guideonce.

About

Field notes from a mixed-fleet IT admin

Real write-ups of real problems, from someone who does this for a living. Written down once, so nobody has to work the same thing out twice.

guideonce is a collection of technical guides written by a working IT administrator who spends their days running a mixed estate: Macs managed through Jamf, Windows through Intune, and the Active Directory and Microsoft Entra identity plumbing that ties it all together. The guides come out of actual work, the kind of problem you get handed on a Tuesday and have to have solved by Friday, rather than out of a content calendar.

The name is the whole idea. Most of these problems get solved once by someone, quietly, under pressure, and then the knowledge evaporates. The next person (often the same person, eighteen months later) starts from scratch, re-reading the same scattered forum threads and half-right vendor docs. This site is an attempt to write the thing down properly the first time, in enough detail that it helps, so it does not have to be figured out again.

What this is

Practical, tested walkthroughs of endpoint management, device security, and identity, aimed at the person doing the work. Where a guide covers both Jamf and Intune, it is because real fleets are mixed and translating between the two yourself is tedious. Where something behaved unexpectedly in the real world, that surprise is written down too, because the useful part of any guide is usually the bit that went wrong.

What this is not

It is not vendor marketing, and nothing here is sponsored. It is not a substitute for official documentation, which is more complete, more current, and correct about the things that change weekly. And it is not exhaustive: it covers the things that have come up in practice and been worth the effort of writing down, not every feature of every product. Treat it as a knowledgeable colleague's notes, not a specification. Always test in your own environment before rolling anything out to a fleet.

Why it is anonymous

The guides are written without a name attached, and that is deliberate. Writing anonymously means being able to be honest about what actually breaks, including the mistakes, the dead ends, and the workarounds that are not in anyone's best-practice guide. Every guide here is scrubbed of anything identifying. The point is to share what works, and what does not, as candidly as possible.

Consulting and contact

The site is free and always will be. If your organisation needs hands-on help with any of this (mixed-fleet management, Jamf or Intune, FileVault and encryption at scale, Active Directory or Entra identity work, or a migration you would rather not do alone) the author is available for consulting and contract work.

hello@guideonce.co.uk

The principles behind every guide

← Read the guides