Our company is scaling rapidly, and my IT team is currently drowning in manual laptop setups and endless helpdesk tickets. We are finally migrating away from an aging on-prem Active Directory environment and want to transition to a fully cloud-based management strategy for our Windows 10 and 11 fleet.
Beyond the basic wipe and lock security features, what advanced capabilities are actual deal-breakers when evaluating a modern Windows device management tool? I’m particularly concerned about handling silent app deployments across different departments and finding a way to securely restrict a handful of public-facing devices we use in our lobby. Any advice from those who have already made the jump?