The Work
I manage devices from the moment they’re assigned to someone until they’re decommissioned. That means enrollment, baseline configuration, ongoing compliance monitoring, and cleanup when the device goes back into inventory. I push configuration profiles, monitor for compliance drift, support both mobile and standard endpoints, and help with OS deployment when new machines arrive.
The goal is straightforward: devices need to be enrolled, configured correctly, and compliant from day one through retirement. But they also need to stay usable for the person sitting in front of the screen. Policies that users can’t meet aren’t policies - they’re noise.
Why It Matters
An unmanaged device is a security gap waiting to happen. A misconfigured device becomes a support burden. And a device with impossible compliance requirements creates friction that makes users resent the whole system. My job is to find the middle ground: strict enough to be secure, flexible enough to be usable.
The hard part isn’t the technology. It’s the discipline. Enrollment gets solid. Baselines get deployed consistently. Compliance policies stay reasonable. When something fails compliance, I fix the device, not fight the user.
What I’ve Learned
Get enrollment and baselines solid first. Complex compliance rules on a shaky foundation just create tickets and frustration. I’ve learned that the best policies are the ones nobody notices because they just work. And I’ve learned that spending time helping users understand why a policy matters beats fighting them on enforcement.