We are frequently asked these questions
IT teams, MSPs, and compliance officers managing Intune environments.
eido uses enterprise-grade encryption and access controls, with ISO27001/9001, and Cyber Essentials. See our Security pages on our support site for full details Security | Eido Product Help and Support
Customers can choose between eido instances being in Azure datacentres in either Germany or USA.
No, eido is cloud-based and integrates via secure APIs.
eido is a reporting and visibility platform for Microsoft Intune.
Yes. baramundi attaches great importance to data protection and IT security. baramundi is ISO 27001 certified and the baramundi Proactive Hub is completely Made in Europe, meets the requirements of the GDPR and enables companies to secure their compliance requirements through functions such as role and rights management, audit trails and encrypted communication.
The baramundi Proactive Hub and its products are cloud native and cloud only. The cloud architecture enables scalable, secure and flexible use.
Baramundi Perform2Work continuously collects and automates data on the digital work environment. The aim is to identify IT problems at an early stage, to make the Digital Employee Experience (DEX) measurable and to optimize it in a targeted manner — even before complaints arise.
The system collects technical and user-related indicators such as CPU, RAM and battery performance, system start times, network quality, crashes or direct user feedback. This data is analyzed, correlated and presented in clear dashboards — for an objective, continuous evaluation of the user experience.
Baramundi Perform2Work Is a Digital Employee Experience (DEX) solution. The tool provides IT departments with valuable insights into the performance and quality of use of end devices — directly from the perspective of employees. In this way, digital workplaces can be specifically optimized and productivity and satisfaction can be sustainably increased.
Yes. baramundi attaches great importance to data protection and IT security. Baramundi is ISO 27001 certified and the management suite is completely made in Europe, meets the requirements of the GDPR and enables companies to secure their compliance requirements through features such as role and rights management, audit trails, and encrypted communication.
The baramundi Management Suite supports:
- Windows, Linux, and macOS systems
- Android and iOS mobile devices
- servers, (I) IoT devices
- Thanks to its platform independence, the suite is ideal for heterogeneous IT environments.
The baramundi Management Suite can be operated both on-prem and as-a-service or hybrid. Companies can choose whether they want to manage their infrastructure themselves or use it as a managed service.
The baramundi Management Suite supports IT teams with numerous routine tasks, such as:
- Software distribution and OS installations
- Patch and update management (including 3rd party)
- Inventory of hardware and software
- Configuring security settings
- Endpoint monitoring and remote support
The baramundi Management Suite is a comprehensive unified endpoint management platform (UEM) that allows companies to centrally manage, secure and automate their IT devices — from Windows PCs to mobile devices to servers or IoT devices.
Consulting usually involves differentiated projects, such as a health check, the implementation of SCCM or targeted optimization in a specific area. We price these at a flat rate or on a time basis.
For quick help through on-demand SCCM support, we offer various attractive hourly packages.
Should we take on tasks permanently and proactively or operate the SCCM, we offer flexible managed services that are priced at a mix of monthly flat rate and services incurred.
Depending on the use case, we also utilize the following technologies in addition to SCCM:
- Microsoft Intune – for cloud-based device management
- Microsoft Defender for Endpoint – for proactive threat detection
- Microsoft Entra ID – for secure identity management
- Patch My PC, PSADT and other tools – for automated software deployment and packaging
- Baramundi Management Suite – as an alternative Unified Endpoint Management solution to the Microsoft ecosystem
The result: A well-conceived, efficient, and secure endpoint strategy tailored to our clients' specific requirements.
We hear this question often – the answer is: not necessarily.
Microsoft continues to maintain SCCM, and it remains the gold standard for granular endpoint management, especially for larger or regulated enterprises. While Intune excels with its modern security features and cloud-based advantages, it does not replace SCCM in every scenario. During a project to replace Ivanti DSM for a client, we were able to demonstrate that they would not be able to cover several items in their requirements catalog using Intune alone.
Most of our clients find that the best approach is a co-management strategy – combining the best of both worlds. And that is exactly where our strength lies.
Yes! In addition to classic SCCM consulting and implementation projects as well as reactive on-demand SCCM support, SOFTTAILOR also offers SCCM as a Managed Service. We take care of:
- Operation, maintenance, and updates for your SCCM environment
- Monitoring & troubleshooting
- Continuous optimization
- Optional software packaging and patch management
You gain time for strategic IT topics – we take care of your SCCM and your entire day-to-day endpoint management operations.
SCCM experts possess extensive specialized knowledge and are rare. Consequently, they are among the more expensive IT professionals. One thing is certain, however: having our SCCM experts manage your systems is significantly more cost-effective for companies than building that same expertise in-house and maintaining redundancy on top of day-to-day operations.
Furthermore, an SCCM environment that finally runs stably also saves costs on troubleshooting.
SCCM is not a self-service tool—it requires experience to run stably and securely. Our clients frequently report:
- Complex configurations
- Issues with software deployment
- Missing patches or security vulnerabilities
- Performance bottlenecks
With an experienced partner by your side, you don't have to worry about any of that. SOFTTAILOR knows the pitfalls, best practices, and Microsoft requirements—and ensures that your environment remains reliable, compliant, and maintainable .
Every project with SOFTTAILOR begins with a no-obligation initial consultation. You tell us what you want to achieve – we listen, analyze, and use that information to provide a proposal and quote for the next steps, which we then discuss and refine together.
This is followed by:
- In-depth analysis of your existing IT infrastructure
- Technical design and prioritization
- Implementation by our SCCM experts
- Documentation, knowledge transfer, and – if desired – ongoing support
You can decide for yourself whether you need targeted support or would like to outsource your entire SCCM operation.
SOFTTAILOR provides comprehensive SCCM consulting – tailored, modular, and customized to your specific needs:
- Planning and building a new SCCM environment
- Migration from legacy systems or existing SCCM
- Optimization & health checks for existing installations
- Integration of cloud components such as Intune or Microsoft Entra
- Implementation of patch management processes with SCCM
- Automated software distribution and packaging with and for SCCM
Always with one goal in mind: stable, secure, and future-proof endpoint managementthat truly lightens your workload.
Our SCCM clients are typically large German medium-sized enterprises or government agencies. Client counts range from 300 to 10,000 or more, with the typical number falling between 1,000 and 3,000. In our initial conversations, we often hear things like, "our SCCM is barely holding it together." That is the moment we know we can help.
SCCM and Intune have different strengths – and can be ideally combined with each other.
While SCCM is optimized for classic Windows environments and on-premises scenarios, Intune excels in the cloud – for example with mobile devices (iOS, Android), BYOD (Bring Your Own Device), or Entra ID and Defender integration. With Conditional Access, Intune offers a fully integrated and superior security layer.
A modern setup often consists of a hybrid environment: SCCM for deep system control and server management, Intune for comprehensive security through flexible cloud integration. SOFTTAILOR supports you in achieving the optimal synergy between both worlds – for greater security, flexibility, and automation.
SCCM (System Center Configuration Manager) is a proven Microsoft solution for the centralized management of endpoints – including desktops, laptops, and Windows servers. Unlike cloud-only solutions like Intune, SCCM can be operated entirely on-premises , offering highly granular control over software distribution, patch management, and compliance.
Especially in complex or regulated environments, SCCM stands out due to its mature features, deep integration with Windows systems, and flexible automation capabilities. Another advantage: client management rights are already included in many Microsoft 365 licenses, which saves on additional licensing costs.
SOFTTAILOR supports companies from planning to implementing an optimal Microsoft Entra ID strategy to implement Zero Trust. Existing infrastructures are taken into account as well as individual target images are developed and technically implemented.
The article mentions three allocations:
Entra Registered Devices — for private devices (BYOD)
Entra Joined Devices — for modern, cloud-based work environments
Hybrid Joined Devices — for systems that still need access to on-premise resources but should use cloud services at the same time
Microsoft Entra Joined Devices use the Web Account Manager (WAM) for authentication. WAM provides a seamless SSO experience and is integrated with modern Microsoft services.
These devices are ideal for companies with a flexible BYOD strategy. They enable secure access to corporate resources without the need to fully integrate private devices into corporate IT or manage them centrally.
Authentication is carried out via CloudAP, Microsoft's cloud authentication provider. This technology verifies users and devices as they access cloud resources without the device needing to be domain-bound.
Microsoft Entra Registered Devices are devices that are not members of a domain but are linked to a Microsoft Entra ID tenant. These devices are usually privately managed and are used in BYOD scenarios where employees use their own devices to access corporate resources. In short, Microsoft Entra knows the device but doesn't require the user to use an organization ID to authenticate.
A later switch to Entra Joined — e.g. from Hybrid or Domain Joined — is not possible directly, but only by completely resetting (wiping) the device. Entra Join should therefore be included in device and rollout strategies at an early stage, ideally as part of planned hardware cycles or migrations, for example.
Microsoft itself recommends Entra Joined as a standard for new devices. The reasons for this include:
- New functions are being developed specifically for cloud native endpoints.
- The devices do not require a VPN and can still use all Microsoft 365 and SaaS services.
- Modern features such as SSO, self-service password reset or remote deployment are immediately available.
Despite these very valid arguments, SOFTTAILOR looks at each IT environment individually and works with you to develop the right concept for identity management.
Entra Joined Devices are devices that are fully and exclusively integrated with Microsoft Entra ID — without connection to a local Active Directory. They are typically used in companies that have consistently geared their IT environment to cloud services or are striving to do so. They also speak of Cloud native devices.
Hybrid Join combines the best of both worlds:
- Local on-premise structures such as GPOs and network drives are retained.
- Modern cloud features such as single sign-on and Intune are immediately available.
- Remote work is done without a VPN (via Entra Private Access) possible.
- The transition to the cloud can be gradual, without the need for a radical change in technology
Hybrid joined devices are with two identity systems at the same time connected: with a local Active Directory and with Microsoft Entra ID. These join types are ideal for companies that want to retain existing local IT structures, but at the same time want to use cloud features such as Conditional Access or Intune.
Domain joined devices are devices that operate exclusively in a local Active Directory environment. This model is used when a company operates a completely on-premise based infrastructure — for example with classic AD, file servers and without integration of cloud services.
Microsoft Entra ID supports four types of device enrollments. These differ in how devices are integrated into identity management and which infrastructure (local, cloud, or hybrid) is used:
Domain Joined — for classic, purely local Active Directory environments.
Hybrid Joined — for devices that are connected to a local AD and Microsoft Entra ID at the same time.
Entra Joined — for cloud-native devices that are fully integrated with Microsoft Entra ID.
Entra Registered — for private or BYOD devices that are registered but not domain-bound.
Der Einstieg in eine ganzheitliche Endpoint-Strategie kann schrittweise erfolgen – je nach Reifegrad der bestehenden IT-Sicherheit.
Beliebte erste Schritte sind:
- Einführung von Patch Management as a Service
- Rollout von Microsoft Intune für zentrale Geräteverwaltung
- Pilotprojekte mit Microsoft DefenderDurchführung eines Endpoint-Security-Audits
Ein individuelles Beratungsgespräch hilft dabei, den optimalen Startpunkt zu finden.
SOFTTAILOR bietet maßgeschneiderte Lösungen zur Absicherung von Endgeräten. Unternehmen können zwischen umfassendem Endpoint Management as a Service oder einzelnen Modulen wie Patch Management as a Service wählen.
Zu den Leistungen gehören:
- Zentrale Verwaltung über Microsoft Intune und SCCM
- Automatisiertes Patchen mit Patch My PC oder Robopack
- Implementierung von Zero Trust und Client Hardening
- Integration von Microsoft Defender for EndpointSecurity-Awareness-Programme für Mitarbeitende
Ziel ist es, interne IT-Teams zu entlasten und die Sicherheitslage messbar zu verbessern.
Zero Trust basiert auf dem Prinzip „Vertraue niemandem“. Jeder Zugriff wird überprüft – auch innerhalb des Unternehmensnetzwerks. In Verbindung mit Conditional Access, MFA und Least Privilege wird so maximale Sicherheit erreicht. So können sich Angreifer, falls Sie sich Zugang zu Unternehmensressourcen verschaffen konnten, viel schwerer ausbreiten.
Schulungen sensibilisieren Mitarbeitende für Sicherheitsrisiken. Awareness-Trainings helfen, Phishing zu erkennen, starke Passwörter zu wählen und verdächtige Aktivitäten zu melden.
Endpoint Protection Plattformen, wie Microsoft Defender erkennen Bedrohungen in Echtzeit, analysieren sie KI-basiert und führen eine erste Abwehrreaktion automatisch durch. Sie ersetzen klassische Antivirus-Software durch intelligente Abwehrmechanismen.
Über 60 % der Cyberangriffe basieren auf ungepatchten Systemen. Regelmäßige Updates schließen bekannte Schwachstellen. Viele Unternehmen können neben dem Tagesgeschäft nur schwer mit den immer kürzeren Patch Zyklen mithalten und benötigen automatisierte Prozesse – wie Patch Management as a Service von SOFTTAILOR.
Systemhärtung entfernt unnötige Funktionen, schränkt Benutzerrechte ein und passt sicherheitskritische Einstellungen an. Sie schließt Angriffsvektoren und verhindert auch, dass Angreifer sich im System ausbreiten können, sollten Sie einen Zugangspunkt finden. So wird die Cyberresilienz signifikant erhöht.
UEM ermöglicht die zentrale Verwaltung aller Geräte im Unternehmen. Tools wie Microsoft Intune automatisieren Konfiguration, Update-Rollouts und Sicherheitsrichtlinien – unabhängig vom Standort der Mitarbeitenden.
Eine Kombination aus technischen und organisatorischen Maßnahmen zur Absicherung von Endgeräten – darunter Endpoint Management mit einer Unified Endpoint Management Lösung, Systemhärtung, Patch Management, moderne Endpoint Protection und Security-Awareness-Trainings.
Veraltete Software, überhöhte Benutzerrechte, fehlende Sicherheitsrichtlinien und keine Endpoint Protection sind häufige Schwachstellen. Besonders gefährlich sind Systeme ohne regelmäßige Updates oder MFA.
"Mitarbeitende sind anfällig für Phishing, Social Engineering und schwache Passwörter. Bereits kleine Unachtsamkeiten können zu schwerwiegenden Sicherheitsvorfällen führen – besonders wenn Endgeräte nicht ausreichend geschützt oder zentral verwaltet sind.
Endgeräte sind das Bindeglied zwischen Endanwendern und Unternehmensressourcen und müssen daher Sicherheitslücken durch das Verhalten von Endanwendern so gut wie möglich technisch begrenzen."
Windows Server 2025 offers enhanced security, improved performance, rebootless hotpatching, and comprehensive capabilities for hybrid cloud scenarios. The platform is ideally suited for modern IT strategies.
Another reason: Older versions are reaching end-of-support. Extended support for Windows Server 2012/R2 ended in October 2023, with Windows Server 2016 following in January 2027. Migrating helps avoid security and compliance risks.
Windows Server 2025 supports both physical servers (certified systems from leading manufacturers such as Dell, HP, Lenovo) and virtual platforms like Microsoft Hyper-V, VMware ESXi, and Citrix Hypervisor. Additionally, the management of hybrid scenarios via Azure Arc is fully integrated.
Windows Server 2025 is offered under a per-core licensing model, with a minimum of 16 core licenses required per physical server. Additionally, Client Access Licenses (CALs) are necessary to grant users or devices access to the server.
Editions and Pricing (As of May 2025):
Standard Edition: Starting at approximately 1,035 USD for a 16-core license. This edition permits running two virtual machines (VMs) on a licensed host.
Datacenter Edition: Starting at approximately 5,609 USD for a 16-core license. This edition offers unlimited virtualization rights, ideal for highly virtualized environments.
Note: The prices mentioned are list prices and may vary depending on the provider, region, and licensing program.
Alternative Licensing via Azure:
For customers who prefer usage-based billing, Microsoft offers a pay-as-you-go model via Azure Arc. This incurs costs of 33.58 USD per CPU core per month.
For management, Microsoft Endpoint Configuration Manager (MECM) is still recommended, as Intune is designed for clients and mobile devices and currently does not support server management. Azure Arc is a viable alternative for smaller or hybrid environments, especially when focusing on cloud-based management and reduced infrastructure complexity.
Yes, a direct migration from Windows Server 2016 or 2019 to 2025 is fully supported. For older versions like 2012 R2, an intermediate step is required. Before upgrading, the compatibility of existing applications should be checked.
Minimum Requirements:
- 1.4 GHz 64-bit processor
- 2 GB RAM • 32 GB free disk space
- Gigabit Ethernet adapter
Recommended:
- Multi-core processor with virtualization support
- 4 GB RAM or more
- Additional disk space for roles and features
- Network adapter with enhanced features
Compared to Windows Server 2019, the new version offers a significantly improved security architecture, greater efficiency in virtualization, new management capabilities via Azure Arc, and hotpatching. Integration into hybrid cloud scenarios has also been greatly simplified.
Windows Server 2025 is available in three editions: Essentials for small businesses (up to 25 users), Standard for medium IT environments with up to two virtual machines (VMs), and Datacenter for highly virtualized or cloud-based infrastructures with unlimited VMs. Each edition uses a core-based licensing model.
Hotpatching allows security-relevant updates to be performed without restarting the server. This significantly increases the availability of critical systems. Prerequisites include a connection to Azure Arc, active Software Assurance, and a separate Microsoft subscription for the Hotpatching feature.
Security features have been extensively enhanced. These include improved network segmentation for isolating sensitive data, the integration of Microsoft Defender for early threat detection and defense, and support for modern protocols such as TLS 1.3 and SMB encryption.
Windows Server 2025 introduces numerous innovations focused on security, efficiency, and hybrid cloud integration. Key improvements include enhanced network isolation, the integration of modern Microsoft Defender technologies, optimized virtualization performance, hotpatching, and seamless Azure connectivity.
SOFTTAILOR helps you plan, set up and manage Windows Autopilot 1.0 and 2.0. Contact us for more information.
Hybrid Entra ID Join is currently not supported, as Microsoft prioritizes the use of purely cloud-based scenarios. However, future updates could provide additional hybrid support options.
The key challenge is that devices cannot automatically be assigned to the correct Azure organization without a hardware hash. This increases the risk of deployment errors and additional administrative burdens. Specifically, the following problems arise:
- Lack of unique identification: Without a hardware hash, it is more difficult to uniquely recognize and correctly configure devices.
- Manual assignment required: Since automatic recognition is not required, devices must be manually assigned to groups, for example via Entra ID.
- Limited deployment: Configurations, applications, and profiles might not be applied as planned.
- Security risks: The missing link can lead to confusion, which represents a potential security risk.
Using Autopilot without hardware hashes is possible, but requires careful planning and clean implementation to ensure a smooth rollout.
Microsoft is continuing to develop Autopilot version 2 (v2). Some of the originally announced features have now been implemented, others are still being phased in. These include:
- The reintroduction of self-deployment and pre-provisioning modes, which are now available again.- Expanded customization options in the Out-of-Box Experience (OOBE), such as a progress bar and visible EULA options.
- Tenant binding, i.e. the direct allocation of devices to a specific tenant.
- Improved admin features, such as predefined security policies and automated device renames.
An autopilot version 3 has not yet been announced. For the latest status, it is recommended to take a look at the Microsoft 365 roadmap or the official Autopilot documentation.
The OOBE in Autopilot 2.0 offers:The new OOBE in Windows Autopilot 2.0 offers a significantly improved user experience. An integrated progress indicator now shows how far the deployment has progressed as a percentage. User navigation and transparency have also been improved: Elements such as the End User License Agreement (EULA) and other options are directly visible, giving administrators and users more control over the process.
Autopilot 1.0:
Apps are installed at the same time, which can cause delays.
Autopilot 2.0:
Apps can be prioritized — critical apps like Defender are installed first, while less important apps are added in the background.
Yes, Autopilot 2.0 supports sovereign clouds such as GCC, GCC High and DoD for the first time, making it particularly attractive for government and security environments. However, the Sovereign Clouds mentioned above all relate to the U.S. market so far.
These are the technical requirements for Autopilot 2.0:
operating system: Windows 11 from version 24H2 (or Windows 11 22H2 with KB5035942).
network: Stable internet connection for setup.
Hardware: Devices with UEFI support.
Identity and endpoint management tools: Entra ID and Microsoft Intune.
Windows Autopilot 2.0 is suitable for companies with a pure cloud strategy that need a more modern architecture, real-time monitoring, and sovereign cloud support. So far, there are no really convincing advantages over Autopilot v1.
Companies with hybrid IT infrastructures or complex requirements (e.g. pre-provisioning) continue to benefit from Windows Autopilot 1.0. The support for Hybrid Azure AD Join makes it the only choice for organizations that combine on-premises and cloud identity management.
No hybrid support: Connecting via Hybrid Azure AD Join is currently not supported.
Limited app installation during OOBE: Up to ten applications can be installed as standard during the Out-of-Box Experience (OOBE). (Note: This limit may change with future updates.)
Device name assignment: There are no device name templates available. Configuration is done using Intune policies, which allows for more flexibility but can mean additional administrative work.
Autopilot 2.0 allows you to simplify device deployment without hardware hashes, real-time monitoring, prioritized app installations, and use in sovereign clouds in the USA.
Windows Autopilot 1.0 and 2.0 differ in several important ways:
Registration and device management:
Autopilot 1.0 requires hardware hashes to register devices, while Autopilot 2.0 eliminates this step and allows direct allocation via Entra ID. This significantly simplifies the registration process
.out-of-box experience (OOBE):
In Autopilot 2.0, OOBE is optimized, offers a percentage progress indicator and more control. However, some automations that exist in Autopilot 1.0 are missing, such as skipping the EULA.
Hybrid Support:
Autopilot 1.0 supports Hybrid Entra ID Join, which is important for hybrid IT environments. This feature is missing in Autopilot 2.0, which is only suitable for cloud environments.
Monitoring and app deployment:
Autopilot 2.0 provides improved real-time monitoring and prioritizes important apps such as Microsoft Defender during setup. In Autopilot 1.0, all apps are installed at the same time, which can cause delays.
Sovereign cloud support:
Autopilot 2.0 supports sovereign clouds such as GCC and DoD for the first time, making it suitable for government and security-critical environments. (Currently only relevant for the U.S. market)”
Windows Autopilot automates the process of deploying devices using policies and configurations from the cloud:
Device assignment: Users or groups are automatically assigned to devices.
Deploying apps and configurations: Software and security policies are applied during initial setup.
Management integration: The devices are directly integrated into tools such as Microsoft Intune and, if applicable, SCCM (co-management).
Windows Autopilot is a cloud-based solution from Microsoft that simplifies and automates the deployment and management of Windows devices. The goal is to relieve IT teams and deliver devices quickly and efficiently to end users without the need for physical intervention.
SOFTTAILOR offers tailor-made solutions to implement CIS benchmarks and Microsoft security baselines and make the right decisions:
guidance: Assistance in choosing the appropriate framework.
implementation: Individual adjustment and roll-out of system hardening
Managed system hardening: Regular update of system hardening as a managed service
1. Activate the security baselines in Microsoft Intune or download the latest version of the security baselines for group policies (GPOs).
2. Tailor the guidelines to meet your specific requirements. Great care should be taken here due to the tatooing effect.
3. Distribute the guidelines to the appropriate devices or user groups.
4. Monitor compliance with guidelines and make adjustments as needed.
1. Download the latest benchmarks from the official website
2. Download Microsoft Security Compliance Toolkit 1.0 to compare the already established guidelines with those from CIS Benchmark
3. Set up import/adjustments according to CIS standards
4. Evaluation of individual policies
5. Monitoring of individual policies in a productive environment
6. Observe monthly reports from CIS benchmarks to stay up to date”
Every company should harden clients and servers in particular according to CIS benchmarks and only rely on the Microsoft Security Baselines in exceptional cases, with limited resources or as a supplement.
Specific to Microsoft products: They are optimally tailored to Windows, Microsoft Edge, and other Microsoft technologies.
Easy to implement: Can be used directly via Microsoft Intune or Group Policy.
automation: Reduces manual effort when securing endpoints.
efficiency: Particularly suitable for companies with limited IT resources.
Available for many platforms: CIS benchmarks are available for Windows, Linux, macOS and cloud services such as Azure and AWS, among others.
Flexibility: Companies can individually adapt the benchmarks to their specific needs.
Compliance: They make it easier to comply with standards such as GDPR, HIPAA or ISO 27001 and are internationally recognized as the “gold standard.”
Community-driven: They are regularly reviewed and updated by security experts worldwide.
Hardened Images: Ideal for cloud users who want to use hardened VMs directly.
“The CIS benchmarks are cross-platform and provide detailed, customizable security guidelines for various systems such as Windows, Linux, and cloud services. They are suitable for companies with heterogeneous IT environments and high security requirements, but require more technical expertise and resources.
Microsoft security baselines, on the other hand, are specifically tailored for Microsoft products such as Windows and Microsoft Edge. They're easier to implement, offer less flexibility, but are ideal for small and medium-sized businesses with limited IT resources and Microsoft-centric environments.”
“Microsoft security baselines are predefined security policies developed specifically for Microsoft products. They include recommended settings for Windows, Microsoft Edge, and other applications to ensure security.
Thanks to integration with Microsoft Intune and Group Policy, they are easy to implement and regularly update to cover new threats. They are particularly suitable for companies that need fast and efficient protection of Microsoft products. However, due to limited individual adaptability and the tatooing phenomenon, implementation should be careful.”
The CIS benchmarks are security guidelines developed by the Center for Internet Security. They help you securely configure systems and applications by providing proven best practices. The benchmarks can be used across platforms and are divided into two security levels:
Level 1: Basic security measures with minimal impact on functionality.
Level 2: Stricter configurations for particularly sensitive environments.
In addition, there is the STIG profile (formerly known as “Level 3”), which goes beyond Levels 1 and 2 and includes additional configurations in accordance with the Security Technical Implementation Guide (STIG). This profile is particularly relevant for companies that work on behalf of the US Department of Defense or must meet its security requirements.
CIS also provides hardened, prefabricated images for cloud platforms such as Microsoft Azure and AWS.
SOFTTAILOR übernimmt die vollständige Umsetzung des Cloud Management Gateway – von der Planung über die technische Einrichtung bis zur produktiven Inbetriebnahme. Dank zahlreicher erfolgreich durchgeführter CMG-Projekte verfügt SOFTTAILOR über fundierte Praxiserfahrung und tiefes Know-how im Zusammenspiel von MECM/SCCM und Azure.
CMG ist eine Erweiterung für Microsoft Endpoint Configuration Manager (MECM/SCCM) und ermöglicht die Verwaltung von Geräten über das Internet, ohne auf eine VPN-Verbindung angewiesen zu sein. Die Infrastruktur bleibt größtenteils On-Premises, während CMG als Cloud-Proxy dient.
Microsoft Intune hingegen ist eine reine Cloud-Lösung für Mobile Device Management (MDM) und benötigt keine lokale Infrastruktur. Es verwaltet Geräte direkt über Azure AD, bzw. Entra ID. Darüber hinaus bietet Intune zusätzlich moderne Sicherheitsfeatures wie Conditional Access, Zero-Trust-Funktionalitäten und die native Integration mit vielen M365 Produkten. CMG fügt SCCM keine Features hinzu, sondern bringt vorhandene Features in die Cloud.
CMG eignet sich für Unternehmen, die SCCM beibehalten möchten, während Intune für eine vollständig cloudbasierte Verwaltung mit modernen Sicherheitsfeatures gedacht ist. Beide können in einer Co-Management-Strategie kombiniert werden.
Neben CMG gibt es weitere Möglichkeiten zur Verwaltung von Endgeräten außerhalb des Unternehmensnetzwerks:
- Microsoft Intune: Komplett cloudbasierte Verwaltung ohne On-Premises-SCCM oder im Co-Management mit SCCM
- VPN-gestützte Verwaltung: Klassische Methode über eine gesicherte Unternehmensverbindung
- DirectAccess oder Always On VPN: Microsoft-Technologien für eine persistente Verbindung zu Unternehmensressourcen
Die Implementierung von CMG umfasst folgende Schritte:
- Erstellen eines Azure Resource Manager (ARM)-Diensteinstanz für CMG
- Konfiguration des Cloud Management Gateway Connector Point in MECM/SCCM
- Bereitstellung von Authentifizierungsmechanismen (Azure AD oder Zertifikate)
- Konfiguration der MECM/SCCM-Clients zur Nutzung des CMG
- Testen der Verbindung und Monitoring über die SCCM-Konsole
CMG bietet mehrere Sicherheitsmechanismen, um eine sichere Verwaltung von Endgeräten zu gewährleisten:
- Verschlüsselte Kommunikation über HTTPS
- Authentifizierung mittels Azure AD (Entra ID) oder Client-Zertifikaten
- Integration mit Conditional Access und weiteren Azure-Sicherheitsrichtlinien
- Keine direkte Verbindung von Cloud-Clients zu internen Unternehmensservern
CMG unterstützt verschiedene MECM/SCCM-Workloads, darunter:
- Softwareverteilung und Anwendungsbereitstellung
- Windows-Updates und Patch-Management
- Endpoint Protection (z. B. Microsoft Defender for Endpoint)
- Inventarisierung und Hardware-/Software-Reporting
- Compliance-Richtlinien und Konfigurationsmanagement
Die Kosten für CMG setzen sich aus mehreren Faktoren zusammen:
- Azure-Compute-Kosten für die Bereitstellung des Cloud-Dienstes
- Datenübertragungskosten für den ein- und ausgehenden Netzwerkverkehr
- Speicherkosten für Protokolle und Telemetriedaten in Azure
Die genauen Kosten hängen von der Anzahl der verwalteten Geräte und dem generierten Datenverkehr ab. Eine Kostenabschätzung kann im Azure Pricing Calculator vorgenommen werden.
Um das CMG erfolgreich zu implementieren, sind folgende Voraussetzungen erforderlich:
- Microsoft Azure-Abonnement für das Hosting der CMG-Instanz
- Microsoft Endpoint Configuration Manager (MECM/SCCM) ab Version 1806
- PKI-Zertifikate oder Azure AD-Authentifizierung, bzw. Entra ID, für die sichere Kommunikation
- Ein öffentlicher FQDN für das CMG
- Eine Internetverbindung für die verwalteten Clients
CMG nutzt Microsoft Azure als cloudbasierten Proxy zwischen den verwalteten Endgeräten und der internen MECM/SCCM-Infrastruktur. Die Kommunikation erfolgt über das Internet, wobei Anfragen vom CMG entgegengenommen und sicher an die On-Premises-SCCM-Server weitergeleitet werden. Die Authentifizierung der Clients kann entweder über Azure AD oder Zertifikate erfolgen.
Das CMG bietet Unternehmen mehrere Vorteile:
- Sichere Verwaltung von Endgeräten über das Internet ohne VPN
- Reduzierung der Infrastrukturkosten durch Verlagerung von Diensten in die Cloud
- Automatische Skalierung je nach Lastanforderungen
- Erhöhte Sicherheit durch Authentifizierung via Azure AD oder Zertifikate
- Unterstützung hybrider IT-Infrastrukturen mit Cloud- und On-Premises-Komponenten
Das Cloud Management Gateway (CMG) ist eine cloudbasierte Lösung von Microsoft, die Unternehmen mit SCCM befähigt, auch Endgeräte außerhalb des Unternehmensnetzwerks sicher zu verwalten. Es dient als Proxy zwischen Microsoft Endpoint Configuration Manager (MECM / SCCM) und Microsoft Azure, sodass Clients über das Internet verwaltet werden können, ohne dass eine VPN-Verbindung erforderlich ist.
Patch My PC implements numerous measures that make the use of Patch My PC compliant with GDPR. The company signs Standard Contractual Clauses and meets customer data protection requirements, including audits and a 24-hour response time to security incidents. Patch My PC is also ISO 27001 certified, which ensures high security standards for customer data.
Our experience shows that Patch My PC is also willing to sign individual data protection agreements, such as NDAs or order processing contracts. In practice, the software has already been used by large German law firms, ministries and industrial companies that have high data protection requirements.
Data from European customers is hosted in an Azure data center in West Europe. In the PMPC portal, you can Settings > Company check whether the value “EU” is stored as the data storage location.
The costs of a migration depend on various factors, such as:
- The size and complexity of your infrastructure
- Desired target system (Intune, MECM/SCCM or Ivanti Neurons)
- Number of software packages and configurations
- Required adjustments and additional services
After an initial consultation, we will provide you with an individual offer to replace Ivanti DSM in your company.
We convert your existing Ivanti eScript software packages to the PSADT (Powershell AppDeploy Toolkit) format. PSADT is the globally adopted open-source standard for software packaging and distribution. We advise our clients to carefully evaluate migrating to any format other than PSADT, as it can lead to significant vendor lock-in.
First, we'll jointly analyze your application landscape to determine which applications may no longer be needed or can be automatically provisioned via patch management catalogs like Patch My PC, Robopack, or Neurons for Patch Management.
Client Management Solutions are core components of your IT infrastructure. Replacing Ivanti DSM and implementing a new UEM solution should therefore be well-planned. Typical challenges include:
- Ivanti DSM functionalities that don't have a 100% equivalent in modern systems
- Processes precisely tailored to Ivanti DSM functionalities
- Administrator and user adaptation
- Compatibility issues between old and new systems
- Data loss risks without thorough planning
- High workload alongside daily operations
Our Goal: Migration without frustration.
The Means: Experience in Ivanti DSM, the target system, and meticulous planning.
Many die-hard Ivanti DSM administrators are initially disappointed after a first look at Microsoft Intune. We understand. Ivanti DSM is incredibly mature when it comes to software distribution, almost unmatched by any other product, and had a large following.
Nevertheless, we recommend companies using Ivanti DSM to switch to Microsoft Intune, as the modern Unified Endpoint Management & Security approach opens up a world beyond just software distribution. And regarding software distribution, there are very few scenarios that cannot be accommodated in co-management with Intune and SCCM, making this combination the top choice for most companies. Another important point: Licenses for Intune and SCCM are often already included in your Windows 365 licenses and incur no additional costs.
Ivanti Neurons also offers many of these features, but despite its attractive user interface, it's not yet as mature as Microsoft Intune.
In a workshop, we'll find the right solution for your company!




