DESKTOP PROVISIONING

A new hire opens a laptop. Everything just works.

Somebody starts Monday. The old process: IT wastes half a day imaging, installing apps, joining domain, setting up email, chasing down the VPN client. The new process: laptop ships from the vendor directly to the employee, they log in with their Microsoft or Google credentials, and 15 minutes later they're in Slack, in email, and on the VPN. That's Autopilot and Jamf, done right.

THE SITUATION

You're hiring. Every new employee is a half-day of IT provisioning that you don't have staff for. Somebody manually reimages a laptop, joins it to the domain, installs Office and Slack and 1Password and Zoom and the six SaaS apps your team uses, configures the printer, sets up the VPN, and walks the new hire through it. Then the new hire realizes their monitor cable doesn't fit their laptop's USB-C port.

You've heard about Autopilot and Jamf Pro. The docs are dense. Nobody on your team has time to read them. So you keep doing it the manual way, and every new hire costs 4-8 hours of internal IT time you can't spare.

Zero-touch provisioning isn't magic. It's an initial setup investment (2-4 weeks) and then it just runs. We handle the setup, and after that new hires provision themselves in an hour of self-service.

HOW WE FIX IT
01
Baseline design
One evening with your team to decide the standard build: which apps get pushed to everyone (Slack, Zoom, 1Password, the four SaaS tools) vs. self-service (design apps, engineering tools). Which policies apply to which role (BYOD guests, contractors, employees, admins). Written down, not just in your head.
02
Wire up the enrollment platform
For Windows: Microsoft Autopilot registered against your Entra ID tenant, Intune configuration profiles per role, autopilot deployment profile so laptops enroll on first boot. For Mac: Jamf Pro or JumpCloud, Apple Business Manager linked so new devices auto-enroll to your tenant on power-on.
03
App packages, not app installs
Standard apps packaged for MSI/PKG deployment via the MDM. Slack, Zoom, Chrome, 1Password, Microsoft Office suite, and whatever else is universal. Role-specific apps deployed to the right Entra ID group automatically. No more 'wait, I need to install the AWS CLI myself?'
04
Vendor drop-ship
New laptops ship directly from CDW / Apple Business to the employee's home or desk. Not to your reception desk. Not to be imaged by anyone. They power on, log in, and everything provisions.
05
Runbook + handoff
Written runbook: how to add a new role, how to update the base image, how to add an app to the standard set, how to troubleshoot when Autopilot fails (it will, occasionally). Your team can run this after we're done — or you keep us on for ongoing maintenance in a managed plan.
WHAT YOU GET
  • Baseline endpoint policy design (per role)
  • Autopilot deployment profile + Intune configuration
  • Jamf Pro / JumpCloud enrollment for Mac fleet
  • Apple Business Manager / Windows Autopilot device registration
  • Standard app catalog packaged and deployed
  • Role-based app assignment via groups
  • Vendor drop-ship workflow (CDW, Apple Business)
  • New-hire onboarding runbook
  • Test provisioning of 3-5 devices end-to-end
HOW THE ENGAGEMENT WORKS
Project first, then optional ongoing

Initial setup: 2-4 week project. After that, ongoing app packaging, policy updates, and per-hire dispatch is either included in a managed plan or a small monthly retainer.

Timeline

Design + setup: 2-3 weeks depending on how many role variants you need. First end-to-end test provision: end of week 3. Full production readiness (all standard apps packaged, all roles configured): 4-5 weeks.

Rough cost

Setup project: $6-15k depending on fleet size, number of role variants, and how many apps need packaging. Software licenses (Intune, Jamf) are separate — usually $6-15/device/month. Once running, per-new-hire cost drops from hours of IT time to about $0.

QUESTIONS WE GET
Autopilot or Jamf — can you do both?
Yes. Most SMBs are mixed Windows/Mac. Autopilot for Windows (via Intune), Jamf for Mac, one identity plane (Entra ID or Okta) tying it together. Standard for us.
What if we don't have Entra ID Premium?
Autopilot requires it. Business Premium licenses include it — if you're on Business Standard, we help you evaluate the upgrade. Usually a $10/user/month bump that unlocks Autopilot + Intune + conditional access.
Can we still do BYOD or contractor devices?
Yes — those go into a lightweight profile (browser-only access, MFA-required, no push-installed apps). Different policy than employee-owned devices, all managed in the same MDM.
What about apps that don't have an MSI/PKG installer?
Rare in 2025. When it happens (some old ERP or industry-specific software), we script the install with PowerShell or a shell script and deploy that via the MDM. It works.
How does this handle laptop replacement or reassignment?
New device: enroll via Autopilot/Jamf, log in, done. Reassignment: remote wipe from the MDM, reissue to the new user, they log in and everything provisions for them. No re-imaging.

Want this handled?

Tell us what's happening. We'll reply the same business day with an honest scope and a realistic price.