Skip to content
Staffactory
  • Careers
Log inContact us
Loading roles…

Work with Staffactory

Browse jobsContact us

Services

  • Contract staffing
  • Contract-to-hire staffing
  • Direct hire staffing
  • IT solutions

Media

  • Blog
  • Vlogs
  • Case studies

Company

  • About
  • FAQ
  • Contact

Careers

  • Browse jobs

Legal

  • Terms & services
  • Privacy policy
Staffactory

We leverage decades of consulting experience in operations, technology, and staffing services to shape strategic roles and source exceptional candidates.

Staffactory LLC, 5901 W Century Blvd, Suite 750, Los Angeles, California 90045
contact@staffactory.com · +1 310-929-8421

© 2026 Staffactory LLC and its Affiliates. All rights reserved.

Careers

Find your dream job

Contract, contract-to-hire, and direct hire roles across the United States.

59 roles

Opening a role requires accepting our Terms and Conditions.

Project Manager - Non-IT

Washington, D.C. · Hybrid · REQ-87163

Information Technology - Technology Trainer

Denver, CO · Hybrid · REQ-50024

Production Operator

Wheeling, IL · Onsite · REQ-12885

Utility Technician I

Garland, TX · Onsite · REQ-65746

Linen Service Specialist

Altamonte Springs, FL · Onsite · REQ-28607

Linen Service Specialist

Minneola, FL · Onsite · REQ-81468

Linen Service Specialist

Orlando, FL · Onsite · REQ-44329

MDM Implementation for Apple and Windows

Long Beach, CA · Onsite · REQ-97190

Programmer Analyst 6

Lansing, MI · Hybrid · REQ-60051

Business Resiliency Specialist

Long Beach, CA · Hybrid · REQ-22912

MDM Implementation for Apple and Windows

Location
Long Beach, CA
Work type
Onsite
Employment
Temporary
Req ID
REQ-97190
Apply now

About the role

Detailed Position Summary: The client is seeking consulting team to design, configure, pilot, deploy, and transition to operations a unified Microsoft Intune endpoint management capability for Apple and Windows devices. The engagement will establish Intune as the primary management and compliance platform, integrate endpoint controls with Microsoft Entra ID and Conditional Access, migrate Apple management from Kandji, migrate Windows management from Intune, introduce Windows co-management and Windows Autopilot, and leave Port staff with documented, supportable operating processes. The consulting team shall provide the technical leadership and implementation capacity required to move from the current project state to production readiness while protecting existing operations. The work must address device enrollment, identity, security, applications, certificates, network access, user migration, operational support, governance, reporting, and knowledge transfer as one coordinated program

Essential Duties and Responsibilities include the following. Other duties may be assigned.

Project Planning and Governance

  • Confirm stakeholders, decision rights, project governance, meeting cadence, escalation paths, and reporting requirements.
  • Develop and maintain the integrated project schedule, backlog, milestone plan, requirements traceability matrix, risk and issue log, decision log, action register, dependency register, and deliverable register.
  • Coordinate Apple and Windows workstreams.
  • Provide weekly status reports covering accomplishments, upcoming activities, milestone health, resource needs, decisions, risks, issues, and changes.

Discovery and Solution Design

  • Assess the existing Intune tenant, Microsoft Entra ID, Configuration Manager, Kandji, applications, network access, device inventory, licensing, security standards, and support processes.
  • Validate functional, technical, security, operational, migration, reporting, and support requirements for macOS, iPhone, iPad, and Windows devices.
  • Develop target architecture and detailed designs covering enrollment, identity, compliance, Conditional Access, security, applications, updates, certificates, connectivity, reporting, remote actions, and recovery.
  • Identify product or licensing gaps and provide documented options, impacts, costs, risks, and recommendations.

Microsoft Intune Foundation and Administration

  • Review and configure Intune tenant settings, enrollment restrictions, device categories, policies, compliance, naming standards, groups, assignment filters, scope tags, role-based access control, connectors, audit settings, and reporting.
  • Define policy naming, versioning, documentation, assignment, testing, promotion, exception, rollback, and retirement standards.
  • Establish monitoring and reporting for enrollment, compliance, configuration deployment, application installation, update status, device risk, inactive devices, and failed actions.

Apple Device Management Implementation

  • Design and implement enrollment profiles for corporate macOS, iPhone, and iPad devices, including supervised enrollment, Setup Assistant options, user affinity, Company Portal, naming, shared devices, loaners, and exception scenarios as applicable.
  • Configure Apple security and compliance controls, including passcode, encryption, FileVault and recovery-key escrow, firewall, screen lock, OS minimums, update policies, jailbreak detection, remote lock, retire, wipe, and lost-device procedures.
  • Implement and test on-premises Azure Kerberos for approved resources, including mapped drives and line-of-business services. Document credential prompts after login, reconnect, restart, VPN connection, and password change.
  • Define standard-user, local-administrator, emergency-administrator, and just-in-time elevation processes. Evaluate endpoint privilege management requirements and document any need for a complementary product.
  • Develop and execute the Kandji-to-Intune migration process.

Windows Device Management Implementation

  • Assess Configuration Manager version, tenant attach, co-management prerequisites, hybrid Microsoft Entra join, applications, network access, update infrastructure
  • Design and implement co-management for an approved pilot collection and develop a controlled workload transition plan for compliance, device configuration, endpoint protection, Windows Update policies, and resource access.
  • Design and implement Windows Autopilot for approved user-driven, pre-provisioned, and selfdeploying scenarios, including hardware registration, deployment profiles, Enrollment Status Page, naming, required applications, and technician workflows.
  • Configure approved Windows security and compliance controls, including BitLocker and key escrow, Microsoft Defender, firewall, attack surface reduction, Windows Local Administrator Password Solution, Windows Hello for Business, local administrator controls
  • Implement Windows Updates, feature and quality update policies, expedited updates, driver update strategy, deadlines, restart behavior, reporting, rollback, and exception handling.
  • Package and deploy approved applications with documented requirements, dependencies, detection logic, supersedence, uninstall, and rollback procedures.
  • Develop and execute the SCCM-to-Intune migration process.

Testing Migration and Production Rollout

  • Develop test plans and acceptance criteria mapped to the approved requirements and architecture.
  • Execute technical validation, Information Management pilot, business pilot, and phased production waves only after documented entry criteria and Port approval.
  • Develop migration waves based on technical readiness, department, device type, user persona, business criticality, location, support capacity, and blackout periods.

Operational Readiness Training and Knowledge Transfer

  • Develop architecture diagrams, configuration records, policy inventories, standard operating procedures, runbooks, troubleshooting guides, support guides, renewal calendars, monitoring procedures, recovery procedures, and escalation paths.
  • Train Service Desk personnel and admins

Required Knowledge and Experience

  • Demonstrated enterprise implementation experience with Microsoft Intune across Windows, macOS, iOS, and iPadOS.
  • Hands-on experience with Automated Device Enrollment, Apps and Books, Apple Configurator, Platform SSO, FileVault, certificates, macOS application deployment, and Apple enterprise troubleshooting.
  • Hands-on experience with Microsoft Configuration Manager co-management, tenant attach, Windows Autopilot, hybrid and cloud Microsoft Entra join, Windows Hello for Business, BitLocker, LAPS, Windows Update for Business, application packaging.
  • Experience integrating Intune compliance with Microsoft Entra
  • Experience planning and executing endpoint migrations with pilot rings, user communications, production waves, rollback, exception handling, and measurable acceptance criteria.
  • Experience designing least-privilege administrative models using Intune RBAC, scope tags, Microsoft Entra roles, Privileged Identity Management, audit logs, and access reviews.
  • Ability to identify product limitations, policy conflicts, licensing dependencies, and operational risks and translate findings into clear technical and management recommendations.
  • Ability to produce complete architecture, configuration, testing, migration, support, operational, and training documentation.

Desired Team Skills

  • Microsoft Intune Expertise: In-depth knowledge and hands-on experience designing, configuring, and operating Microsoft Intune for enterprise Windows, macOS, iOS, and iPadOS environments.
  • Apple Device Management: Proven experience implementing Automated Device Enrollment, Apple Configurator, certificates, FileVault, application deployment, and macOS security controls.
  • Windows Endpoint Management: Proven experience with Microsoft Configuration Manager co-management, tenant attach, Windows Autopilot, Windows security baselines, BitLocker, Windows LAPS, Windows Hello for Business, Windows Updates, application packaging
  • Identity and Conditional Access: Strong understanding of Microsoft Entra ID, device registration and join models, Conditional Access, authentication methods, device compliance, Privileged Identity Management, role-based access control, and hybrid identity dependencies.
  • Application and Configuration Management: Experience packaging, deploying, updating, and troubleshooting Windows and Apple applications, configuration profiles, scripts, certificates, Wi-Fi, VPN, printers, file shares, and other enterprise resources.
  • Endpoint Migration and Deployment: Proven ability to plan and execute Intune migrations, Configuration Manager co-management transitions, Windows Autopilot deployments, pilot programs, production waves, rollback procedures, and device lifecycle processes.
  • Apple and Windows Troubleshooting: Strong analytical and troubleshooting skills to identify and resolve complex enrollment, identity, compliance, application, certificate, connectivity, update, and policy-assignment issues across Apple and Windows platforms.
  • Technical Leadership: Ability to provide endpoint architecture guidance, recommend operational improvements, coordinate technical dependencies, and guide implementation decisions across multiple workstreams.
  • Communication and Collaboration: Excellent communication skills to work effectively with Infrastructure Operations, Security Operations, Network Operations, Service Desk, application owners, leadership, Microsoft, Apple, and other vendors.
  • Documentation and Knowledge Transfer: Ability to create detailed architecture diagrams, configuration records, policy inventories, test plans, migration procedures, operational runbooks, troubleshooting guides, support documentation, and knowledge-transfer materials.

Requirements

Must have

  • Microsoft Intune
  • Apple MDM
  • Windows Endpoint Management
  • Intune Migration
  • SCCM Co-Management
  • Windows Autopilot
  • Microsoft Entra ID
  • Apple Security
  • Windows Security
  • Application Packaging
  • Certificates / PKI
  • Conditional Access
  • Endpoint Migration
  • Troubleshooting
  • Technical Architecture
  • Documentation & Training
  • Technical Leadership

Experience: 7–15 years

‹ All roles