AI training for Copilot, Claude and OpenAI. Book your slot now 09 974 2379Client PortalRemote Support
Belton IT Nexus
Belton · Run / Protect / Improve / BuildView all services ›
Belton · Knowledge, not gatekeepingResource library ›
Belton IT Nexus · Est. 2004 · Newmarket, AucklandAbout us ›
Home/ Insights/ Product review

The device management stack, reviewed

Jason AgnewFounder & CEO
Aug 2026Product Review
6 minRead

Six products decide whether a company's laptops are managed or merely owned. We run all six across client fleets, every day, and this is the honest account of each: what it does, where it earns its keep, and where it will test your patience.

Read it as one stack rather than six purchases. The value is in how they fit together, and most of the failures we are called in to fix are integration failures rather than product failures.

Microsoft Intune: the quiet workhorse

We have watched Intune mature from a rough MDM into the default way business devices get managed. Every laptop enrolled, configured, patched and wipeable from one console, that is Intune doing its job invisibly.

In practice it means every company device is enrolled the moment it is set up: security policies applied, the right apps installed, disk encryption enforced, updates scheduled, all without anyone touching the machine by hand. When a laptop is lost or a staff member leaves, the device can be locked or wiped remotely from the same console.

The quiet win is compliance. Intune continuously checks each device against the rules you set, things like encryption on, screen lock enforced, OS patched, antivirus healthy, and can feed that state into conditional access, so a non-compliant device simply does not get into your company data until it is fixed. That is the difference between hoping your fleet is secure and being able to show it. It covers Windows and macOS side by side, plus mobile, which matters now that most businesses run a mixed fleet.

It rewards patience. Profiles and compliance policies take real design, and the feedback loop on a bad policy can be slow. A rushed rollout creates noise, prompts users did not expect, apps that half-deploy, devices stuck in limbo. The platform is at its best when someone has thought through the policy design first and rolled it out in rings rather than all at once.

Verdict: if your fleet is not enrolled, you do not manage your fleet. The foundation of modern device security.

Windows Autopilot: the unboxing moment

Autopilot has been around since 2017, and the demo still lands: a sealed laptop couriered to a new hire becomes a fully configured, secured company device in under an hour, with no IT hands on it. Paired with Intune, a new laptop ships straight from the supplier to a new starter's desk and builds itself on first sign-in.

Behind the trick is registration discipline and profile design, plus resets that occasionally test your patience. The payoff is onboarding that scales and offboarding that is just as clean.

Verdict: how device provisioning should work. We will not deploy fleets any other way.

Windows 11: five years of rollouts

Windows 11 shipped in October 2021 with hardware requirements that made fleets honest: TPM 2.0 or no ride. Five years of managed rollouts later, the OS itself has been a non-event, in the good sense.

The real story was lifecycle. The requirement forced replacement conversations businesses had deferred for years. Painful once, healthier after, especially with Windows 10 support now behind us.

Verdict: stable, secure, fine. The lesson was fleet planning, not the OS.

Windows 365: a PC in the browser

Windows 365 shipped in 2021 as AVD's simpler sibling: a fixed-price Cloud PC per user, no host pools, no scaling design. For boards, contractors and BYOD-heavy teams, that simplicity wins.

Per-seat economics favour AVD as numbers grow, so we model both before recommending either. The product itself has been reliable to the point of forgettable.

Verdict: the easy on-ramp to cloud desktops. Know when to graduate.

Azure Virtual Desktop: the 2021 sleeper

AVD matured in 2021, and we have used it since for firms with heavy apps, contractors and anywhere-work policies: a full Windows desktop in Azure, with nothing sensitive on the endpoint.

The discipline is cost. Host pools left running overnight burn money, so autoscaling is not optional. It is the difference between AVD being brilliant and being cancelled.

Verdict: the right answer to a specific set of problems, run with a hand on the meter.

Apple Business Manager: Macs that behave

Apple Business Manager arrived in 2018 and changed the conversation: Macs, iPhones and iPads that enrol themselves into management at first boot, zero-touch, the Apple version of Autopilot.

Combined with MDM, it ends the "Macs are special" era: same enrolment, same compliance, same remote wipe. The gripe is Apple's pace of change in management APIs, which keeps integrators on their toes.

Verdict: if your business runs Apple, ABM is not optional. It is the adult way to do it.

What we would tell you

Start with Intune and Autopilot. Those two change what onboarding and offboarding cost you, and they are the pair that makes every other control enforceable rather than aspirational. Windows 11 is a planning exercise, not a product decision. Cloud desktops are a specific answer to a specific problem, and if nobody has modelled the per-seat economics against AVD then the decision has not actually been made yet. If you run Apple at all, Apple Business Manager is table stakes.

The pattern across all six is the same: the licence is not the control, the configuration is. Most of the fleets we inherit already own most of this and have switched on almost none of it.

Reviewed from live fleet experience · published August 2026 · we earn a fair margin on some products we supply; reviews are not sponsored.

Jason Agnew
Jason AgnewFounder & CEO, Belton IT Nexus. Twenty-two years building specialist IT and security for New Zealand business.

Want it deployed
properly?

A 90-minute discovery & security session. We'll tell you what fits your environment, and what doesn't.

And relax

Getting started is the easy part.

Onboarding without drama

We do the switch: your current provider, the migration, the handover, all of it. Most teams barely notice the cutover happened.

Everything looked after

On the right plan, compliance, reporting and budgets are handled inside the partnership. You run the business; we run the IT underneath it.

Your QBR writes itself

Quarterly business reviews are generated automatically from your live environment: spend, posture, recommendations and roadmap, ready for the board, reviewed with your account manager.

The honest bit: the full looked-after experience comes with the right plan. We charge fairly for what we take on, and when costs step up it's because you are taking on more, always moving in the right direction.

Sovereign by design

New Zealand owned and operated.

Sovereign data centres across New Zealand and Australia, with your data kept onshore wherever it's required. Our team understands New Zealand, and our leaders have built, scaled and secured businesses right across the New Zealand landscape.

Sovereign data centres · New Zealand & Australia
  • Auckland
  • Christchurch
  • Sydney
  • Melbourne
  • Brisbane
  • Perth
International data-centre operations
  • Singapore
  • Germany
  • Netherlands
  • USA

Servers available in minutes, not days.

Explore data centres & hosting →
Partners & platforms
Microsoft Solutions Partner, Modern Work Microsoft Solutions Partner, Security
Fortinet Partner Veeam Partner Lenovo Partner HP Partner SentinelOne Partner Microsoft Azure Microsoft Copilot Claude
Book your free discovery & security session