Skip to content
Lambert Consulting

Artificial Intelligence: A Cross-Functional Offering

Results first. Infrastructure second.

An assistant for your documents, end-of-line verification, a platform for multiple services. Where artificial intelligence is applied is determined by your data, not by a catalog.

See all solutions
4Comparing Architectures, Criterion by Criterion
2 fieldsSoftware and hardware under one roof
All Use CasesUse cases first, technology last

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation
Microsoft · Desktops and Mobile Devices

Microsoft Intune

You've already paid for it. The question is what it actually does.

Almost all companies with Microsoft 365 E3 or E5 already have it Intune, license included. So the issue is no longer whether to buy it—it’s about knowing what your tenant actually enforces. A green compliance dashboard proves nothing — a policy only checks what it’s been told to check, and it doesn’t prohibit anything unless conditional access is based on it. That’s where our work begins.

Windows Version 10 is now only a supported versionAs of October 14, 2025, Intune still accepts these posts but no longer guarantees their behavior
In a certain version, the agent no longer receives anythingSince April 2026, in versions prior to 1.58.103.0, applications, scripts, and remediation tasks stop without a message
A tenant’s country is set at the time of creationIntune exists in Switzerland. But the geography is derived from the directory, and it can no longer be corrected with a single click afterward

How It All Fits Together

One platform, two doors.

Since 2023, there are no longer two competing products, but rather one product family and a single management center. What remains true is that the two entry points do not lead to the same fleet: one retrieves the machine via the Internet, while the other waits for it on your network.

The Microsoft Family Intune

A single administration center, a single identity, a single set of compliance rules. If a document or quote still mentions Microsoft Endpoint Manager, it’s referring to this suite: Microsoft has retired that name.

First Door

Microsoft Intune

The service in the cloud. It connects to the device wherever it has network coverage, without going through your infrastructure.

  • +Laptops used off-site, remote work, contractors
  • +Phones and tablets, both Android and Apple
  • +Macs and Linux workstations for technical roles
  • +Personal devices, without registering them
Second door

Configuration Manager

The device installed in your home, formerly known asSCCM. It operates on your network, even when your network does not have Internet access.

  • +Installing the system on a bare-metal machine
  • +Closed networks, workshops, industrial sites
  • +Servers Windows, and large local files
  • +Very detailed hardware and software inventory
Collection

The co-management : the same position, led by both

An entry can carry the customer Configuration Manager and be registered in Intune. Seven configuration areas then switch over one by one, whenever you choose, and you’re under no obligation to switch them all. This is the normal state of a corporate IT infrastructure, not a transitional phase that you need to move beyond as quickly as possible.

Details about the seven domains, the order in which to switch them, and what’s best to leave as is are listed on the page Configuration Manager .

What it does, in plain terms

Six things, and the sixth is the only one that protects.

The first five are shown in a demonstration and put everyone’s minds at ease. The sixth is not shown, does not appear in any of the slides, and is the only one that prevents anything. A park where the first five are present and the sixth is absent is a managed park, not a protected park.

The Arrival

Register the device and set it up on your own

A brand-new computer, straight out of the box, can be set up without going through the IT department: it registers itself, receives its name, applications, and settings. On Windows, this is handled byAutopilot ; on Apple devices, it is handled by the manufacturer’s automated registration program.

Software

Install, Update, Remove

Applications are deployed without the user’s involvement, update automatically, and are removed when the user changes workstations. The Microsoft-managed enterprise catalog eliminates the need to manually package the most common software. This is a feature that incurs an additional charge, and we state this clearly in writing rather than demonstrating it.

Settings

Set up the configuration without a domain

Disk encryption, firewalls, passwords, networking, printers, restrictions: what Group Policy used to do on a computer connected to the domain, Intune it does on a computer that isn’t. The syntax is different, and the translation isn’t automatic.

Patches

Keep Windows up to date, in waves

Updates are rolled out in rings, with a delay and a restart window: first a small group, then the entire company. This is the tool’s most cost-effective feature, and the one most often left at its factory default setting.

No registration required

Protecting Data on a Device That Isn't Yours

On an employee’s personal phone or a contractor’s device, you can restrict only work-related apps: prohibit copying and pasting to personal devices, require a password, and remotely erase company data without affecting family photos.

The Sixth

Deny access when the device does not comply

A compliance rule detects; it does not prohibit. It is conditional access, Entra ID, that turns this detection into a closed door. Without it, a non-compliant workstation can still access email —and that’s the flaw we find most often.

The Starting Point

Four situations—and only one is yours.

A project Intune is almost never “install Intune .” It follows one of these four paths; they don’t all cost the same, and choosing the wrong path costs more than choosing the wrong tool. We’re currently working on all four of them with clients today.

Situation 1

Nothing, or almost nothing

The workstations are set up by hand, the group policies do what they can, and the phones aren't managed at all. The license Intune is included in the subscription, but it has never been activated.

This is by far the fastest approach: there’s nothing to dismantle. You set up the identity foundation, compliance, and conditional access, then enroll users in waves.

The telltale sign: No onecan say exactly how many positions are budgeted.
Scenario 2

An abandoned plot of land

Intune has been up and running for years. It contains forty profiles whose authors are unknown to anyone, three conflicting compliance rules, and groups named “test2” that are in production.

The challenge isn't technical: it's figuring out what actually applies today before making any changes. This is the most common situation, and the one where we break the most things by rushing.

The telltale sign: Noone dares to delete a profile anymore, for fear of what it contains.
Situation 3

Configuration Manager in place

A SCCM has been running for ten years, it’s doing its job very well, and yet people keep telling you that you should “switch to cloud .” The right answer is almost never to stop it.

We connect it, activate the co-management, and adjust the settings one by one, starting with the ones that won’t cause any problems. Each change is reversible.

The telltale sign:Laptops are brought back to the office once a month to “get their updates.”
Scenario 4

Another mobile management tool

Workspace ONE, Jamf, MobileIron, Ivanti : The management solution exists and works, but you have to pay for it a second time even thoughIntune is already included in the Microsoft subscription.

The actual work involves a step-by-step inventory of correspondence, followed by a brief, monitored dual management process. The costs here are associated with the certificates and the network, not the registration of the devices.

The telltale sign: Twoconsoles display two different messages on the same phone.
The Other Door

Do your computers never connect to the Internet? Configuration Manager That's still the right answer.

Workshop closed, separate industrial network, machine needs to be reinstalled from the network, servers Windows to maintain: in these areas, the system installed on your premises does what the cloud doesn’t do. We handle both, with the same engineers —and we’ll let you know when that’s the right answer.

What No One Writes About
Green compliance doesn't prove anything.

This is what we’ve observed in nearly all the instances we take over. The dashboard is green, management is reassured, and yet nothing is prevented. There are three reasons for this, and you can verify them in just a few minutes in your own console.

A rule only controls what it has been instructed to control

A compliance policy that only checks the “system version” box will flag a computer as compliant even if it lacks encryption, a firewall, and up-to-date antivirus software. The green checkmark does not mean “protected”; it means “compliant with what was specified.”

Without conditional access, compliance does not prohibit anything

Intune checks the device's status. Only conditional access, at Entra ID, denies the connection. Many companies have one but not the other: the assessment is correct, but the door remains open.

A device that no longer turns on remains green

A station whose operator has been offline for too long, or that has not communicated for weeks, retains its last known status. A ski area without monitoring of the lift itself turns green as time passes.

So the first thing we produce isn’t a plan: it’s the actual state of what your tenant is currently implementing, device by device, rule by rule, including what’s verified, what isn’t, and what’s simply silent. The rest of the scope is determined based on that—and nothing before it.

How much it costs, before the meeting

What's included, and what costs extra.

The usual hassle with projects Intune arises when the quote comes in: a feature shown in the demo turns out to be an option billed per user. Might as well say it now. The basic plan does the job; the eight advanced features are genuine, useful, and come at a cost.

Included in your subscription

The basic plan is enough to maintain a park

It is included in Microsoft 365 E3, E5, and in the plans for small businesses that include Intune. This is what we use for the vast majority of our projects.

  • +Registration and device setup, includingAutopilot
  • +Deployment of Applications and Scripts
  • +Configuration profiles on the five systems
  • +Compliance Rules and Update Management
  • +Data protection in apps, without registering the device
  • +The customer Configuration Manager, whose license is included
None of our implementation contracts require an additional license.
Billed per user, in addition

Eight advanced abilities, to be decided one by one

They can be purchased as a set or separately, depending on the situation. Each one addresses a specific need: the question is never “Should I buy them?” but “Which one solves a problem you actually have?”

  • Remote Assistance — Take Control of the Workstation, with Audit Trail
  • Elevation of Privileges — Removing Administrator Rights Without Disrupting Business Operations
  • Enterprise Applications Catalog — Popular Software Bundled by Microsoft
  • Managed Certificate Authority — Certificates Without Setting Up Infrastructure
  • Advanced Job Analysis — Measuring the User Experience
  • Tunnel for Managed Apps — Internal Access Without Registering the Device
  • Android firmware update, performed remotely and without user intervention
  • Specialized equipment —headsets, large screens, meeting rooms
We'll tell you which one works for you and which one won't.

A clarification to avoid a common misunderstanding: Intune is not an antivirus program. It configures the antivirus software built into Windowsand reads its status; detection and incident response are handled by a separate product with its own license. Similarly, conditional access is a feature of the directory, not ofIntune : it requires a level ofEntra ID that most enterprise subscriptions already include, but not all.

Our Approach

Nothing happens until the tenant's actual status is determined.

Five steps, always in this order, and the third is the point of no return: it’s the pilot who decides what happens next, not the kickoff meeting. Each step produces something you keep, even if you decide to stop there.

01

The actual status of what applies

We note what the system currently enforces: every profile, every compliance rule, every assignment group, and, above all, what is not verified at all.

We also note issues that are no longer being reported: employees who have been with the company too long, devices that have been inactive for weeks, and duplicate registrations.

What You Keep A chart of the current rules, along with their actual effects The list of out-of-range devices, and why Discrepancies between what is advertised and what is actually implemented
02

The Foundation: Identity First, Compliance Second

Order is non-negotiable. We clean up the directory and the groups, write the compliance rules that verify what matters, and then enable conditional access, which finally gives them the power to deny access.

Certificates and the network must be handled here, not later: they are what cause projects to fail at the time of the switchover.

What You Keep A written, named, and line-by-line documented set of rules Conditional access strategies, with their justified exceptions A fallback account that doesn’t depend on what you just set
03

The pilot, featuring real users

A real group, chosen together with you, that actually does the work: an entire department rather than three lab machines. That’s the only way to see what breaks.

This is the decisive stage. If the pilot indicates that part of the fleet needs to stay on Configuration Manager, we acknowledge it and adjust the plan—this happens, and it’s good news, not a failure.

What You Keep The list of pain points, along with their solutions The registration procedure, written for your teams The documented decision: what’s being removed, what’s staying, and why
04

Wave-based switching, with a return to the previous state

By site, by service, or by business unit—never an entire Monday morning. Each wave has its own stop criteria, and each switch in the configuration domain can be reversed with a single action.

Problem records don't hold up the batch; they stand out and are handled separately.

What You Keep The wave schedule and the criteria that trigger a halt Registration tracking, post by post The rollback procedure, tested before it’s needed
05

The Handover, and What Remains After We're Gone

Your teams need to be able to manage the platform without us. We provide training, we document everything, and we remain available to handle issues you don’t want to deal with yourselves.

We also handle communications with the publisher's support team when a bug is on their end: it's a job in and of itself, and it's not pleasant at all.

What You Keep Operational documentation, current as of the release date Training for your administrators on your tenant Top-tier support, if you want it

What You Should Know Beforehand

Six things they won't tell you during a demonstration.

None of these is a deal-breaker. But each one has already thrown off someone’s schedule, and it’s better to check for them before signing than in the middle of the transition.

The data region is set when the tenant is created

Intune It is operated from three major regions, and it also exists at the local level in Switzerland. This is good news for anyone who needs to keep their data in Switzerland—with one strict condition.

The geographic location is based on the country listed in the directory at the time it was created, and this value does not change thereafter. A request to move existing data must be submitted to the publisher’s support team; the migration may take up to twenty-four months after the request. This is therefore an issue that must be addressed on day one, not the last day.

Intune Do not reinstall a bare machine

Autopilot Starting with a Windows that is already booted. It customizes a machine; it does not install it from the network: there is no network boot, no task sequence, and no system image to deploy.

To restart a workstation whose hard drive is empty, you need either a prepared USB drive or Configuration Manager. This is the first—and most honest—reason to keep the tool installed on your own computer.

An old fleet is tolerated, not supported

As of October 14, 2025, Windows version 10 is no longer an authorizedversion: these devices can still be registered, but their behavior is no longer guaranteed. On Apple’s end, only the last three major versions are fully supported.

On the Android side, per-user management requires version 10 or later, and the old device administration method was discontinued in December 2024 on all phones running Google services. A fleet of slightly older rugged devices should be inventoried before committing to a date.

A cloned position is unmanageable

Intune rejects the image of a machine that is already registered: the registration token appears twice, and the device fails to register or synchronize, often without a clear error message.

The trap mainly affects virtual machines and remote desktops, where it is common practice to duplicate a reference image. The rule is simple: clone before registration, never after.

In a certain version, the agent remains silent

Since April 2026, a workstation Windows whose management extension predates version 1.58.103.0 no longer receives Win32 applications, scripts, or remediation actions. It remains visible in the console, appears to be in good health, and no longer executes anything.

Since June 2026, the content of these apps has also required encrypted distribution: a local cache that remains in plain text is bypassed, and bandwidth is redirected to the Internet without anyone noticing.

Software packaging remains a job

Intune It distributes what it’s given. Business software that used to be installed via a connection script, a local database, and a license key per workstation: all of that has to be rewritten, and that’s often half the actual workload of a project.

The enterprise application catalog covers standard software, but it is a paid option and does not cover your in-house software. We price this item separately, on a per-application basis, rather than as a flat rate.

Frequently Asked Questions

What we're asked to do before we begin.

Eight questions that come up on every first date. The answers are short, and they don't try to sell you the most expensive option.

Should we stop our SCCM to switch to Intune ?

No, and it's actually rarely a good idea. Both tools belong to the same family and can control the same workstation together: this is the co-management. Seven settings are then toggled one by one, whenever you choose.

We regularly see companies that handle Configuration Manager for the installation of systems and servers, and entrust everything else to Intune. This division is not a flawed compromise: it is the most common configuration for corporate IT infrastructures. Details can be found on the page Configuration Manager.

Our documentation mentions Microsoft Endpoint Manager, and our directory ofAzure AD. Is this still valid?

The content, yes; the names, no. Microsoft Endpoint Manager has become Microsoft Intune and Azure Active Directory has become Microsoft Entra ID. The historical tool installed on your premises, formerly known as SCCM MECM, is now called simply Configuration Manager.

This isn't just a matter of vocabulary: it's a sign that your document was written before these tools were consolidated into a single platform. We revisit this type of document regularly, and most of the technical work remains valid —it's the project structure that has changed.

Does our management data remain in Switzerland?

They can, on one condition: that the listing was created with Switzerland as the directory country. There is indeed a Swiss geographic category for Intune, but it must be selected on the first day and cannot be changed with a single click afterward.

If your tenant was originally created in another country, you may need to request a data migration from the vendor’s support team; please allow up to twenty-four months. We verify this point during the initial assessment, because it can sometimes determine the entire architecture.

Can we manage Macs and iPhones just as well as PCs?

Yes, and for a long time now. Apple phones are actually the area where Intune is the most advanced: automatic registration upon purchase, apps, restrictions, and remote wipe.

On Macs, coverage is good but not the same as on Windows : some fine-tuning requires configuration files, and some very “Apple”-oriented companies benefit from keeping a specialized tool on hand. We’ll let you know if this applies to you rather than forcing a single console.

What about computers that never connect to the Internet?

They are not for Intune. A device managed in the cloud must be able to reach the service regularly; a workshop workstation on a separate network will never be able to do so.

That’s exactly the domain of Configuration Managerthat operates on your local network. A single fleet can easily have its laptops in Intune and its production machines on the tool installed at your site.

Will our users lose their administrator privileges?

It’s a decision, not a consequence. Intune It allows you to revoke these rights, but nothing obligates you to do so at the time of the transition—and mixing the two projects is the best way to make both of them fail.

When you're ready to do so, the privilege escalation feature allows you to grant access on a case-by-case basis to tasks that truly require those privileges. This is a paid option, and the decision to use it is made after the switchover, never during it.

What's happening with our group strategy game?

It cannot be ported as-is. Many of the settings have an equivalent in Intune, some do not, and some are no longer necessary once the station is outside the domain.

The key toeffective work is to sort through things before translating: in the parks we’re taking over, a significant portion of the existing strategies haven’t been relevant for years. Copying them would be like paying to carry dead weight.

How long does it take?

It depends on three things, and nothing else: the number of business applications to repackage, the initial state of the directory, and the number of sites where someone must be physically present.

Here’s what we can say: the assessment of the current system takes place within the first few weeks; a pilot program with real users launches shortly thereafter; and the migration of an entire enterprise environment takes months—not quarters, and not weeks. We don’t give a date until after the assessment, because any date given before that is meaningless.

Continued

Let's start with what your tenant is actually doing

An hour with the engineers who will be doing the work, and your console open. We'll tell you what's working, what's not, and in what order to tackle it— including when the answer is to leave things as they are for now.

Preparing the proposal is free; assessing the existing conditions is the first step in the project. We are happy to arrange a meeting with the engineers who will be doing the work. We have been authorized to provide staffing services since 2018: an engineer can also join your team for a fixed term.

The Decisive Question

If a non-compliant workstation connects tomorrow morning, what will stop it?

If you can identify the conditional access policy that is blocking it, your infrastructure is in good shape: the rest is just maintenance.

If the answer is “compliance is green, then nothing can stop it. Green is a statement of fact, not a door—and that’s where we’ll start.