Endpoint management
Device management, patching and bring your own device access
A practical ownership model for business devices, personal devices, updates, access and offboarding.
The first control is knowing which devices can access business data and who is responsible for them. Choose corporate ownership, managed personal access or browser-only access deliberately. Then apply a supported operating system, timely updates, encryption, screen lock, security tooling and a tested removal path.
From day-to-day administration
Details worth settling early
Choose the control plane the team can operate
Intune can be a natural fit where Entra ID, Microsoft 365 licensing and device compliance already form the centre of administration. An established ManageEngine environment may remain sensible where its packaging, reporting and support routines are working. Migration effort and operator familiarity belong in the comparison.
Personal devices need an exit path
Before permitting personal devices, decide how business access is removed, what company data can be selectively wiped, what the business can see and what happens when a device is lost or the employee leaves.
Design choices that matter
- Bring your own device (BYOD) arrangements combine access, privacy, support and employment considerations with device cost.
- Patch reporting needs coverage and unresolved exceptions alongside the configured schedule.
- Offboarding must remove tokens, application access and local data where the chosen model allows.
- Microsoft Intune can suit a Microsoft-centred environment; an established platform such as ManageEngine may remain the better control plane when it already covers the required devices and workflows.
How to approach the work
- 01
Inventory access
Identify devices, owners, operating systems, management state and the business services each can reach.
- 02
Choose device classes
Define what requires a corporate device, what can use managed personal access and what can remain browser-only.
- 03
Set a minimum baseline
Require supported software, encryption, screen lock, update reporting, malware protection and appropriate multi-factor authentication.
- 04
Pilot management
Test enrolment, application deployment, privacy visibility, support, lost-device response and removal.
- 05
Operate lifecycle
Review patch exceptions, stale devices, ownership changes and retirement on a regular schedule.
What to test before handover
- Access inventory complete
- Device classes approved
- Privacy notice issued
- Patch evidence available
- Lost-device process tested
- Offboarding removes access
- Retirement documented
Problems to catch early
- Requiring intrusive control of personal devices without clear notice
- Reporting patch success while unmanaged devices remain invisible
- Allowing departed staff to retain synchronised files or active tokens
Useful technical references
- Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide
- Australian Signals Directorate, Australian Cyber Security Centre — Essential Eight explained
- Microsoft Learn — Planning guide to move to Microsoft Intune
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.