Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
IT engineer configuring a laptop from a management console

Standardising the Windows workplace

Two hundred users, eight device models, four image versions and three ways of installing the same application. Every one of those variants was a sensible decision at the time, and together they are why support costs what it does.

Updated July 2026 3 min read Written by the ITproposal team
In short

Standardise on two or three device profiles, one enrolment method and one application delivery mechanism. Every extra variant multiplies the testing, the documentation and the number of ways a support call can go.

Zero-touch enrolment, where a device ships from the supplier and configures itself when the user signs in, removes the imaging step entirely. It is the biggest single reduction in rollout effort available.

Standardise the boring layer first: enrolment, security baseline, application delivery and update rings. Personal preferences at the top of the stack matter far less than consistency at the bottom.

What variety actually costs

Every model added to an estate brings its own driver set, its own dock behaviour, its own firmware cycle and its own set of quirks the desk has to learn. Two models is manageable. Eight is a permanent tax on every support call, because the first question becomes which variant this user has.

The saving that created the variety is almost always smaller than the ongoing cost. Buying whatever was cheapest that quarter saves a few per cent on purchase and adds a support burden that lasts the life of the device.

Two or three profiles, not eight models

A workable standard for a mid-market organisation.
ProfileWho gets itRoughly
StandardMost of the organisation14-inch, 16 GB, integrated graphics
MobilePeople on the road or on siteLighter, longer battery, mobile connectivity
PowerDesign, engineering, data workWorkstation class, 32 GB or more
SharedFloor, training rooms, temporary staffEntry business range, hardened profile

Four profiles from one manufacturer is far easier to run than eight models from three. The choice of brand matters less than the discipline of sticking to the profiles for a full cycle, which is set out in Dell, HP or Lenovo.

Zero-touch enrolment changes the arithmetic

The traditional model has a device arriving at IT, being unboxed, imaged, joined, configured and then delivered. That is one to three hours per device, and it is why rollouts are measured in weeks.

Zero-touch enrolment sends the device from the supplier straight to the user, registered against your tenant. The user signs in and the device configures itself: policies, applications, security settings, printers. The engineer never touches it.

For a rollout of any size that is the difference between a project and a delivery schedule. It also makes replacing a broken laptop trivial, because a spare from a cupboard becomes a working device in the time it takes to sign in.

Golden image or configuration as policy

The older approach builds a single image containing everything and applies it to every device. It is predictable and it ages badly: the image needs rebuilding whenever anything changes, and it ties you to hardware that the image was built for.

The current approach keeps the operating system as the manufacturer shipped it and applies everything else as policy, so the configuration is a definition rather than a snapshot. It takes longer to set up and considerably less to maintain, and it survives a hardware change without a rebuild.

For most mid-market organisations the second is now the right answer. The exception is a heavily customised environment with applications that resist policy-based installation, and those are worth identifying before committing.

Update rings, not update chaos

Two extremes are both common and both wrong: updates applied immediately to everyone, or updates deferred indefinitely because a previous one caused a problem.

Rings solve it. A small pilot group takes updates first, a broader group a week later, the rest a week after that, with critical security updates on a shorter cycle for everyone. It catches the bad update on twenty machines instead of two hundred, and it means the answer to when updates get applied is a schedule rather than an argument.

What to standardise first

  • Enrolment. One way devices join. Everything else depends on it.
  • Security baseline. Disk encryption, endpoint protection, screen lock, local administrator rights. Same everywhere, no exceptions by seniority.
  • Application delivery. One mechanism. Not a mix of a portal, a script and somebody installing things by hand.
  • Update rings. Defined groups with a defined delay.
  • Then the profiles. Hardware standardisation follows naturally once the layer beneath it is consistent.

How we run this day to day is described under managed IT, and the delivery of the devices themselves under IT lifecycle.

Frequently asked

Questions we get about this

What comes up when an estate is being tidied up.

How many device models should we standardise on?

Two or three profiles from one manufacturer, four at most. Every extra model brings its own drivers, dock behaviour and quirks, and the support cost of that variety usually exceeds the purchase saving that created it.

Is a golden image still the right approach?

For most mid-market organisations, no. Keeping the operating system as shipped and applying everything else as policy takes longer to set up and much less to maintain, and it survives a hardware change without a rebuild. Heavily customised environments are the exception.

What is zero-touch enrolment?

The device ships from the supplier directly to the user, registered against your tenant. The user signs in and it configures itself: policies, applications, security settings. It removes the imaging step entirely, which is the largest single cost in a traditional rollout.

How should we handle Windows updates?

In rings. A small pilot group first, a broader group a week later, the rest a week after that, with critical security updates on a shorter cycle for everyone. It catches a bad update on twenty machines instead of two hundred.

Related services

Where this lands in our work

Where the workplace is run.

Want this looked at for your own sites?

Half an hour on a call is usually enough to tell you whether we are the right party for it, and we will say so if we are not.