Role and Project Details:
The Business Analyst II / Communications Resource will support the implementation of Microsoft Intune for Windows and macOS devices, including enrollment, policy configuration, application deployment, and end-user readiness. This role will work closely with technical teams, project stakeholders, and end users to ensure a smooth rollout of Intune and Autopilot across Windows, macOS, iOS, and Android.
The environment includes:
• Intune for Windows, macOS, iOS, and Android (corporate-owned and BYOD)
• Enrollment via Automatic Enrollment (Windows) and Apple Business Manager/Configurator (macOS)
• Central management of settings, security, and applications
• Use of the Company Portal for user-driven actions
________________________________________
Key Responsibilities
1. Project Kickoff & Coordination
• Help review and confirm project objectives and scope.
• Support the creation and maintenance of:
o Project plan, activities, and milestones
o Stakeholder and contact lists
o Remote connectivity requirements
o Review meeting agendas and schedules
• Assist in documenting the current state:
o Existing Intune and MECM deployments
o Device models in scope (Windows, macOS, iOS, Android; corporate-owned and BYOD)
o Current Intune applications and Blackberry Enterprise Server (BES) configuration.
2. Design & Planning Support
Work with the technical team and business stakeholders to capture and document:
Intune & Autopilot Design
• Compliance requirements.
• Features and configurations to be implemented.
• Branding and end-user experience requirements.
• Enrollment and registration needs (Windows and macOS).
• MDM policies and device configuration.
• Security, compliance, and Conditional Access requirements.
• Application packaging, deployment, and update strategy.
• Windows feature and driver update approach.
• Device compliance and reporting needs.
• MFA, PIN, and other device security requirements.
• Intune automatic enrollment setup.
• macOS integration with Apple Business Manager.
• MECM co-management needs.
Autopilot Design
• Azure AD automatic enrollment profiles.
• Enrollment Status Page behavior.
• Automatic and pre-provisioned deployment profiles.
• Zero-touch deployments (Entra join).
• Self-Deploying Mode configuration.
• Reporting and alerting requirements.
• Access requirements for on-premises Active Directory resources.
Intune Design
• Troubleshooting and support processes.
• Device enrollment flows for:
o Windows
o macOS
o iOS
o Android
• Apple Business Manager integration.
• Application configuration and deployment for:
o Windows
o macOS
o iOS
o Android
• Reporting needs:
o Device management
o Endpoint security
o Analytics
• Windows Update (update rings).
• Application protection (MAM) and device compliance policies.
• App packaging requirements (Windows: .msi/.exe; macOS: DMG).
• Hybrid Entra AD/co-management requirements.
• Onboarding/offboarding from BES.
The BA will help structure and document all of the above into clear design and process documentation.
________________________________________
3. Implementation Support
The technical implementation will be led by Insight’s engineers and architects. The Business Analyst II / Communications Resource will:
For Windows Autopilot (Zero Touch):
• Track and document:
o Implementation of up to 10 applications (.msi or .exe).
o Configuration of up to 4 device groups and up to 2 personas.
o Driver updates for up to 4 device models.
o Software updates configuration and deployment to one Intune group.
• Support creation of clear instructions for:
o Hardware device hash collection.
o Windows 11 device enrollment processes.
For Windows Autopilot Self-Deploying Mode:
• Document:
o Device group creation.
o Profile creation with “Self-deploying” mode.
o Configuration of language, location, keyboard, and network.
o Hardware hash upload.
o Out-of-Box Experience (OOBE) behavior.
• Ensure user-facing and support documentation clearly explains the “no touch” experience and when it applies.
For Microsoft Intune (Windows & macOS):
• Support and document:
o Tenant administration structure.
o Users, groups, and role assignments.
o Automatic enrollment configuration.
o Enrollment of up to 10 device models each for Windows and macOS, using up to 2 profiles.
o App packaging and deployment:
§ Up to 10 Windows apps (.msi/.exe).
§ Up to 10 macOS apps (DMG).
o Baseline configurations and security policies for Windows, macOS, iOS, and Android.
o App protection policies and data protection scenarios (enrolled vs. app-protection-only).
o Up to 4 compliance policies per platform.
o Lockdown/hardening policies for corporate-owned devices.
o Driver updates for up to 4 device models.
o Apple Business Manager integration steps for macOS.
o Entra ID user/device policies (up to 10).
o Monitoring, alerts, reporting, and software update management.
The BA will convert technical configurations into:
• Process flows
• End-user guides
• Support runbooks
• FAQs
________________________________________
4. Pilot Coordination
Intune & Autopilot Pilot (Windows & macOS):
• Coordinate pilot deployments of:
o Up to 20 Windows devices per model (up to 4 models).
o Up to 20 macOS devices.
• Responsibilities include:
o Creating and distributing end-user communications (emails, quick start guides, FAQs).
o Helping schedule pilot deployments with stakeholders.
o Supporting validation of access to on-premises resources for Autopilot devices.
o Collecting feedback from users and support staff.
o Documenting issues, changes, and adjustments made after the pilot.
o Summarizing pilot outcomes for leadership.
Mobile Device Pilot (BYOD iOS & Android):
• Coordinate pilot for:
o Up to 20 BYOD iOS devices.
o Up to 20 BYOD Android devices.
• Responsibilities include:
o End-user communications and instructions for enrollment.
o Supporting and documenting:
§ Offboarding from BES.
§ Onboarding to Intune.
o Collecting user and support feedback and documenting findings.
________________________________________
5. Communications & Change Management
• Develop clear, user-friendly communications:
o Announcement emails.
o Enrollment guides and screenshots.
o “What’s changing” summaries for end users and managers.
• Create and maintain:
o FAQs.
o Step-by-step procedures for different device types and personas.
o Simple overviews for non-technical stakeholders.
• Help ensure messaging is consistent across all platforms (Windows, macOS, iOS, Android) and aligned with branding and security requirements.
________________________________________
6. Knowledge Transfer & Documentation
• Work with technical teams to:
o Gather and organize all project documentation (design, configurations, policies, pilot results).
o Create support documentation and runbooks for IT Operations and Service Desk.
• Support and document knowledge transfer sessions:
o Capture key decisions, processes, and lessons learned.
o Ensure final documentation is complete, accurate, and accessible.