Blog · Bring Your Own Chaos
Rolling Out Intune Without the Chaos
We’ve covered a lot of ground in this series. Part 1 was the problem; i.e. unmanaged laptops and phones nobody’s tracking. In part 2, we delved into mobiles and part 3 covered what you get once Intune’s properly set up. This last part is the bit everyone asks about once they’re sold on the idea: how do you get there without turning your business upside down?
Where Rollouts Usually Go Wrong
The stress people associate with a device management rollout doesn’t come from doing it quickly. Rather, it comes from working everything out for the first time while it’s happening. A business that decides to deploy Intune may start configuring policies from scratch, enrolling a device, finding something’s broken, adjusting, enrols another one and finding another problem. The issue here is each mistake gets discovered in a live environment on a device someone’s trying to use for actual work.
That’s a pretty rough way to do it and it’s where a lot of horror stories come from. It’s also not the only way to do it.
Outlaw Security Baselines
The difference at Outlaw is that we’re not building the policy set from nothing on someone’s live rollout. We’ve got an Intune baseline that’s already been tested, refined, and deployed across plenty of other businesses first. That includes things like:
- Defender for Business, configured with the same threat protection settings we know work, not settings someone’s guessing at for the first time
- OneDrive, set up to automatically back up and sync the folders people work from, so nothing’s sitting only on a local disk
- LAPS, giving every device a unique local admin password instead of one shared password across the fleet
- Compliance policies, tied into Conditional Access so a device that doesn’t meet the standard doesn’t get into company email or files
- Storage Sense, keeping devices running cleanly without someone needing to manually clear space
When businesses approach us and ask for more ‘security’ this is one of the many things we provide. Often, the decision makers don’t know the technical details of what they need and with Outlaw baselines, they don’t have to. Our tried and tested policies are proven to work across various IT environments and industries.
Speeding Up Deployments
If you’re building a baseline from scratch, phasing it slowly makes sense, because you’re finding problems as you go and you want those problems contained to a small number of devices at a time. If the baseline’s already proven, that logic no longer applies. That’s why, once we’re confident in the baseline for a given business, we’d usually rather roll it out across the whole fleet in one clean pass than stretch it over weeks. A short, well-communicated adjustment beats a drawn-out one where half the business is on the new setup and half isn’t, and nobody’s quite sure which category their laptop falls into.
Where BYOD Fits Into This
Personal phones, covered in part 2, don’t need to wait for the rest of the rollout to finish, and they don’t need to move at the same pace either. App protection policies are a different tool solving a different problem, and they can go live independently of whatever’s happening with laptop enrolment. If mobile access to email has been a known gap for a while, there’s a good case for sorting it early rather than treating it as part of the same project.
Staff Communication Still Matters, Whatever the Speed
Rolling out quickly doesn’t mean rolling out without warning. A short, plain-English heads-up before anyone sees a new prompt on their screen still makes the difference between a smooth switch and a flood of confused calls to IT the same afternoon. At Outlaw, we make sure you know exactly what you’re getting, when, and – perhaps most importantly – why.
What an Outlaw Device Management Deployment Looks Like
In practice, because our baseline’s already proven, we’re usually not building anything new when we roll it out to a client. Unless your business has specific IT policy requirements to accommodate, our policies go out together, across the fleet, in one or two properly planned stages, rather than being dragged out over months. That means your environment is secured and devices are properly managed quicker. Your staff get a clear explanation of what’s changing before it changes, and BYOD gets sorted on its own timeline alongside it.
The speed isn’t recklessness. It’s what’s available to you once the guesswork’s already been done somewhere else first.
Wrapping Up
This fourth part wraps up the running theme of this series: most small businesses aren’t unmanaged because of a decision anyone made. It’s just never been anyone’s job to fix, and the tools to fix it have usually been sitting in the Microsoft 365 licence the whole time.
Ready to Start Your Own Rollout?
If you’ve read this series and recognised your own business somewhere in it, that’s a good sign you’re closer to solving this than you think. The hardest part is usually just working out where to start, which is exactly what we help with. We’ve already done the guesswork, so you’re left with a set of policies that work for your businesses.
This is also exactly what we cover in our Free M365 Assessment, including a realistic view of what a rollout would look like for your specific setup.