Windows 11 & Intune Transformation
Our flagship end-to-end transformation: from Configuration Manager, MDT and Group Policy to a cloud-native, security-hardened Intune and Windows 11 estate. Security baselines enforced, Conditional Access designed, Autopilot provisioning, application packaging and a phased Windows 11 rollout, all in one structured programme that draws on every engagement on this page.
What you get
- Governed, security-hardened Intune environment assessed against CIS, NCSC and Microsoft security baselines
- Conditional Access policy design
- Zero-touch Autopilot provisioning across the estate
- Full documentation and knowledge transfer
Engagement shape: Typically 6 months for full delivery, in structured phases with governance checkpoints.
A future-ready platform combining Intune, Autopilot, Entra ID and Windows 11. Delivered for an NHS urgent-care provider ahead of the Windows 10 end-of-support deadline: phased, governed and completed on time.
Intune & Autopilot Implementation
Replace imaging infrastructure entirely: new devices ship straight to users, enrol into Intune and configure themselves out of the box. Discovery of your current build process, a Low-Level Design, Autopilot profiles, Intune enrolment, packaging standards and a supported pilot rollout.
What you get
- Low-Level Design document
- Autopilot profiles and Intune enrolment configured
- Supported pilot rollout
- MDT/PXE imaging retired
Engagement shape: Design-and-pilot engagements from as little as 14 days; full transformations run to around 6 months.
Zero-touch enrolment with no IT hands on any device, and no imaging infrastructure to maintain. Designed and piloted within 14 days for a healthcare group's device-refresh programme; delivered as part of a full six-month modern-management transformation for a private bank.
Configuration Manager (MECM, formerly SCCM) to Intune
A governed, workload-by-workload move from Configuration Manager to Intune: co-management as the bridge, then updates, applications, compliance and configuration shifted in stages, collections mapped to Entra ID groups, and the on-premises infrastructure decommissioned once nothing depends on it.
What you get
- Co-management established as a safe transition state
- Workloads moved to Intune in governed stages, pilot rings first
- Applications repackaged and tested for Intune deployment
- Configuration Manager infrastructure decommissioned, with evidence
Engagement shape: Phased by workload; delivered standalone or as part of a wider Windows 11 transformation.
Management consolidated in one cloud console, with the server estate that supported it retired. For a London university we migrated management to Intune and decommissioned SCCM entirely inside a six-month window, as part of a full Windows 11 transformation.
Group Policy to Intune Migration
Evidence-based policy migration and re-engineering. We analyse every GPO you actually apply, separate the settings that matter from the accumulated dead weight, and re-engineer what remains as clean Intune configuration, rather than lifting decades of policy into the cloud unexamined. The analysis half is a discrete engagement in its own right: see Consultancy & Analytics.
What you get
- Full inventory of applied, redundant and conflicting policy
- Settings mapped to Intune settings catalog and CSP equivalents
- Security posture assessed against CIS, NCSC and Microsoft security baselines
- Legacy GPOs retired with a documented audit trail
Engagement shape: Analysis first, then migration by policy area with pilot rings; commonly a strand of a wider Intune transformation.
Policy you can read, test and roll back, in place of inherited sprawl. GPO-to-CSP migration was a core strand of a private bank's modern-management transformation, replacing twenty years of accumulated policy with a documented, security-framework-aligned Intune configuration.
Exchange & Microsoft 365 Migration
Phased, zero-disruption moves across the messaging and collaboration estate: unsupported on-premises Exchange onto Exchange Subscription Edition or Exchange Online, mapped drives and UNC paths onto OneDrive for Business, and governed cross-tenant access when a merger needs two organisations working together before the full consolidation.
What you get
- Migration design with clearly defined phases and joint responsibilities
- Phased mailbox and service migration with coexistence throughout
- OneDrive run book with tested scripts, rollback options and post-migration clean-up
- Cross-tenant collaboration configured and governed in days
- Legacy decommissioning
Engagement shape: Phased delivery planned around your third-party integrations and timeline; cross-tenant access typically live within days of discovery.
For a specialist IP law firm we delivered Exchange 2016 to 2019 to Subscription Edition with zero disruption to email service. A private bank's OneDrive migration ran from a piloted run book their own team executed, and a multi-academy trust used our cross-tenant access design twice as it merged with successive partner trusts.
Entra ID & Cloud-Native Device Transformation
The move from hybrid-joined, domain-dependent devices to a fully Entra-joined, cloud-native estate: identity and Conditional Access design, the right migration path for each device cohort (Autopilot reprovisioning or staged cutover), and the Active Directory dependencies that keep devices tethered identified and retired.
What you get
- Entra-joined target state and Conditional Access designed
- Active Directory dependencies (policy, print, file shares, legacy authentication) inventoried and unwound
- Per-cohort migration path with pilot rings and rollback
- Devices landed Entra-joined, managed entirely from Intune
Engagement shape: Dependency assessment first, then phased cohorts; often the closing phase of a wider transformation.
Cloud-native is the destination state of our flagship transformation above. We take estates there in phased, governed cohorts, with the evidence to show each domain dependency was retired rather than quietly left behind.