Run · Service 06

Endpoint & mobility

Every device that touches your data, enrolled and accounted for — laptop, phone, tablet or rugged handheld, corporate or personal. From the box it arrives in to the day it is securely wiped.

A rugged handheld scanner being used to scan a barcode in a warehouse
Where we come from

This is the discipline we were built on

Before Next Cyber, our founder led professional services at Ivanti — a global vendor in unified endpoint and mobile device management — delivering enrolment programs across government and enterprise fleets, including environments where devices go into places with no reliable network and no IT staff within four hundred kilometres.

That background shows up in unglamorous ways: we plan for the device that fails enrolment, the user who factory-resets their phone on holiday, the depot that ships fifty handhelds to the wrong state, and the executive who will not accept a work profile on a personal phone.

Most MDM projects do not fail technically. They fail at enrolment logistics and at the conversation with the people whose devices are being managed.

Platforms

Four platforms, one set of policies

The control objective should not change because somebody chose a different operating system. The implementation always does.

Windows

Intune with Autopilot, Windows Update for Business rings, BitLocker with escrowed keys, Defender policy and LAPS for local administrator credentials.

macOS & iOS

Jamf or Intune with Apple Business Manager, automated device enrolment, FileVault escrow, managed app configuration and volume purchasing.

Android

Android Enterprise in fully managed, dedicated or work profile mode, zero-touch enrolment, and kiosk configuration for shared and single-purpose devices.

Rugged & purpose-built

Zebra, Honeywell and Datalogic handhelds for warehouse, field and logistics work, including staged provisioning and barcode-driven enrolment.

Lifecycle

Six stages, and we own every one

Most providers pick up at stage three and drop off after stage four. The cost and the risk live at both ends.

  1. Specify

    Standard builds by role, so you are buying three configurations rather than thirty. Sized for a realistic four-year life, not the cheapest unit price today.

  2. Procure & register

    Purchased through distribution and registered to your Autopilot, Apple Business Manager or zero-touch account before it ships — so it enrols itself on first power-on.

  3. Enrol

    Zero-touch where the platform supports it. The device arrives at the user's home or desk, they sign in, and it configures itself. No imaging bench, no shipping to head office first.

  4. Configure & comply

    Baseline security policy, encryption, applications delivered by role, and a compliance state that conditional access can act on — a non-compliant device loses access to company data automatically.

  5. Maintain

    Patch rings, application updates, certificate renewal, drift detection, and warranty tracking so a fleet-wide fault is identified as a fleet-wide fault.

  6. Retire

    Selective wipe for BYO, full wipe and deregistration for corporate, asset register updated, and certified data destruction with a certificate for your records.

Personal devices

BYO, handled without reading anyone's photos

The fastest way to lose a BYO rollout is for one person to believe you can see their personal messages. Usually they are wrong, and occasionally they are not.

  • Work profile containerisation on Android and user enrolment on iOS — corporate data lives in a separate, encrypted container.
  • Selective wipe only. On offboarding we remove the work container. Personal photos, messages and applications are untouched and untouchable.
  • A written statement of visibility issued to every enrolling user, listing precisely what the organisation can and cannot see.
  • No location tracking on personal devices. On corporate and shared devices it is enabled only where there is a stated operational reason.
  • Conditional access as the enforcement point, so an unenrolled personal device gets browser-only access rather than a hard block.
  • An opt-out path for staff who decline enrolment — usually a corporate-supplied device, because the alternative is unmanaged access.
Questions

What people ask

We have Intune licensed but never deployed it. Can you pick it up?

That is one of our most common engagements. It is usually two to four weeks: review what is half-configured, define the policy baseline, pilot with a group who will tell you honestly when something breaks, then enrol in waves by department.

Can you manage devices we did not supply?

Yes, though existing devices need manual enrolment rather than zero-touch, which is more work per device. We usually run existing hardware through manual enrolment and register everything purchased from that point onward, so the fleet converges over a refresh cycle.

What about devices with no reliable internet?

Staged provisioning before dispatch, offline-capable policy, and enrolment profiles that tolerate long gaps between check-ins. For field and logistics fleets we also set compliance grace periods so a device does not lose access because it spent four days out of coverage.

How do you handle shared devices?

Shared device mode for frontline workers, so sign-out genuinely clears the session and the next person does not inherit the last person's mailbox. For kiosk and single-purpose devices, a locked-down configuration exposing only the applications required.

How many devices can you actually account for

The assessment includes a full device and enrolment audit. The gap between the asset register and reality is usually the interesting part.