Centralized management of employees’ end devices as the basis of IT security transformation
Case from IT Security - End User Management (MDM)
Direction: IT Security
What business challenges needed to be solved?
The "Aesculab" IT team made a practical request: to provide centralized management of employees' corporate devices, to obtain the possibility of their immediate blocking in case of risks, and to increase the overall level of control over the IT environment, taking into account remote and hybrid work.
However, in the process of business analysis of needs, together with the Customer, we rethought this request and expanded it to the level of a strategic task – building a managed and secure IT environment. Thus, the point task of device management formed the basis for a systemic transformation of approaches to IT security and administration.
Business goals of the project
- Increasing the level of IT security, taking into account the remote and hybrid work of employees
- Increasing the level of corporate data protection
- Reduction of operating costs for servicing users of corporate information services
IT goals of the project
- Standardization of security configurations and policies
- Centralized management of end devices
- Automated control of the life cycle of devices
- Control of software installed on corporate devices
- Compliance Policy development and device compliance control (Compliance Management)
- Implementation of Zero Trust and Conditional Access
Zero Trust is at the heart of the target architecture
"Never trust, always verify" is the principle of the modern Zero Trust IT security model.
As part of the project, we developed:
- Device compliance policy (Compliance Policy)
- Device compliance control policy (Compliance Management)
- Conditional Access Policy
"Single-vendor platform" approach when choosing a solution
The basis of the solution is Microsoft Intune. When forming the architecture, we took into account that "Aesculab" already used Microsoft products for corporate communication. Further development of the security circuit within one vendor is a logical and strategically justified step.
Why choose Intune?
- Part of the Microsoft 365 ecosystem — lower integration risks and security architecture complexity compared to disparate MDM and IAM solutions
- Complies with the Zero Trust model and integrates with Microsoft Entra Conditional Access — access only from eligible devices
- Cloud service — scalability without capital costs, regular updates, without the need to maintain your own MDM infrastructure
- Remote Help — remote assistance without third-party programs, less time for administrators to access devices
Automation of key processes of the life cycle of the device
When the user mark crosses 200 corporate devices, it is worth thinking about automating the life cycle of devices. Microsoft Intune closes this task as well. In particular, we implemented:
- Zero-touch onboarding: Devices are automatically connected to the enterprise environment and receive policies through Microsoft Entra ID without the involvement of the IT team
- Centralized management and standardization: All devices follow the same security policies
- Compliance control: automatically check devices and restrict access in case of non-compliance
- Operational response: Remotely lock devices or restrict access in a few clicks
- Safe decommissioning: wipe/lock scripts to protect data when the device is released or lost
Results of the project
The whole project, from the express audit to the implementation of the decision, lasted 2 months. The implementation of the MDM solution based on Microsoft Intune was carried out in accordance with the planned scope of work and achieved the set IT and business goals.
- Centralized management of end devices (Windows, mobile devices) is provided
- Standardized security and configuration policies are implemented
- Implemented compliance control (Compliance Policy) and conditional access (Conditional Access)
- The key processes of the life cycle of the device are automated
Business value received by the Customer
- Increased operational efficiency by reducing the burden on the IT team
- The risks associated with the human factor and uncontrolled devices have been significantly reduced
- Instead of a point solution, a long-term strategic approach to IT security has been formed
Thank you to the "Aesculab" team for your trust.
Decision
-
1
Week 1-2
Express audit of the IT environment, risk assessment and determination of the target Zero Trust architecture.
-
2
Week 3–6
Deployment of Microsoft Intune, configuration of security policies, Compliance and Conditional Access.
-
3
Week 7-8
Device lifecycle automation, scenario testing, IT team handover and training.
Decision
-
Microsoft Intune
-
Office 365
-
Microsoft Entra
About the company:
-
Branch:
Laboratory studies
-
Company size:
800+ specialists
-
Location:
Lviv, Ukraine
Tell us about your project
Briefly describe your request or idea - we will promptly respond and offer the optimal solution.