Case study feature image
Field notes · Endpoint management

Getting a new fleet under management, one PC at a time

Azure AD joined, but nothing deployed. Here is what it actually took to get NinjaOne onto every machine onsite, then pull the whole fleet into Intune.

NinjaOne on every PCFleet enrolled in IntuneMonitoring and compliance live
By Harvey Roxas  ·  Field notes  ·  Endpoint management
When a new site comes across to us, none of the good stuff works until the fundamentals are in place. Patching, monitoring, remote support, compliance reporting: all of it sits on top of one thing, which is an agent on every machine that reports back. This is the story of putting that layer down by hand.

Where we started

The devices were already Azure AD joined, so identity was sorted. Everything else was not. There was no mobile device management, no remote monitoring and management tool, and no software deployment path of any kind. A brand new environment with nothing in it.

My job was to get NinjaOne onto every PC in the fleet.

Day one
  • Azure AD joined
  • Not enrolled in Intune
  • No RMM agent
  • No remote deployment path
After
  • NinjaOne on every machine
  • Every device enrolled in Intune
  • Patching and monitoring running
  • Compliance policies applying

Why it had to be done by hand

Deploying software to a fleet is normally a script and a coffee. That assumes you already have something to deploy through. Here we did not, and every remote option ruled itself out:

  • Push it through Intune. Nothing was enrolled yet, so there was nothing to push from.
  • Push it through the existing RMM. There wasn’t one. That was the whole point of the visit.
  • Push it through Group Policy. Azure AD joined with no on-premises domain, so no GPO to hang it off.

That left the honest answer: go onsite with the installer on a USB drive and work through the fleet machine by machine. So that is what I did.

How it ran

Step 1

Walk the floor first

Before touching anything, confirm what is actually out there. A device list is a starting point, not the truth. Machines in drawers, spares, and the laptop someone took home all have to be accounted for or they become the gap later.

Step 2

Install the agent, PC by PC

NinjaOne installed from USB on each machine, then checked in before moving on. Verifying at the device is slower than trusting the installer, and it is the difference between a fleet that is covered and a fleet that looks covered.

Step 3

Enrol the fleet into Intune

With NinjaOne running everywhere, our Infrastructure Engineering team pushed a PowerShell script through it to pull every device into Intune. The manual work bought us the remote path, and the remote path did the rest in one pass.

Step 4

Check the numbers match

Device count in NinjaOne against device count in Intune against what we saw on the floor. Three numbers, one answer, no stragglers.

What that groundwork unlocks

Once both tools are reporting, the day to day service actually works the way it is supposed to.

Patching

Updates go out on a schedule and we can see what applied and what failed, per device.

Monitoring

Disk, health and security alerts surface before someone has to log a ticket about them.

Support

An engineer can connect to a machine and fix it without a site visit or a screen-share wrestle.

Compliance

Intune applies policy and reports on it, so device posture is a report rather than an assumption.

The unexciting work is the work

On paper this is not the most interesting job going. Walking from PC to PC with a USB drive is repetitive and manual, and there is no clever trick to make it shorter when there is nothing in the environment to automate through.

But it is the groundwork everything else depends on. If that step is done badly, or done to 90 per cent of the fleet, then patching has holes, monitoring has blind spots, and ticket resolution takes longer than it should. Nobody sees the missing agent. They just see the machine that never gets fixed properly.

A lot of the value in IT work comes from doing the basics right, so the bigger systems can actually function.

Harvey Roxas, Zetta

That is most of what onboarding looks like at our end. Not a launch, just a floor being laid properly so nothing has to be redone in six months.

Work with us

Stop worrying about IT

Zetta Essentials is our managed IT service for small business in Perth. One flat rate of $95 per user per month, excludes GST. We do the groundwork, then we run it.

Acknowledgement of Country

Zetta acknowledges the Whadjuk people of the Noongar nation, the Traditional Custodians of the land on which we live and work, and pays respect to Elders past and present.

Transform Your Organisation

Other Blog Posts

Need IT Assistance?