Cogent NetworksCogent Networks Cogent NetworksDriving Innovation, Powering Success. Cogent OS
HOME/SERVICES/CLOUD & MICROSOFT/WORKPLACE MODERNISATION
Service line

Any device, anywhere -
without losing control.

Today's workforce is mobile and remote, expecting access anytime, anywhere, on any device. We build the workplace that delivers that while keeping access control, compliance and security intact.

ZERO-TOUCHANY DEVICE, ANYWHERESECURE BY DESIGNDAY-ONE-READY
19
Hubs staging and kitting devices
Zero-touch
Autopilot provisioning
24/7
Desk cover in 20 languages
The proposition

Day one, done right

A new joiner's laptop ships from our hub already Autopilot-enrolled and asset-tagged. It arrives at their home or desk, they sign in with their corporate identity, and policies, applications and Conditional Access land automatically. Their Teams Voice number is live. They are productive before they sit down, and nobody in IT touched the device.

That story is the test of a modern workplace, and it only works if procurement, staging, identity, endpoint management and the service desk are one joined-up chain rather than five handoffs. We own the whole chain: the hub that images and ships the device, the Intune policy that configures it, the identity model that secures it, and the desk that supports the person using it.

The balance we are managing is user empowerment against control. Mobility, personalisation and self-service on one side; access control, compliance and security on the other. Modernisation that sacrifices either one gets rolled back within a year.

What we modernise

Six layers of the workplace

Modern workspace architecture

The design decision underneath everything else: what runs locally, what runs in the cloud, and where virtual desktops genuinely earn their cost.

·Workspace design across cloud and hybrid·Virtual desktop and DaaS where the use case fits·Application delivery and packaging strategy·Persona-based device and access standards

Device as a Service

Devices as an operating cost with a managed lifecycle, rather than a capital purchase that ages invisibly.

·Per-device commercial model·Procurement through to refresh in one contract·Staging, imaging and kitting at our hubs·Refresh planning driven by age and DEX data·Secure exit through certified ITAD

Unified endpoint management

One management plane across Windows, macOS and mobile, with compliance enforced rather than reported.

·Intune across Windows, macOS and mobile·Compliance and configuration policy baselines·Staged update rings and patch governance·Remote hardware and software management·BYOD models with app protection policy

Identity-first security

The perimeter is identity now, so it gets the investment - centralised access management with least privilege as the default.

·Entra ID configuration and hardening·Conditional Access policy design·Passwordless and phishing-resistant MFA·Privileged access and just-in-time elevation·Centralised security and access management

Collaboration & voice

Teams as the workplace hub, including telephony and the meeting rooms it has to work in.

·Teams deployment and governance·Teams Voice: numbers, call queues, devices·Meeting-room integration with our AV service·Guest and external collaboration models

Employee experience

Measuring what users actually experience, then fixing it before they raise a ticket.

·Digital employee experience monitoring·Proactive remediation on degraded devices·Workplace and adoption analytics·Sentiment and friction reporting per persona
The experience layer

Where modernisation becomes visible

The architecture matters, but this is the part employees notice. Four services that remove queueing, waiting and depot round-trips.

IT tech bar & concierge

A staffed presence on site - a walk-up bar in larger offices, a scheduled concierge visit in smaller ones. Most device problems are solved faster face to face than through three ticket updates, and the presence itself changes how IT is perceived.

Smart lockers & vending

Zero-queue device swaps and accessories: a user collects a replacement or a peripheral from a locker at any hour using a code from their ticket, and the faulty unit goes back into the same locker for collection into our reverse-logistics chain.

Cloud-based OS provisioning

Reimage anywhere without a depot round-trip. A device that needs rebuilding is reset and re-provisioned over the network from the cloud, so a corrupted machine in a remote office is recovered the same day rather than shipped twice.

Self-service portal & AI assistant

A catalogue for the requests that do not need a human - access, software, peripherals, room bookings - with an assistant that answers from your own knowledge base and raises a ticket cleanly when it cannot.

Lifecycle

Joiner, mover, leaver - as one loop

The three moments where workplace IT is judged, and where estates leak devices, licences and access. Tied into warehouse staging at one end and certified disposal at the other.

LIFECYCLE
Joiner, mover, leaver
01
Joiner
Device staged and shipped from the hub, Autopilot-enrolled; identity, licences, policies and Teams Voice provisioned before the start date.
02
Onboard
First-login support, application delivery, security enrolment including MFA, and a short orientation to the workplace tooling.
03
Mover
Role change re-applies persona policy, access is re-scoped to least privilege, and hardware is upgraded or swapped where the new role needs it.
04
Leaver
Access revoked on the leave date, device remotely wiped or retired, licence harvested and returned to the pool.
05
Recover
Device returns through the hub for refresh into stock or certified disposal with a destruction certificate per asset.
COGENT OS TOOLING
Cogent OS workplace tooling
01 Autopilot enrolment02 Intune policy baselines03 Identity provisioning04 Licence pool05 Asset & CMDB06 DEX telemetry07 Self-service catalogue08 ITAD chain
COGENT OS · WORKPLACE LIFECYCLELIVE
REFEVENTDEVICESTATE
JML-4471Joiner · shipped from Gajków hubLT-88214Day-1 ready
JML-4488Mover · persona policy re-appliedLT-81190Complete
JML-4492Leaver · remote wipe issuedLT-77402Wiped
JML-4492Asset returned · ITAD queueLT-77402Certified
19
Hubs shipping devices
DELIVERY MANAGER & QUALITY CONTROL
Experience quality control
01
Measure
DEX telemetry on boot time, crash rate, battery health and application performance per device.
02
Detect
Degradation flagged as a proactive ticket before the user reports it.
03
Remediate
Automated fixes where possible, deskside or locker swap where not.
04
Analyse
Friction by persona, site and device model; refresh candidates identified from data.
05
Improve
Policy, image and refresh plan adjusted at the quarterly review.
Zero-touch
Provisioning as standard
19
Staging and kitting hubs
20
Desk languages
1
Asset record, buy to disposal
Transformation roadmap

Six stages, cohort by cohort

Modernisation fails when it is attempted estate-wide at once. We prove the target experience on a cohort, then roll it in waves.

01
Assess
Current workplace baselined: device age and health, identity posture, policy sprawl, application estate and user friction.
02
Design
Target experience defined per persona - device standard, policy set, access model, application delivery and support model.
03
Pilot
A representative cohort runs the target experience end to end, including a real joiner and a real leaver.
04
Wave rollout
Deployed by site or business unit, devices staged and shipped from the nearest hub, displaced kit recovered.
05
Adopt & train
Floor-walking, champion network and short-format training so the tooling is used as designed.
06
Operate & improve
Managed estate with DEX monitoring, proactive remediation and quarterly review of policy and refresh.
Centralised security
One access-management plane
Rapid procurement
Secure, hub-staged, shipped ready
On-site concierge
Proactive presence, not a queue
Lower total cost
Fewer touches, longer device life
Measurable experience
DEX data, not survey anecdote
The numbers

Experience, measured

DAY-ONE-READY RATE
96%
Joiners productive on their start date
TICKET DEFLECTION VIA DEX AND SELF-SERVICE
Proactively remediated34%
Self-service resolved28%
Locker swap, no visit14%
Deskside required24%
DEVICE ESTATE BY AGE PROFILE
3,170TOTAL
0-12 months 1,2401-2 years 9802-3 years 6403+ years - refresh due 310
Proof

A comparable engagement

CASE STUDY · MULTI-COUNTRY ENTERPRISE · WORKPLACE TRANSFORMATION
520
Devices
70%
Zero-touch coverage
32%
Reduction in desk tickets

An organisation with offices across several countries was building devices manually in each location, with different images, different policy sets and a joiner process that took a week from start date to productivity. Leavers routinely kept devices, and nobody could state the estate age profile with confidence.

We standardised on persona-based device and policy standards, moved provisioning to Autopilot with staging and shipping from our in-country hubs, and rebuilt the identity model with Conditional Access and phishing-resistant MFA. Smart lockers were installed at the larger sites for zero-queue swaps, and DEX monitoring was deployed across the estate so degradation surfaced before tickets did.

Joiners now receive a device that configures itself on first sign-in, movers get policy re-applied automatically on role change, and leavers are wiped on the leave date with the asset recovered through the hub into refresh or certified disposal. The estate age profile is now a live report rather than a guess.

Anonymised by agreement. Client names available under NDA.

FAQ

Questions buyers ask

Do we have to buy devices through you for zero-touch to work?

No. Autopilot registration can be applied to devices you buy elsewhere, and we can receive, register, image and ship them from our hubs regardless of who sold them. Buying through us usually simplifies lead times and in-country availability because our entities import directly, but it is not a condition of the service.

Is Device as a Service just leasing?

It is a lifecycle service with a per-device commercial model, which is not the same thing. The fee covers procurement, staging and kitting, deployment, support, spares, refresh planning and certified disposal - so the device is managed for its whole life rather than financed and then forgotten. You can compare it against capital purchase openly; for some estates outright purchase is still cheaper and we will say so.

What do smart lockers actually solve?

Queueing and travel. A user with a failed laptop collects a replacement from a locker using a code from their ticket at any hour, without waiting for a technician or a courier, and drops the faulty unit into the same locker for collection. In larger buildings it removes a large share of deskside visits entirely; in small offices it is not worth the cost and we say so.

How does DEX monitoring differ from normal monitoring?

Conventional monitoring tells you a device is up. DEX tells you what using it feels like: boot and login times, application responsiveness, crash and hang rates, battery and disk health. That lets us fix degradation proactively and identify refresh candidates from evidence rather than from age alone - which often means keeping healthy older devices longer and replacing unhealthy newer ones sooner.

Can you modernise without a full estate replacement?

Yes, and it is usually the right sequence. Identity, policy, security baseline and self-service can be modernised on the devices you already have, which delivers most of the security and support benefit. Hardware then refreshes on its natural cycle into the new standard rather than being force-replaced to enable the programme.

Related

Other service lines in this practice

Microsoft 365 PracticePractice overview

Want day one to actually work?

Tell us the headcount, the countries and the current joiner process. We will show you the target experience, the pilot cohort and what it costs per device.

Get a Quote Talk to an expert
+44 20 3936 1085 · INFO@COGENTNETWORKS.COM