is registered at purchase. The machine ships from the supplier directly to the person. They switch it on, sign in with their work account, and it joins the tenant, applies policy, installs their applications and is ready to use.

This pairs directly with how we handle procurement, and it is what makes remote onboarding work properly rather than approximately.

Compliance is the part that gets skipped

Having the capability is not the control. The control is a policy that continuously checks encryption, screen lock, operating system version and security agent presence, and blocks non-compliant devices from company data until they are fixed.

Deployments that enrol devices but never enforce compliance are common. They give you an inventory and a remote wipe button, which is worth having, and none of the actual prevention.

Check your licensing first

Intune is included in Microsoft 365 Business Premium and in E3 and E5. It is not in Business Standard or Business Basic.

A significant number of businesses on Business Standard are paying for add-ons that Business Premium would have included, or are missing security capability they assume they have. It is worth a licensing review before buying anything.

What you get with JTIT

Concrete deliverables, not vague promises.

New devices configure themselves

With Autopilot, a laptop shipped straight to a new starter enrols, applies policy and installs applications on first sign-in. No imaging, no visit to head office.

A lost laptop is a phone call, not a crisis

Remote wipe on company devices, and selective wipe of company data on personal ones, leaving the owner's photos alone.

Compliance enforced, not requested

Encryption, screen lock, minimum OS version and security agent presence checked continuously, with non-compliant devices blocked from company data.

BYOD without owning the phone

App protection policies control company data inside company apps on personal phones, without managing the device or seeing anything personal.

Software deployed centrally

Applications and updates pushed to the fleet rather than installed one machine at a time, which is also how you know what is actually installed.

Offboarding that completes

When someone leaves, access is revoked and company data removed from their devices as part of the same process, rather than hoping the laptop comes back.

How it works

A predictable, no-surprises process.

  1. 01

    Design the policy set

    Compliance baseline, configuration profiles, and which device types are managed versus app-protected. Decided against how your people actually work.

  2. 02

    Enrol the existing fleet

    Current devices brought under management progressively, rather than in a single disruptive push, with users told what changes.

  3. 03

    Set up Autopilot for new devices

    Hardware registered at purchase so future machines ship direct to the user and configure themselves on first boot.

  4. 04

    Monitor and maintain

    Compliance state monitored, policies adjusted as the OS and your requirements change, and non-compliant devices chased rather than ignored.

Frequently asked questions

Can you manage staff personal phones without seeing their private data?

Yes, and this is the distinction worth understanding. Full device enrolment gives the organisation management of the whole device and is appropriate for company-owned hardware. App protection policies work differently: they control company data inside company applications — preventing copy-paste into personal apps, requiring a PIN for Outlook, allowing selective wipe of company data only — without enrolling the device. On a personal phone, app protection is almost always the right answer, and it is worth telling staff explicitly that you cannot see their photos or browsing.

What is Autopilot?

A provisioning service that lets a new device configure itself. The hardware identity is registered with your tenant at purchase, so when the device is first switched on and the user signs in with their work account, it joins the tenant, applies your policies, installs applications and is ready. No imaging, no technician touching it, and it works with the device shipped directly to a home address anywhere in Australia.

What happens if someone loses a laptop?

For a managed, encrypted device: it is remotely wiped, and because the disk was encrypted, the data was already unreadable without credentials. The practical exposure is close to zero, provided the compliance policy enforcing encryption was actually applied — which is precisely why compliance enforcement matters more than having the capability.

Do we need Intune if we already have antivirus?

They solve different problems. Endpoint protection deals with threats on the device. Intune deals with whether the device should have access to company data at all — is it encrypted, patched, locked, and running the security agent. Without something enforcing that, an unpatched personal laptop with no screen lock can sign in to your Microsoft 365 data quite happily.

Is Intune included in our Microsoft 365 licence?

It depends which licence you hold. Intune is included in Microsoft 365 Business Premium and in the enterprise E3 and E5 plans, and is not included in Business Standard or Business Basic. Businesses on Business Standard frequently find that moving to Business Premium is worth it for Intune and the security features that come with it. Licensing review is worth doing before buying anything as an add-on.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote