Quick Summary
Manual device setup is time-consuming, consumes IT resources, slows down onboarding for new hires, and creates security risks due to inconsistent configurations. This article unpacks how IT teams can configure devices and how device subscription providers like Devices for Teams can help your company automate the configuration process before deployment.
Is Your IT Team Still Setting Up Laptops One by One?
In January, a Manchester-based marketing agency hired twelve new staff members. Then their IT Manager had to spend nearly two weeks configuring laptops, troubleshooting the many failed configurations, and sending devices back and forth to resolve issues encountered during remote setup attempts.
This is an ongoing problem for most UK businesses. Since 30% of their employees are now required to split their time between home and office, the “walk over and fix it” approach is no longer viable. Remote teams require machines that function from day one.
Configuring a device means undertaking as much of this technical work as possible before employees can access the machine and begin work. If you bundle the configuration process into a laptop subscription model, the £25,000 upfront hardware cost will be replaced by the certainty of regular monthly payments.
Why Trust Us?
Devices for Teams has worked with thousands of companies for more than 40 years. Our 4.9 Trustpilot rating (based on 1000+ customer reviews) reflects the many satisfied customers who have used our services, and it demonstrates the high level of trust we have established with them.
In addition to procurement and secure disposal, we manage all aspects of the device lifecycle, including configuration, so your team can focus on other matters.
What Is Device Configuration?
Device Configuration is the process of setting up laptops, desktops, tablets, and mobile phones for employee use when they leave the business. This creates the foundational technology required for the device to be functional, not consumer-friendly.
The configuration of a device has multiple layers, with security as the first layer; full-disk encryption, endpoint protection, firewalls, and auto-patching are included within this layer to protect company information, whether employees are working at home or at the kitchen table.
Secondly, access is configured, including single sign-on, two-factor authentication, VPN, and Wi-Fi connection settings. Employees will have all the tools they need once they log in to their account and will not need to submit an IT ticket to perform their job.
Productivity is the third layer, which can include applications installed on the device, email accounts set up, cloud storage syncing, etc. — there is no friction between unboxing the device and actually using it for the employee.
Lastly, each device must enrol in a Mobile Device Management (MDM) system. The MDM provides IT with complete visibility and control over the entire device fleet, even when devices are in different physical locations.
Why Does Device Configuration Matter?
1. Security Starts at Setup
The IBM Cost of a Data Breach Report has shown that a Remote Work environment increases the cost of a breach. All devices that leave the warehouse are at risk for having gaps in their security configuration from day one. Encryption may be turned off on the device, endpoint protection may not be configured, and firewall rules may be set to Consumer-Friendly instead of Business-Secure.
The first step in eliminating these risks is to properly configure them before they are delivered to users. Each Laptop leaves our warehouse with encryption enabled, protection software installed, and security policies being enforced. This enables the IT department to remotely locate, lock, or wipe a lost or stolen device using an MDM solution.
2. Productivity Gains Are Immediate
Any time employees spend trying to get their computers set up is time they aren’t getting work done. For companies that hire 50 employees per year, these hours add up fast. If each new employee wastes half a day due to problems with devices, it’s estimated that you’re losing 200 hours of employee productivity.
Using pre-configured devices reverses that.
3. IT Teams Get Their Time Back
Manually setting up devices is an arduous and redundant task that keeps IT employees from working on actual projects that generate revenue for the organisation. If your system administrators spend three days a month manually deploying images to laptops, they are spending those same three days on something other than improving infrastructure or auditing security.
At scale, configuration enables IT to focus on more important tasks rather than on configuring hardware and software.
4. Remote and Hybrid Work Actually Works
Distributed teams rely on devices working properly without remote support by a technical specialist; you can’t ask someone based in Edinburgh to send their laptop to London for repair. Zero-touch deployment is designed to address the above issue.
When shipped to employees’ homes from configuration centers, devices are already enrolled in MDM (Mobile Device Management) and include all necessary applications. When powered on for the first time, the device downloads its last configuration and displays a fully functional workspace.
5. Consistency Across the Fleet
Without configuration standardisation, over time, each new device will be set up differently; one laptop may have slightly different security settings than another. An unauthorized application was added to one of them. It creates a headache for support and a potential security gap due to inconsistent device configurations.
Configuration profiles ensure that all machines are configured identically, regardless of the role or position. If there is a problem with a machine, the IT department will know exactly which machine(s) are affected rather than guessing at their state.
How to Prepare for Device Configuration
1. Define Your Deployment Standards
Before you touch any device, be clear on what configured means for your organisation. What applications do each department need to work with? What security settings will satisfy compliance requirements in your organisation? What level of network access will remote workers need as opposed to office-based staff?
A documented deployment standard will ensure that configurations are consistent, no matter if you’re setting up five devices or fifty, and it provides the person responsible for setting up your devices with a clear brief to work from. Without it, you’ll have a fragmented fleet where every laptop is slightly different.
2. Map Roles to Profiles
Different roles require different setups. What a developer uses on their laptop is very different from what a sales representative uses. The finance department will have a different software and application setup from the design and development teams.
Create separate configuration profiles for the most common role types. Begin by creating a base profile that includes all security requirements and the most commonly used applications across your organisation. Then create additional configurations based on each employee’s unique role.
3. Choose Your MDM Platform
Your Mobile Device Management (MDM) solution will be the platform for managing the ongoing lifecycle of your devices and configuring them. The key is understanding your mobile ecosystem.
If you are in an Apple environment, then your devices can be enrolled in Apple Business Manager and then paired to an MDM Solution such as Jamf or Shepherd. Both provide similar functionality, but Jamf costs about 10% more than a Shepherd MDM Solution.
If you have a Windows environment, then Microsoft Intune will integrate with your Azure Active Directory and your Microsoft 365 accounts.
If you have Samsung Android devices, they will have access to Samsung Knox, which provides a way to containerise data so employees can keep their personal data separate from company data.
4. Start With a Smaller Rollout
When you’re implementing new configurations or moving to a new MDM platform, do not update all devices at once. Test a small group of users from various job titles and locations before you roll it out.
What works perfectly in your London office may fail for someone using a different internet service provider (ISP) in Leeds. Troubleshooting an issue with five devices is much simpler than fixing fifty. Once you have solved your problem, then expand.
Steps to Implementing Device Configuration
1. Build Your Configuration Profiles
Configuration Profiles are where you set up the real settings that get sent to your devices. Most organisations will have at least three configuration layers.
There is a base layer that covers all security fundamentals, from encryption and endpoint protection to firewalls and patches – and it is applied to all devices regardless of user role.
Then there are department profiles that provide users with specific application capabilities. Finally, there are compliance profiles that are used to enforce regulatory standards applicable to your organisation. Healthcare organisations will also require configurations that support their legal and regulatory obligations regarding data protection.
2. Enrol Devices in MDM
New devices need to register with your MDM system before you can deploy them. This registration connects each device to your management console, allowing you to send configuration settings and remotely monitor compliance with them.
With zero-touch deployment, enrollment will occur automatically. The first time an employee powers on a laptop, it will pull down its assigned configuration profile without any manual intervention from the user.
3. Deploy to Users
With user profiles built and employee devices registered with the organisation, the deployment is scalable. Office-based employees have the appropriate devices at their workstations and are ready for use upon arrival. Remote employees will receive pre-configured laptops shipped directly to their home address.
The overall IT onboarding experience is greatly simplified. Employees can now receive a device that is ready to work the moment they log-in; this eliminates the need for IT to spend an excessive amount of time (hours) processing each new hire.
4. Monitor and Maintain
Configuration does not stop after deployment; for devices to remain secure and compliant, ongoing management is required. Your MDM dashboard is where you can view the status of your entire fleet, including which devices are non-compliant or missing required security updates.
Your Security Policies will need to be updated periodically to keep pace with evolving threats. As an employee changes positions or departments, some devices will need to be reconfigured.
5. Plan for End of Life
Devices will need to be replaced at some point; however, they typically contain company data that you want to keep under your control.
D4T’s Boomerang Service manages device retrieval and safe destruction of the devices. When an employee is leaving, or it is time to replace a device, D4T will send a secure, protective collection crate to the employee.
After receiving the device, D4T will erase all information from the device and either recycle it responsibly or refurbish it for use by another employee. D4T allows returned devices to be reused as new devices by other employees, reducing hardware spend and extending the device’s useful life.
Build a Device Configuration Method That Scales
Every manual configuration your IT team performs is time that could be spent on work that drives real business progress. Every single laptop that comes in with issues can mean another employee has to spend their first few weeks waiting instead of contributing.
Devices for Teams manages configuration end-to-end (MDM enrolment, security configurations, app deployments), delivers devices directly to employees’ home offices or remote work locations, and, when an employee leaves, Boomerang retrieves the laptop and wipes it clean.
Your devices will be ready for work as soon as you turn them on.
Book a consultation and let us sort out your fleet.
Andrew Morgan is Co-Founder of HardSoft Computers, where he’s spent over 30 years driving innovation in tech leasing. With a focus on making IT solutions flexible and accessible, Andrew leads strategy across product development, SEO, and digital marketing.
He’s passionate about helping businesses thrive with the right technology and regularly shares insights on the HardSoft blog.
LinkedIn: Andrew Morgan
Email: [email protected]