Migration & Transformation

Windows 11 and Intune migration, delivered on evidence

Move once. Move with evidence. From Windows 11 and Intune to Autopilot, Entra ID, Exchange and OneDrive, we design and deliver complex enterprise migrations in governed phases, built around the estate you actually have rather than assumptions about it.

Delivery programmes

From legacy to cloud-native, without the drama

On every programme, approvals, staged deployment and rollback ride our delivery platform, so each phase moves on evidence rather than optimism.

Windows 11 & Intune Transformation

Our flagship end-to-end transformation: from Configuration Manager, MDT and Group Policy to a cloud-native, security-hardened Intune and Windows 11 estate. Security baselines enforced, Conditional Access designed, Autopilot provisioning, application packaging and a phased Windows 11 rollout, all in one structured programme that draws on every engagement on this page.

What you get

  • Governed, security-hardened Intune environment assessed against CIS, NCSC and Microsoft security baselines
  • Conditional Access policy design
  • Zero-touch Autopilot provisioning across the estate
  • Full documentation and knowledge transfer

Engagement shape: Typically 6 months for full delivery, in structured phases with governance checkpoints.

A future-ready platform combining Intune, Autopilot, Entra ID and Windows 11. Delivered for an NHS urgent-care provider ahead of the Windows 10 end-of-support deadline: phased, governed and completed on time.

Intune & Autopilot Implementation

Replace imaging infrastructure entirely: new devices ship straight to users, enrol into Intune and configure themselves out of the box. Discovery of your current build process, a Low-Level Design, Autopilot profiles, Intune enrolment, packaging standards and a supported pilot rollout.

What you get

  • Low-Level Design document
  • Autopilot profiles and Intune enrolment configured
  • Supported pilot rollout
  • MDT/PXE imaging retired

Engagement shape: Design-and-pilot engagements from as little as 14 days; full transformations run to around 6 months.

Zero-touch enrolment with no IT hands on any device, and no imaging infrastructure to maintain. Designed and piloted within 14 days for a healthcare group's device-refresh programme; delivered as part of a full six-month modern-management transformation for a private bank.

Configuration Manager (MECM, formerly SCCM) to Intune

A governed, workload-by-workload move from Configuration Manager to Intune: co-management as the bridge, then updates, applications, compliance and configuration shifted in stages, collections mapped to Entra ID groups, and the on-premises infrastructure decommissioned once nothing depends on it.

What you get

  • Co-management established as a safe transition state
  • Workloads moved to Intune in governed stages, pilot rings first
  • Applications repackaged and tested for Intune deployment
  • Configuration Manager infrastructure decommissioned, with evidence

Engagement shape: Phased by workload; delivered standalone or as part of a wider Windows 11 transformation.

Management consolidated in one cloud console, with the server estate that supported it retired. For a London university we migrated management to Intune and decommissioned SCCM entirely inside a six-month window, as part of a full Windows 11 transformation.

Group Policy to Intune Migration

Evidence-based policy migration and re-engineering. We analyse every GPO you actually apply, separate the settings that matter from the accumulated dead weight, and re-engineer what remains as clean Intune configuration, rather than lifting decades of policy into the cloud unexamined. The analysis half is a discrete engagement in its own right: see Consultancy & Analytics.

What you get

  • Full inventory of applied, redundant and conflicting policy
  • Settings mapped to Intune settings catalog and CSP equivalents
  • Security posture assessed against CIS, NCSC and Microsoft security baselines
  • Legacy GPOs retired with a documented audit trail

Engagement shape: Analysis first, then migration by policy area with pilot rings; commonly a strand of a wider Intune transformation.

Policy you can read, test and roll back, in place of inherited sprawl. GPO-to-CSP migration was a core strand of a private bank's modern-management transformation, replacing twenty years of accumulated policy with a documented, security-framework-aligned Intune configuration.

Exchange & Microsoft 365 Migration

Phased, zero-disruption moves across the messaging and collaboration estate: unsupported on-premises Exchange onto Exchange Subscription Edition or Exchange Online, mapped drives and UNC paths onto OneDrive for Business, and governed cross-tenant access when a merger needs two organisations working together before the full consolidation.

What you get

  • Migration design with clearly defined phases and joint responsibilities
  • Phased mailbox and service migration with coexistence throughout
  • OneDrive run book with tested scripts, rollback options and post-migration clean-up
  • Cross-tenant collaboration configured and governed in days
  • Legacy decommissioning

Engagement shape: Phased delivery planned around your third-party integrations and timeline; cross-tenant access typically live within days of discovery.

For a specialist IP law firm we delivered Exchange 2016 to 2019 to Subscription Edition with zero disruption to email service. A private bank's OneDrive migration ran from a piloted run book their own team executed, and a multi-academy trust used our cross-tenant access design twice as it merged with successive partner trusts.

Entra ID & Cloud-Native Device Transformation

The move from hybrid-joined, domain-dependent devices to a fully Entra-joined, cloud-native estate: identity and Conditional Access design, the right migration path for each device cohort (Autopilot reprovisioning or staged cutover), and the Active Directory dependencies that keep devices tethered identified and retired.

What you get

  • Entra-joined target state and Conditional Access designed
  • Active Directory dependencies (policy, print, file shares, legacy authentication) inventoried and unwound
  • Per-cohort migration path with pilot rings and rollback
  • Devices landed Entra-joined, managed entirely from Intune

Engagement shape: Dependency assessment first, then phased cohorts; often the closing phase of a wider transformation.

Cloud-native is the destination state of our flagship transformation above. We take estates there in phased, governed cohorts, with the evidence to show each domain dependency was retired rather than quietly left behind.

In practice

Complex moves, delivered to plan

Healthcare

An NHS urgent-care provider moved to Intune, Autopilot and Windows 11 ahead of the Windows 10 end-of-support deadline: phased, governed and completed on time.

11,000+

Professional services

Windows 10-to-11 migration support across 11,000+ endpoints in 100+ global locations, including a validated like-for-like Windows 11 image.

Financial services

A private bank's full modern-management transformation (Autopilot, co-management, GPO-to-CSP migration and an NCSC-aligned security framework) delivered as a fixed-scope programme in around six months.

The clock is running

Still running Windows 10?

Support ended on 14 October 2025. Extended Security Updates bought a year of breathing room, and that year is nearly spent.

ESU Year 1 ends on 13 October 2026, and Year 2 doubles the per-device cost. Every month on extended support also widens the gap your eventual migration has to jump: application vendors keep dropping Windows 10 from their support matrices, and assessors and insurers take an increasingly dim view of extended-support estates.

An urgent exit can still be a governed one. A short assessment puts evidence behind every device and application decision, and a phased, pilot-first migration gets you off the ESU curve before it doubles again.

Fair challenges

What clients ask before migrating

Will our users notice the migration?

Only in the ways they should: faster devices, fewer logon scripts, self-service provisioning. Every programme runs pilot-first with staged, approval-gated deployment and rollback, so problems surface in the pilot ring, not on the trading floor.

Our applications aren't packaged for Intune. Doesn't that block everything?

It's the most common blocker, which is why packaging is scoped alongside every implementation. Our packaging service turns source media into tested .intunewin packages on roughly a three-day average turnaround, so the app estate keeps pace with the rollout.

Six months sounds like a long time.

It's six months to retire SCCM, MDT and twenty years of Group Policy, with security baselines, Conditional Access and zero-touch provisioning at the end of it. Discrete pieces move much faster: Autopilot piloted in 14 days, cross-tenant access in days. The programme is phased, so value lands throughout, not at the end.

We're mid-merger. Do we wait for the full tenant migration?

No. That's exactly what cross-tenant access is for. Your teams get secure, governed collaboration in days, and the full consolidation happens later, properly planned, without pressure-driven shortcuts.

We're not ready for Microsoft 365. Are we stuck on old Exchange?

No. Exchange Subscription Edition gives you a fully supported on-premises platform, migrated in phases with coexistence throughout. It solves today's support problem and leaves every cloud option open.

Plan a migration that lands

Bring us the deadline and the estate. A senior specialist will map the phases, the risks and the quick wins on a scoping call, before you commit to anything.