Why We Had to Move Away From SCCM
SCCM (now Microsoft Endpoint Configuration Manager) is a powerful tool. It's also a tool built for a world where everyone works in the office, on a corporate network, with a wired connection.
By 2021, at a multinational IT environment, that world was gone. Users were working from home, from client sites, from airports, from anywhere. SCCM's agent-based, on-premises-first model was straining under the pressure.
The deciding factors that pushed us toward Modern Management:
SCCM vs. Modern Management — Key Differences
| Factor | SCCM | Intune + Autopilot |
|---|---|---|
| Device provisioning | Manual image + IT setup | Zero-touch, user self-enroll |
| Remote management | VPN required | Cloud-native, no VPN needed |
| New device setup time | 2–4 hours with IT present | 45 min, user does it themselves |
| Compliance visibility | On-network only | Real-time, anywhere |
| Infrastructure required | SCCM servers, WSUS, SQL | Zero on-premises footprint |
The 90-Day Rollout Plan
Phase 1 — Foundation (Weeks 1–3)
Before enrolling a single device, I spent 3 weeks on:
1. Azure AD Group Structure
IT-Intune-Pilot (10 IT team members first)
IT-Intune-Wave1 (50 users, low-risk)
IT-Intune-Wave2 (100 users, standard)
IT-Intune-Wave3 (50 users, executives — last)
2. Compliance Policy Baseline
- Minimum OS version (Windows 11 22H2+)
- BitLocker encryption required
- Defender real-time protection required
- Password complexity required
3. Conditional Access — Report-Only Mode Critical step: set CA policies to report-only for 2 weeks before enforcing. This shows you who would have been blocked — before you actually block them.
Phase 2 — Pilot (Weeks 4–6)
Ten IT team members enrolled first. We ate our own cooking. Key findings:
- Two users had unsupported OS versions → update required before migration
- Company Portal had missing apps → added 6 more software packages
- BitLocker recovery key escrow not working → fixed Azure AD integration
Always run a pilot with your own team first. Never with executives. If things break, fix it before real users see it.
Phase 3 — Phased Rollout (Weeks 7–11)
Wave-by-wave enrollment:
| Wave | User Count | Duration | Key Consideration |
|---|---|---|---|
| IT Team | 10 | Week 4–6 | Testing + learning |
| Low-risk users | 50 | Week 7–8 | Comfortable with tech |
| Standard users | 100 | Week 9–10 | Bulk rollout with FAQ |
| Executives | 50 | Week 11 | White-glove only |
For each wave, I sent a pre-enrollment email:
"On [date], your device will be enrolled in our new IT management system. This takes 20 minutes and you don't need IT present. Here's what to do: [link to guide]. If you have any issues, call me directly."
The direct number in the email was critical. It gave users confidence and stopped tickets from being raised for every small question.
Phase 4 — macOS with JamF (Parallel Track)
macOS devices went through JamF, not Intune, because JamF provides much deeper macOS management. The JamF enrollment is simpler:
- User opens System Preferences → Management Profile
- Downloads and installs the corporate MDM profile
- JamF runs automated policy — installs required apps, enforces FileVault
- Done in 15 minutes
JamF apps deployed automatically:
- Required corporate software bundle
- Microsoft Office for Mac
- Defender for Endpoint (macOS)
- VPN client
- OneDrive
Phase 5 — iOS and Android MDM
For mobile devices, we used Intune Company Portal:
- User installs Company Portal from App Store/Play Store
- Enrolls with corporate credentials
- Conditional Access enforced — corporate email only on enrolled devices
The key policy decision: we did NOT enforce MDM on personal devices. We gave users the choice — enroll your personal device and get corporate email, or carry two devices. Most chose to enroll. Some chose two devices. Both options were respected.
The Mistakes I Made (So You Don't Have To)
Mistake 1: Deploying Conditional Access Without Report-Only First
I did this in a previous role. Blocked 30% of users from email on a Monday morning. Never again. Always run report-only for 2 weeks minimum.
Mistake 2: Not Communicating the "Why" to Users
Users react badly to their devices being "managed" if they don't understand why. The explanation that worked best:
"This protects you and the company. If your laptop is lost or stolen, we can remotely wipe it so your data stays safe. If your device gets malware, we can detect and respond before it spreads."
Frame it as protection for the user, not control by IT.
Mistake 3: Not Planning for the Exceptions
Some users had legitimate exceptions — medical devices, specialist software, unusual hardware. Build an exceptions process before you start, not after. Unplanned exceptions during a rollout cause delays and frustration.
Post-Migration Results
After 90 days, the results across a few hundred devices:
◆ Before vs After Modern Workplace Rollout
The 90-day timeline was aggressive but achievable. The key was the phased approach and the pilot-first mentality.
Modern device management is not optional in 2026. It's the foundation of enterprise security.
◆ Pro Tips
- ▸ Always run your Conditional Access policies in report-only mode for 2 weeks before enforcing — this reveals who would be blocked without any user impact.
- ▸ Start your Intune pilot with the IT team — run every policy on yourselves first so you catch configuration issues before they affect business users.
- ▸ Roll out to executives last, not first — by the time they enroll, your process should be smooth and your helpdesk documentation complete.
- ▸ Frame MDM enrollment to users as data protection, not IT surveillance — "if your laptop is stolen, we can wipe it remotely" is far more compelling than "we're deploying policy compliance."
- ▸ Use JamF for macOS instead of Intune — deeper macOS policy control, simpler enrollment, and better compatibility with Apple-specific management features.