Flagship A consulting engagement, not a subscription — I build the pipeline in your repo and hand it off. Request a scope call
Windows · macOS · iOS — one control plane

Run Intune
like software.
Intune DevOps.

Intune is a unified endpoint management platform, and almost nobody runs it as one. Most estates keep SCCM for Windows, Jamf or nothing for Mac, and a separate MDM for phones — three toolchains drifting apart, with scripts holding the seams together.

I consolidate that onto one plane and then run it the way software is run: configuration-as-code, CI/CD across GitHub Actions and Azure DevOps, drift detection with attribution, staged rollout rings, and point-in-time restore — documented and handed off so your team owns it.

4
Pipelines
Your
Repo & data
0
Lock-in
LIVE
intune-backup — GitHub Actions
# Nightly drift detection — 01:00 PT Running Intune backup... 1,884 objects backed up to IntuneBackup/ Detecting configuration drift... Drift detected — 3 file(s) changed   # Graph audit log enrichment 📌 deploy_automation (service principal) 📌 j.martinez (console change) 📌 unattributed — Settings Catalog   Branch drift/2026.03.18_01.00 pushed Teams notification sent
Who this fits
ENTERPRISEHEALTHCAREFINANCEEDUCATIONMSP

A different method, not a cheaper product

There are two ways to get configuration history out of a tenant.
One is a subscription. The other is a pipeline you own.

The subscription route

  • Recurring per-seat subscription
  • Your configs live in their cloud
  • Black-box comparison you can’t inspect
  • Snapshot-only version history
  • Restore = open a support ticket
  • Cross-tenant compare = enterprise add-on
  • Per-user pricing scales with headcount
vs

The pipeline route — yours

  • You own the pipeline outright — no subscription
  • Your repo, your data, your audit trail
  • Every line is yours to inspect and extend
  • Full git history with field-level diffs
  • One-click restore with dry-run preview
  • Cross-tenant comparison built in
  • Scales with your tenants, not your headcount
$0

recurring licence cost — you own the pipeline outright, and it scales with your tenants rather than your headcount

What gets built

What's in your repo when I leave.

Not a product you subscribe to — eight things that exist in your own repository, under your own control, after the engagement ends.

Apps & Scripts as Code

Applications and scripts deploy from declarative manifests, schema-validated before merge. Your team ships endpoint changes through pull requests and never opens the Intune console to do it.

Insider Channels, One Tenant

Segregated release channels built on device categories — run an insider or pilot ring inside your production tenant with no second tenant and no extra licensing. Moving a device between channels is an attribute change, not a re-enrollment, so it takes seconds and never wipes the machine.

Automated Daily Backup

Every policy, profile, script, and app config backed up to JSON in your GitHub repo. Runs nightly, zero manual effort.

Drift Detection & Attribution

Know exactly who changed what in the Intune console — enriched from the Microsoft Graph audit log with UPN-level attribution.

Change Reports

Field-level diff reports in HTML and Excel. Filter by policy type, platform, author, or assignment group. Per-commit timelines.

Cross-Tenant Comparison

If you do run separate tenants, compare Dev, Test, and Prod side by side. Deep-diff JSON configs, spot missing policies, flag assignment discrepancies.

Point-in-Time Restore

Roll back to any git commit, tag, or branch. Dry-run mode previews every change. Environment approval gates protect production.

Teams Notifications

Drift alerts, pipeline results, and restore confirmations pushed directly to your Teams channels. Stay informed without the noise.

How it works

Four pipelines. One repo. Windows, macOS and iOS in the same place.

Pipeline 01

Backup & Drift

Nightly backup with audit-enriched drift detection

Pipeline 02

Change Report

Field-level diff reports in HTML + Excel

Pipeline 03

Compare Tenants

Cross-environment deep JSON comparison

Pipeline 04

Restore

Dry-run, selective restore, approval gates

The Engagement

How we work together

A scoped consulting engagement, priced to the project — not a subscription. You keep everything I build.

Step 01

Scope

Assess your tenants, tooling, and goals; agree on outcomes and a fixed scope.

Step 02

Build

Stand up the config-as-code repo, CI/CD pipelines, and guardrails in your environment.

Step 03

Document

Runbooks and diagrams so the pipeline is understood — not a black box.

Step 04

Hand off

Train your team and transfer ownership — no lock-in, no ongoing dependency on me.

Request a Scope Call → Book a Consult

Built on IntuneCD — and well past it

Tenant backup and reference snapshots run on IntuneCD, the open-source Intune backup engine. No reason to reinvent that, and you get a tool with a community behind it rather than something only I understand.

What I build on top is the part that isn’t available off the shelf: applications and scripts deployed declaratively, so your team ships endpoint changes through pull requests and never opens the Intune console to do it. Schema validation before merge, staged rollout rings with enforced canary caps, a blast-radius approval gate that halts on newly-broadened targeting, and drift detection between declared and live state — all running as GitHub Actions in your own repo, documented and handed off. Endpoint automation and infrastructure delivery, based in Seattle.

Your configs deserve
version control.

Let's scope your Intune DevOps pipeline. No vendor lock-in — just your policies, in your repo, under your control, run like software.

Request a Scope Call → About The Kelsicks