A new joiner's laptop ships from our hub already Autopilot-enrolled and asset-tagged. It arrives at their home or desk, they sign in with their corporate identity, and policies, applications and Conditional Access land automatically. Their Teams Voice number is live. They are productive before they sit down, and nobody in IT touched the device.
That story is the test of a modern workplace, and it only works if procurement, staging, identity, endpoint management and the service desk are one joined-up chain rather than five handoffs. We own the whole chain: the hub that images and ships the device, the Intune policy that configures it, the identity model that secures it, and the desk that supports the person using it.
The balance we are managing is user empowerment against control. Mobility, personalisation and self-service on one side; access control, compliance and security on the other. Modernisation that sacrifices either one gets rolled back within a year.
The design decision underneath everything else: what runs locally, what runs in the cloud, and where virtual desktops genuinely earn their cost.
Devices as an operating cost with a managed lifecycle, rather than a capital purchase that ages invisibly.
One management plane across Windows, macOS and mobile, with compliance enforced rather than reported.
The perimeter is identity now, so it gets the investment - centralised access management with least privilege as the default.
Teams as the workplace hub, including telephony and the meeting rooms it has to work in.
Measuring what users actually experience, then fixing it before they raise a ticket.
The architecture matters, but this is the part employees notice. Four services that remove queueing, waiting and depot round-trips.
A staffed presence on site - a walk-up bar in larger offices, a scheduled concierge visit in smaller ones. Most device problems are solved faster face to face than through three ticket updates, and the presence itself changes how IT is perceived.
Zero-queue device swaps and accessories: a user collects a replacement or a peripheral from a locker at any hour using a code from their ticket, and the faulty unit goes back into the same locker for collection into our reverse-logistics chain.
Reimage anywhere without a depot round-trip. A device that needs rebuilding is reset and re-provisioned over the network from the cloud, so a corrupted machine in a remote office is recovered the same day rather than shipped twice.
A catalogue for the requests that do not need a human - access, software, peripherals, room bookings - with an assistant that answers from your own knowledge base and raises a ticket cleanly when it cannot.
The three moments where workplace IT is judged, and where estates leak devices, licences and access. Tied into warehouse staging at one end and certified disposal at the other.
Modernisation fails when it is attempted estate-wide at once. We prove the target experience on a cohort, then roll it in waves.
An organisation with offices across several countries was building devices manually in each location, with different images, different policy sets and a joiner process that took a week from start date to productivity. Leavers routinely kept devices, and nobody could state the estate age profile with confidence.
We standardised on persona-based device and policy standards, moved provisioning to Autopilot with staging and shipping from our in-country hubs, and rebuilt the identity model with Conditional Access and phishing-resistant MFA. Smart lockers were installed at the larger sites for zero-queue swaps, and DEX monitoring was deployed across the estate so degradation surfaced before tickets did.
Joiners now receive a device that configures itself on first sign-in, movers get policy re-applied automatically on role change, and leavers are wiped on the leave date with the asset recovered through the hub into refresh or certified disposal. The estate age profile is now a live report rather than a guess.
Anonymised by agreement. Client names available under NDA.
No. Autopilot registration can be applied to devices you buy elsewhere, and we can receive, register, image and ship them from our hubs regardless of who sold them. Buying through us usually simplifies lead times and in-country availability because our entities import directly, but it is not a condition of the service.
It is a lifecycle service with a per-device commercial model, which is not the same thing. The fee covers procurement, staging and kitting, deployment, support, spares, refresh planning and certified disposal - so the device is managed for its whole life rather than financed and then forgotten. You can compare it against capital purchase openly; for some estates outright purchase is still cheaper and we will say so.
Queueing and travel. A user with a failed laptop collects a replacement from a locker using a code from their ticket at any hour, without waiting for a technician or a courier, and drops the faulty unit into the same locker for collection. In larger buildings it removes a large share of deskside visits entirely; in small offices it is not worth the cost and we say so.
Conventional monitoring tells you a device is up. DEX tells you what using it feels like: boot and login times, application responsiveness, crash and hang rates, battery and disk health. That lets us fix degradation proactively and identify refresh candidates from evidence rather than from age alone - which often means keeping healthy older devices longer and replacing unhealthy newer ones sooner.
Yes, and it is usually the right sequence. Identity, policy, security baseline and self-service can be modernised on the devices you already have, which delivers most of the security and support benefit. Hardware then refreshes on its natural cycle into the new standard rather than being force-replaced to enable the programme.
Tell us the headcount, the countries and the current joiner process. We will show you the target experience, the pilot cohort and what it costs per device.