Skip to content

Modern Workplace

Devices that arrive ready to work, stay secure and update themselves.

Imaging, Group Policy and a desk full of laptops waiting to be built slow every new starter and leave devices drifting out of date. We move device management to Intune and Windows Autopilot, so a new device is ready from the box and every device stays configured, patched and compliant.

Start with a Microsoft 365 security assessment
Empty open-plan office at dusk, with windows looking over a river city.

What we implement

  • Microsoft Intune for Windows, macOS, iOS and Android
  • Windows Autopilot, so devices are set up from the box by the user or a technician
  • Windows Autopatch or Intune update rings for Windows, Office and drivers
  • Windows 11 upgrades, planned around application compatibility
  • Compliance and configuration policies built as a baseline, including Essential Eight settings
  • Application packaging and deployment through Intune
  • BYOD and mobile app protection policies that keep company data in company apps
  • Moving from imaging and Group Policy to cloud-managed settings
  • Teams Phone: calling plans or Operator Connect, number porting, call queues and auto attendants
Four stages left to right: Design, Build, Cutover with a rollback path, and Handover.

How it runs

  1. Assess: current device builds, Group Policy, applications and management tools.
  2. Design: the Intune baseline, enrolment methods, update approach and app deployment.
  3. Pilot: IT first, then a pilot group from each department.
  4. Roll out: devices enrolled or refreshed in waves, with Group Policy and imaging retired as each wave completes.
  5. Hand over: policies documented and kept as code, with a lifecycle process for keeping them current.

Security built into the baseline

Device compliance feeds Conditional Access, so only healthy, managed devices reach company data. Attack surface reduction rules, BitLocker, local admin removal, macro settings and application control are part of the baseline, which covers several Essential Eight strategies in one piece of work.

Experience behind it

Before North Ark, our founder's work included Microsoft Teams and Modern Workplace projects and Defender for Endpoint implementations. Every policy we build is exported and versioned, so you can see what changed and why.

Questions buyers ask

Can we use Autopilot with our existing devices?

Yes. Existing Windows devices can be registered for Autopilot and reset into management, usually as part of a refresh or Windows 11 upgrade.

Windows Autopatch or our own update rings?

Autopatch suits organisations that want Microsoft to manage the rollout of updates within set rules. Your own rings suit those who need more control. We help you choose.

Do you manage Macs and iPhones?

Yes. macOS, iOS and Android are managed through Intune, with Apple Business Manager for company-owned Apple devices.

Do you supply the devices?

No. You buy devices from your preferred supplier, registered for Autopilot, and they arrive ready to enrol.

Can you manage devices for us afterwards?

Yes. Intune and device policy lifecycle is part of Managed Microsoft 365 and security, along with a service desk for your users.

Do you set up Teams Phone?

Yes. We design Teams Phone with calling plans or Operator Connect, port your numbers and set up call queues and auto attendants.

Start a conversation

Get new starters working on day one.

Tell us how devices are built and managed today.

Talk to an Engineer