The challenge
Toronto Public Library had Microsoft Intune managing its Windows estate, but staff Apple devices sat outside it. Every unmanaged Mac was a device the library could not confirm was encrypted, could not push a security baseline to, and could not act on if it went missing. For a public institution, that gap has a clock on it.
Closing it meant more than switching enrolment on. Applications had to arrive without staff installing anything themselves, administrative access needed a clear boundary, and macOS brings constraints of its own. TPL wanted every one of those decisions documented and approved before configuration started.
Our approach
BITSUMMIT ran the work as a scoped pilot, settling the design in workshops with TPL before enrolling a single device.

Settle the design before configuring anything
Design workshops covered user personas for staff and IT administrators, use cases, policy and configuration, onboarding and offboarding workflows, and application management. The outputs became a design document with every decision written down, approved by TPL before configuration began.
Decide the enrolment and access model
Domain-join and cloud-only were evaluated against whether access to on-premises resources was genuinely required. Sign-in was restricted to Entra ID accounts, users were given standard roles with only IT retaining administrative access, and two personas were defined to drive device configuration.
Enforce the security baseline
Microsoft's recommended macOS baseline was applied alongside TPL-specific compliance policies. FileVault encryption was enforced with recovery keys escrowed in Intune, and the Secure Enclave used for key protection and local credentials. Where a platform control could not be technically enforced, BITSUMMIT documented containment practices rather than claiming coverage it could not deliver.
Provision and deploy without user involvement
Zero-touch provisioning was implemented through Apple Business Manager and Automated Device Enrollment, so devices configured themselves on first boot. Core applications were packaged and pushed centrally, App Store titles alongside DMG and complex installers, delivered through Apple VPP and custom scripts. End-user installs were not permitted.
Validate and hand over
Devices were enrolled and configured, with SSO, encryption and application deployment validated end to end. An as-built document captured the delivered state, and a knowledge transfer session walked TPL's team through it.
The outcome
Staff Macs are managed devices now. They arrive configured, encrypted with keys the library holds, carrying a security baseline and the applications staff need, without anyone installing software themselves. Administrative access sits with IT alone.
Just as useful is what the pilot established for everything that follows it. The personas, policies, application packages and onboarding workflows are documented and repeatable, and the decisions behind them were approved by TPL rather than assumed on its behalf.



.webp)
