Device management
Config profiles, compliance and Autopilot for Windows, iOS and Android, without the settings that quietly break helpdesk.
- Configuration profiles
- Compliance policies
- Autopilot & enrollment
Microsoft 365 Β· Intune Β· Entra blueprintAn opinionated, MKB-first blueprint for Intune and Entra. Every policy carries a plain-language why, a naming system you can actually read, and a straight line from documentation to a deployed tenant. No hieroglyphics required.
Built for Business Premium on Windows 11 Pro. Tier-ups flagged, never assumed.
You don't manage one tenant, you manage all of them at once. By hand, that's herding cats, blindfolded, while the cats are on fire π±βπ₯. Standardization is the fire extinguisher, and a solid Microsoft 365 blueprint is how you go from just keeping the lights on to actually serving clients at a higher level.
Even with standards written down, real-world IT gets messy. Colleagues come and go, everyone adds their own creative spin, and repetitive clicking breeds sloppy little mistakes. Give it a few months and no two clients look alike, even though on paper they're identical twins. Eventually nobody remembers what "normal" was supposed to be. π΅βπ«
No code dumps, no wall of PowerShell to copy-paste and pray. Just plain instructions, explanations and blueprints for the policies, groups and configs that make up your golden master. Think IKEA manual for Microsoft 365, minus the leftover screws. π©
For educational purposes: you press the buttons, so if something explodes you know who to blame (hint: not me π). MIT-licensed, emojis over acronyms, on purpose.
Config profiles, compliance and Autopilot for Windows, iOS and Android, without the settings that quietly break helpdesk.
Conditional Access and Identity Protection that hold up under real users, real travel, and real 2 AM incidents.
The emoji naming convention that ties it all together, so every policy, group and profile tells you what it is before you open it. Yes, emojis. No, not just to be cute. π¦
Staring down 50 policies at 2 AM, you shouldn't have to open each one to remember what it does. Every object is named so the icons tell you what it is before you finish reading. Your future self says thanks π§ . Hover or tap the pieces.
One pattern, everywhere: [Type Icon][Target Icon][Modifiers] [Type Code] - [Descriptive Name]
GoldenMaster tells you what good looks like and why. SuperVision stamps that master across every customer tenant and tells you the moment one drifts.
An opinionated reference every setting can be traced back to. Read it, adapt it, argue with it. Every recommendation earns its place on its own merits.
Turn the blueprint into real configuration across client tenants: standardization, repeatability with fewer errors, and drift monitoring that flags the moment a golden master slips out of sync. Tags carry each client's quirks without breaking the standard.
The reasoning behind the reference: the edge cases, the tattooing settings that refuse to leave, and the exits you didn't know were wide open.
Emergency access accounts that actually work when everything else is on fire, and stay locked the other 364 days.
Read βUsers shouldn't be able to walk a managed device out the door. Blocking unenrollment, and the inverse policy that undoes it cleanly.
Read βUser-driven, self-deploying, pre-provisioned, the practical differences, and which one your MKB clients actually want.
Read βThe blueprint grows out of a community of MSP engineers who argue about this stuff at length so you don't have to. Bring your tenant horror stories, we have coffee and strong opinions β.