A workstation ready on arrival In thirty minutes.
Three offices, 40 Macs and 70 Apple devices. A new workstation sets itself up, with no technician on site.
- Client
- ai4 Architecture Architecture practice
- Locations
- Geneva, Lausanne, Porto Three offices, one team
- Scope
- 40 Macs, 70 devices Apple laptops and mobiles
- Solution
- Centralised management Deployment and encryption
Contents
ai4 Architecture, three offices in Geneva, Lausanne and Porto.
ai4 Architecture designs and delivers its projects from Geneva, Lausanne and Porto, and hires regularly to see them through. 40 Macs and 70 Apple devices in service, two offices opened in a few years, a growing team. Opening an office in Lausanne also means needing IT support in Lausanne to the same standard as Geneva.
Visit ai4 ArchitectureGrowth outpaced the infrastructure.
The infrastructure was still that of a small practice: personal accounts holding company data, workstations built by hand, and no certainty about what was encrypted. None of this kept the firm from working.
Every hire cost half a day on site, every departure raised the question of the data left on the machine, and each office organised things its own way.
Three decisions that stopped being reasonable.
None of them is negligence. They were taken when everyone fitted in a single room, and nobody had a reason to revisit them when the firm opened two new offices.
Growth outpaced the infrastructure
Two more offices opened in a few years, a team hiring regularly, and the same technical foundation as when everyone fitted in a single room.
IT was nobody’s job
It ran on goodwill: every workstation was set up by whoever was free that day, machine naming followed their own logic, and no one kept the inventory.
The tools worked
A calendar shared from a personal iCloud account works perfectly well. Until the day the person leaves, and the calendar leaves with them.

One console for the whole fleet.
Centralised management of the Apple fleet
We enrolled the devices in a dedicated Apple management solution. Every Mac, iPhone and iPad is now visible from a single console, with its status, system version and compliance.
We automated machine naming. A machine names itself, based on its model, hardware identifier and user. No more verbal convention, no more exceptions.
Deploying a new workstation
A new Mac is delivered straight to the employee. On first power-up, it joins the firm’s fleet automatically, applies the settings, installs the business applications and turns on encryption.
The employee is up and running in about thirty minutes. A few simple steps remain on their side: creating their session and confirming their settings. The essential happens without an on-site visit.
Deploying a workstation
Leaving consumer cloud accounts behind
We migrated the shared calendars and contacts out of personal iCloud accounts, into an environment dedicated to the firm, built on open standards (CalDAV and CardDAV).
Two concrete consequences. Business data no longer depends on an employee’s personal account. And the day someone leaves the firm, the company’s calendar and address book stay with the company.
Encryption, across the whole fleet
FileVault, the Mac’s built-in encryption, is active across the whole fleet, with recovery keys held centrally.
A laptop forgotten on a train is no longer a data incident, it is a hardware incident.
A hire without half a technical day.
Preparing a workstation
30 min
A new Mac delivered to the employee joins the fleet on its own, applies the settings and turns on encryption. Before, the same operation took about 1h45 on site.
Fleet encrypted and inventoried
100 %
Every Mac, iPhone and iPad is visible from a single console, with its status and compliance. Encryption is active on every Mac, with recovery keys held centrally.
What changed for the firm is not just the time saved. A hire no longer requires setting aside half a technical day. A departure no longer raises the question of what stays on the machine. And management knows, at any moment, which devices are in service and in what state.
A known fleet, a workstation ready on delivery.
For the firm
The risk, before
Half a technical day per hire, on site; no reliable inventory; and three offices each organising things their own way, with no shared rule.
The benefit, since
About thirty minutes of preparation per workstation, with no site visit or technician; a single console for the three offices; and a known state for every device before the incident, not after.
For employees
The risk, before
A workstation set up as availability allowed, a calendar shared from a personal account, and a laptop nobody knew was encrypted.
The benefit, since
A new Mac delivered directly, up and running in about thirty minutes, shared tools that no longer depend on someone’s account, and business data that stays with the company after a departure.
Testimonial
Our job is to design buildings, not to administer computers. Today all three offices run on the same fleet, under the same rules, and we no longer have to think about it.
Three decisions to take at fifteen devices.
- Enrol devices in a management console from the first Mac, when there is only one to enrol.
- Separate work accounts from personal accounts before the first shared calendar settles on one of them.
- Check that a workstation is encrypted when it is handed over, rather than when one goes missing.
This foundation made it possible to go further: telephony across the three entities, then securing access. None of it would have held without first putting the fleet itself in order.
Your fleet, now
Start by counting your machines.
Devices, compliance, operational gaps. We look at what you already have, then we tell you what is missing. No commitment.
Book an Apple audit