Cloud & Identity · Church & Non-Profit · Deployment · 2026

Adding Threat Detection to a Fleet That Was Already Managed

A church staff team running a managed Windows and Mac fleet

The challenge

The organisation had done the hard part already — its workstations were enrolled in central management and had a consistent configuration. What management alone does not give you is detection: knowing that something is happening on a device, and being able to respond to it without somebody happening to notice first.

Where we came in

Detection tooling is easy to deploy and easy to deploy badly, because the failure mode is not silence — it is noise. Defining application exclusions with the client before switching on remediation is what separates a system people act on from a system people mute.

What we did

  • Verified prerequisites and licensing before beginning configuration
  • Linked detection tooling to the existing device management tenant rather than running it standalone
  • Built onboarding policies through the management platform already in place
  • Defined application exclusions with the client up front to avoid false positives on legitimate tools
  • Applied security baselines and antivirus profiles for Windows, and equivalent profiles for macOS
  • Validated coverage across the fleet rather than assuming enrolment equals protection

Where it landed

  • Both Windows and macOS workstations report into one detection and response console
  • Automated remediation is in place, tuned with client-agreed exclusions rather than switched on blind
  • Built on the existing management platform, so no second agent estate to maintain

Technologies

  • Microsoft Defender for Endpoint
  • Microsoft Intune
  • Windows 11
  • macOS
  • Security Baselines

Delivered and closed out in our project management system. Outcomes describe the resulting state — we have not published a measured before-and-after for this engagement.

Back to all projects