Field notes for people who manage things
Practical, tested guides on endpoint management, MDM and the messy realities of running a real device fleet. Figured out properly the first time, so nobody has to work it out twice.
Read the guides →Every command and configuration here was run on a real machine, not pasted from a forum and hoped for. Where something behaved unexpectedly, that is written down too.
Mixed fleets are normal. Guides cover Jamf and Intune side by side where it matters, so you are not left translating between them yourself.
The useful part of any guide is usually the thing that went wrong. Conflicts, surprises and "why is it doing that" all get their own section.
Latest guide
A staged set of standalone runbooks for moving an Apple silicon fleet off Jamf. Audit what you actually enforce and watch two dozen profiles collapse into three, enrol cleanly via no-affinity ADE, and enforce FileVault so the key genuinely escrows. Written wart-and-all, including the day the recovery key vanished from the console and the command that proved the disk was fine.
Enabling FileVault by policy so it actually escrows, why a break-glass admin is always visible at the pre-boot screen whatever you do, and the compliance password setting that silently desyncs the encryption credential and locks you out of your own fleet.