Defined implementation

Set up and manage company laptops through Intune.

Configure the agreed enrollment process, policies, applications and update groups. Test them on pilot devices before the wider rollout.

PricePrice fixed after a short scope call.

Delivery6 to 8 weeks

What you receive · illustrative sample

See what a delivered device has to pass.

Illustrative deployment matrix. Platform, applications and pilot groups are agreed before rollout.

CheckPilot acceptanceOwner keeps
EnrollmentDevice joins the intended tenant and groupEnrollment instructions
ApplicationsInstall, detection and uninstall testedApplication/dependency register
Encryption and complianceKey escrow and agreed compliance verifiedPolicy reference and results

Related delivery record

Intune application packaging and Azure permissions work

Read what changed and how it was checked ↗

Engagement context

When this engagement applies.

Devices are unmanaged, or set up differently from each other. Some need a controlled move into Intune before the Windows 10 paid update rate rises on October 14, 2026.

Scope considerations

  • Windows-first standard scope
  • Cloud-native Entra join
  • Client owns fleet-wide coordination

The defined work

Engagement scope.

  1. 01

    The device fleet is inventoried: what exists, what is enrolled, and what reaches company data unmanaged.

  2. 02

    The enrollment path is built so a new device arrives already configured, with Autopilot where the design calls for it.

  3. 03

    Compliance and configuration policies, the required application set, and update rings are deployed as one bounded standard.

  4. 04

    A pilot ring enrolls first, and the defects that only appear with real users are found and closed there.

  5. 05

    The administrator takes over a documented standard with the rollout plan for the remaining fleet.

Acceptance

Completion has an agreed standard.

Done when pilot devices enroll, receive the expected configuration and applications, report the agreed compliance state, and pass user tests.

  • Compliance, configuration, and security baseline policies are deployed

  • BitLocker and recovery-key escrow are configured

  • Update rings and the standard application set are in place

  • The pilot group is enrolled and passes the named compliance tests

  • The administrator has been walked through the handoff documentation

Commercial basis

Price, scope and timing are considered together.

Engagement price

Price fixed after a short scope call.

The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:

What determines the scope

  • Device count and platform mix
  • Number of applications in the standard set
  • Existing management dependencies to check before a cloud-native deployment; migration from another MDM is quoted separately
  • Enrollment complexity and number of Autopilot profiles

Delivery calendar

6 to 8 weeks

How engagements work

Scope & responsibilities

The full engagement boundary.

Review the exclusions, required client participation, change controls and operational handover for this engagement.

Exclusions
  • Custom application packaging is separately scoped by application, installer, dependencies and acceptance tests
  • Individual device repair
  • Onsite support
  • Broad user training
  • Ongoing endpoint management
  • SCCM, GPO, or third-party MDM migration is separately scoped after dependency review
Client responsibilities
  • Own fleet-wide user coordination and scheduling
  • Provide the standard application list and installers
  • Own end-user support and help-desk activity
  • Approve the pilot group and change windows
Change and rollback method
  • A pilot group is set up before any wider rollout, and each policy is tested there first.
  • Policies are staged by assignment group; rollback is unassignment, per policy, within one change window.
  • Update rings are configured so the business chooses its exposure to each release, and nothing forces a reboot mid-shift.
Operational record and handover
  • The device inventory with enrollment and compliance state, before and after
  • The policy and baseline configuration as an as-built
  • Pilot test results, including the user tests
  • The rollout runbook for the remaining fleet

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Discuss this engagement

Put the scope in context.

Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.

Scope the Intune Deployment