All success stories
Modern Workspace
Toronto Public Library

TPL Closes the Gap on Unmanaged Staff Macs

Toronto Public Library's staff Apple devices brought under Microsoft Intune, with enforced FileVault encryption, a hardened security baseline and zero-touch provisioning through Apple Business Manager.

Industry
Public Sector & Government
Service line
Modern Workspace
Timeline
2 months
TPL Closes the Gap on Unmanaged Staff Macs
FileVault
Encryption enforced, recovery keys escrowed in Intune
Zero
-touch
Provisioning via Apple Business Manager and ADE
IT-only
admin
Users run standard roles via Entra ID sign-in

The challenge

Toronto Public Library had Microsoft Intune managing its Windows estate, but staff Apple devices sat outside it. Every unmanaged Mac was a device the library could not confirm was encrypted, could not push a security baseline to, and could not act on if it went missing. For a public institution, that gap has a clock on it.

Closing it meant more than switching enrolment on. Applications had to arrive without staff installing anything themselves, administrative access needed a clear boundary, and macOS brings constraints of its own. TPL wanted every one of those decisions documented and approved before configuration started.

Our approach

BITSUMMIT ran the work as a scoped pilot, settling the design in workshops with TPL before enrolling a single device.

macOS management flow from design workshops through access model, security baseline, zero-touch provisioning and handover, designed by BITSUMMIT

Settle the design before configuring anything

Design workshops covered user personas for staff and IT administrators, use cases, policy and configuration, onboarding and offboarding workflows, and application management. The outputs became a design document with every decision written down, approved by TPL before configuration began.

Decide the enrolment and access model

Domain-join and cloud-only were evaluated against whether access to on-premises resources was genuinely required. Sign-in was restricted to Entra ID accounts, users were given standard roles with only IT retaining administrative access, and two personas were defined to drive device configuration.

Enforce the security baseline

Microsoft's recommended macOS baseline was applied alongside TPL-specific compliance policies. FileVault encryption was enforced with recovery keys escrowed in Intune, and the Secure Enclave used for key protection and local credentials. Where a platform control could not be technically enforced, BITSUMMIT documented containment practices rather than claiming coverage it could not deliver.

Provision and deploy without user involvement

Zero-touch provisioning was implemented through Apple Business Manager and Automated Device Enrollment, so devices configured themselves on first boot. Core applications were packaged and pushed centrally, App Store titles alongside DMG and complex installers, delivered through Apple VPP and custom scripts. End-user installs were not permitted.

Validate and hand over

Devices were enrolled and configured, with SSO, encryption and application deployment validated end to end. An as-built document captured the delivered state, and a knowledge transfer session walked TPL's team through it.

The outcome

Staff Macs are managed devices now. They arrive configured, encrypted with keys the library holds, carrying a security baseline and the applications staff need, without anyone installing software themselves. Administrative access sits with IT alone.

Just as useful is what the pilot established for everything that follows it. The personas, policies, application packages and onboarding workflows are documented and repeatable, and the decisions behind them were approved by TPL rather than assumed on its behalf.

Staff Apple devices brought under Intune with enforced encryption, a hardened baseline and zero-touch provisioning, on a design TPL approved before configuration began.
BITSUMMIT

Your story could be the next one.

Tell us what you're trying to modernize, secure or migrate. We'll bring a plan and a named senior engineer.

Schedule a call