What we have learned running fleets
Working notes from the environments we assess, migrate and operate. No gated whitepapers, no vendor press releases — just the things we find ourselves explaining repeatedly.
New to the acronyms? Our glossary defines MDM, UEM, MTD, the Essential Eight, IRAP and PROTECTED in plain English — including the distinctions that get blurred in procurement.
More insights
Procurement is where mobile rollouts actually stall
The technical work on a fleet refresh is rarely what delays it. The delay is in how the devices were bought, and it is almost always avoidable.
"Hosted in Australia" is not the same as sovereign
Data residency, data sovereignty and operational sovereignty are three different claims. Most vendor answers only address the first one.
Conditional Access without locking everyone out
The control is straightforward. Deploying it without an outage takes report-only mode, break-glass accounts and a rollout order most people get backwards.
Intune or Ivanti? Choosing an MDM platform you will still like in three years
The honest comparison, from a partner that runs both in production for Australian government. Where each one wins, and the questions that actually decide it.
Protective markings break the moment mail reaches a handset
The desktop enforces the marking. The phone treats it as text in a subject line. That asymmetry is why so many agencies still classify their mobile mail down.
Carrier DEP, explained — and why so few resellers can do it
Zero-touch enrolment only works if the device is in Apple Business Manager. Carrier DEP is how carrier-supplied iPhones get there, including ones you already own.
Zero trust for mobile, past the slide
The architecture is well described and rarely implemented on the fleet. Four things have to be true on a handset before the model means anything.
Retention is not backup — what Microsoft 365 does not protect
Microsoft protects the platform. Protecting your data in it is your responsibility, and the gap only becomes obvious at the worst possible moment.
What a contact list gives away
Nobody classifies the address book, and on a government handset it is often the most sensitive thing on the device. Here is what leaks and how.
The Essential Eight leaves your phones out — and everyone knows it
The ACSC mitigation strategies were written for a desktop fleet. Here is what happens to the mobile estate in the gap — and how to close it.
The SOCI obligation reaches further into IT than most operators assume
Critical infrastructure risk programs concentrate on operational technology. The corporate endpoint that reaches into it is usually nobody's responsibility.
Wi-Fi problems are usually density problems
Adding access points to fix a slow network usually makes it slower. What is actually wrong is almost always capacity, channel planning or backhaul.
What Maturity Level Two actually asks of a mobile fleet
The Essential Eight maturity model was built around workstations. Translating each level to a mobile estate is possible, and nobody has written it down for you.
Build or buy: the four questions that actually decide it
Custom software is usually the wrong answer and occasionally the only one. These are the questions that tell you which case you are in.
Mac in a Windows shop — what actually has to change
The Macs are already there. Managing them properly is less work than most Windows-first IT teams expect, and different in ways worth knowing in advance.
Migrating off Ivanti EPMM without wiping a single device
The fear that stops most EPMM migrations is that every handset has to be factory reset. It does not. Here is how a low user impact migration actually runs.
Declarative device management is quietly replacing the MDM you know
Apple is moving management from commands a server pushes to declarations the device enforces itself. What changes, and what to ask your MDM vendor.
Designing a network for a site nobody visits
Remote and unattended sites break the assumptions of office network design. What matters is not throughput — it is what happens when something fails at 2am.
Choosing a managed service provider for Australian government work
Sovereignty, personnel vetting, procurement pathways and the certification claims that get blurred. What public sector buyers should check before signing.
Changing managed service provider without an outage
Transition is the riskiest part of any managed services contract and the part nobody plans in detail. What a controlled handover actually involves.
MDM is not mobile security
Device management tells you a handset complies with your policy. It does not tell you the handset is being attacked. That gap matters.
Smishing works because a phone is a worse place to be careful
The same person who spots a phishing email at their desk taps the link on their phone. That is not a training failure — the device is structurally worse at this.
How to decide whether an app belongs on a government phone
App approval is usually a yes or no made by whoever was asked. A repeatable assessment takes about twenty minutes and produces a decision you can defend.
BYOD, COPE or corporate-owned: choosing an ownership model
The ownership model decides your privacy position, your cost base and how much control you actually have. Most organisations pick it by accident.
Twelve questions to ask a managed service provider before you sign
Most MSP proposals look identical on paper. These are the questions that separate them — including the ones we would rather you did not ask us.
Jamf or Intune for a Mac fleet?
Both manage Macs properly now. The decision is about how deep your Apple requirements go and who is going to operate the platform.
What a mobile fleet actually costs, and where the money goes
The device price is the smallest line. Here is the full cost of running a managed mobile fleet, including the parts that never appear in a business case.
Offboarding is a security control, and it is usually the weakest one
Onboarding gets a checklist, an owner and a deadline. Departure gets an email. The access that survives a departure is the access nobody is watching.
What you are probably paying for twice in Microsoft 365
Most organisations run third-party tools that duplicate something already included in the licence they hold. Here is where the overlap usually sits.
Android Enterprise has four management modes and you probably want two
Work profile, fully managed, fully managed with work profile, dedicated. Which one applies decides what you can enforce and what you can never see.
The most common cause of a fleet outage is an expiry date
Almost every total loss of MDM control we have been called into was a certificate or token that lapsed. It is the most preventable outage in mobility.
What a real disaster recovery test looks like
A backup job reporting success proves the job ran. It proves nothing about whether you can recover, how long it takes, or whether the data is usable.
Service desk metrics that actually mean something
First response time is the easiest metric to hit and the least useful. These are the numbers that tell you whether a service desk is any good.
Want this applied to your environment?
Most of what we write here started as a finding in an assessment. If any of it sounds familiar, that is usually a good reason to have one.