Skip to main content
O-Digital O-Digital
EN

Centralized management of employees’ end devices as the basis of IT security transformation

Case from IT Security - End User Management (MDM)

Centralized management of employees’ end devices as the basis of IT security transformation

What business challenges needed to be solved?

The "Aesculab" IT team made a practical request: to provide centralized management of employees' corporate devices, to obtain the possibility of their immediate blocking in case of risks, and to increase the overall level of control over the IT environment, taking into account remote and hybrid work.

However, in the process of business analysis of needs, together with the Customer, we rethought this request and expanded it to the level of a strategic task – building a managed and secure IT environment. Thus, the point task of device management formed the basis for a systemic transformation of approaches to IT security and administration.

Business goals of the project

  • Increasing the level of IT security, taking into account the remote and hybrid work of employees
  • Increasing the level of corporate data protection
  • Reduction of operating costs for servicing users of corporate information services

IT goals of the project

  • Standardization of security configurations and policies
  • Centralized management of end devices
  • Automated control of the life cycle of devices
  • Control of software installed on corporate devices
  • Compliance Policy development and device compliance control (Compliance Management)
  • Implementation of Zero Trust and Conditional Access

Zero Trust is at the heart of the target architecture

"Never trust, always verify" is the principle of the modern Zero Trust IT security model.

As part of the project, we developed:

  • Device compliance policy (Compliance Policy)
  • Device compliance control policy (Compliance Management)
  • Conditional Access Policy

"Single-vendor platform" approach when choosing a solution

The basis of the solution is Microsoft Intune. When forming the architecture, we took into account that "Aesculab" already used Microsoft products for corporate communication. Further development of the security circuit within one vendor is a logical and strategically justified step.

Why choose Intune?

  • Part of the Microsoft 365 ecosystem — lower integration risks and security architecture complexity compared to disparate MDM and IAM solutions
  • Complies with the Zero Trust model and integrates with Microsoft Entra Conditional Access — access only from eligible devices
  • Cloud service — scalability without capital costs, regular updates, without the need to maintain your own MDM infrastructure
  • Remote Help — remote assistance without third-party programs, less time for administrators to access devices

Automation of key processes of the life cycle of the device

When the user mark crosses 200 corporate devices, it is worth thinking about automating the life cycle of devices. Microsoft Intune closes this task as well. In particular, we implemented:

  • Zero-touch onboarding: Devices are automatically connected to the enterprise environment and receive policies through Microsoft Entra ID without the involvement of the IT team
  • Centralized management and standardization: All devices follow the same security policies
  • Compliance control: automatically check devices and restrict access in case of non-compliance
  • Operational response: Remotely lock devices or restrict access in a few clicks
  • Safe decommissioning: wipe/lock scripts to protect data when the device is released or lost

Results of the project

The whole project, from the express audit to the implementation of the decision, lasted 2 months. The implementation of the MDM solution based on Microsoft Intune was carried out in accordance with the planned scope of work and achieved the set IT and business goals.

  • Centralized management of end devices (Windows, mobile devices) is provided
  • Standardized security and configuration policies are implemented
  • Implemented compliance control (Compliance Policy) and conditional access (Conditional Access)
  • The key processes of the life cycle of the device are automated

Business value received by the Customer

  • Increased operational efficiency by reducing the burden on the IT team
  • The risks associated with the human factor and uncontrolled devices have been significantly reduced
  • Instead of a point solution, a long-term strategic approach to IT security has been formed

Thank you to the "Aesculab" team for your trust.

Decision

  • 1

    Week 1-2

    Express audit of the IT environment, risk assessment and determination of the target Zero Trust architecture.

  • 2

    Week 3–6

    Deployment of Microsoft Intune, configuration of security policies, Compliance and Conditional Access.

  • 3

    Week 7-8

    Device lifecycle automation, scenario testing, IT team handover and training.

Decision

  • Microsoft Intune

    Microsoft Intune

  • Office 365

    Office 365

  • Microsoft Entra

    Microsoft Entra

About the company:

Medical laboratory "Eskulab" is a leading laboratory of the international level of diagnostic research quality in Lviv with the largest network of branches in the west of Ukraine. The network has more than 150 departments where patients can receive more than 2,000 laboratory tests in the fields of clinical chemistry, immunology, bacteriology, molecular genetics and cytomorphology.
  • Branch:

    Laboratory studies

  • Company size:

    800+ specialists

  • Location:

    Lviv, Ukraine

Tell us about your project

Briefly describe your request or idea - we will promptly respond and offer the optimal solution.

0/2000

By submitting this form, I agree that O-Digital will process my personal data in accordance with Privacy policies.

Budget:

Preferred method of communication

When it is convenient to contact you

The file must not exceed 20 MB.