Andrew Yeoman / Case studies / Legacy → Intune
Case study · Endpoint re-architecture

Two legacy stacks, retired into Intune

SCCM at one employer, KACE at another — the same cloud-native destination, reached by a different migration strategy each time. ~8,000 endpoints, both now on Autopilot zero-touch.

Scope
~8,000 endpoints, 2 employers
Stacks retired
SCCM · KACE
Strategies
Co-managed · Rip-and-replace
Result
Autopilot zero-touch, both
The thesis

Same destination, twice — and a different route each time.

Two employers, two legacy on-prem management stacks, one target: cloud-native Intune. The interesting part isn't the destination — anyone can say they moved a tool to Intune. It's that each estate needed a different migration strategy, and choosing the right one is the actual job.

At the SCCM shop the answer was co-management: build Intune to run alongside a mature SCCM estate and move workloads over gradually. At the KACE shop the answer was the opposite: a KACE appliance with no coexistence path, so a clean replacement and decommission. Below is each, and why.

Legacy function (SCCM / KACE)
Cloud-native equivalent
Software distribution & packages
Intune Win32 apps (.intunewin) + deployment rings
Scripts & break/fix (KScripts, SCCM scripts)
Intune proactive remediations + platform scripts
On-prem patching
Windows Update for Business rings
Imaging (task sequences, KBE bench)
Windows Autopilot — zero-touch, no golden image
Inventory & asset records
Intune hardware inventory + Entra device objects
On-prem site servers / appliance
Cloud console, managed from anywhere
Migration 01 · SCCM

The SCCM estate — co-managed, gradual.

Strategy · Co-management

Built the Intune side alongside an SCCM estate I didn't manage, then shifted workloads over incrementally.

~4,500 endpoints

This employer ran an established SCCM estate that I didn't own. A big-bang cutover was off the table — too much depended on it, and disruption wasn't acceptable. So I built the Intune side to coexist: enable co-management, then move one workload at a time (compliance, then configuration, then updates, then apps) as each proved out, until Intune could stand on its own.

This was also a from-zero Intune build. Autopilot enrollment, EAP-TLS certificate Wi-Fi via ADCS, and 600+ Win32 apps packaged to a repeatable standard — consistent detection rules, silent installers, and deployment rings that the team still builds against.

Intune (from zero)Co-managementWorkload slidersAutopilotADCS EAP-TLS600+ Win32 appsPowerShell
Migration 02 · KACE

The KACE estate — clean replacement.

Strategy · Rip-and-replace

Appliance-bound estate with no coexistence path, so Intune replaced KACE outright — then the appliance was retired.

~3,500 endpoints · nine sites

This employer ran an on-prem Quest KACE appliance: software distribution, scripting, patching, inventory, and a bench imaging workflow all tied to a box on the network. There was no gradual coexistence path the way SCCM offers — so the strategy was replacement, not coexistence. Stand up Intune, cut cohorts over ring by ring, remove the KACE agent, and decommission.

Imaging was the sharpest win. It took over a day to set up a machine and steps were regularly missed. Autopilot — now live — replaced it outright: a device registers to the tenant and provisions itself on first boot, with nothing left to miss. In parallel, a self-service software catalog replaced a request queue where a single app could take weeks.

IntuneAutopilotKACE decommissionUpdate RingsProactive RemediationsSPFx self-service catalogGraph API
The outcome

The numbers that matter to the people using the machines.

Device provisioning
1+ day, steps missed Zero-touch
Autopilot (live) replaced day-long bench imaging — nothing left to miss.
Single app request
Weeks Under 1 hour
Self-service catalog replaced the manual request queue.
Endpoints off on-prem
~8,000 Cloud-native
Across two employers — SCCM and KACE both retired.
Management reach
On-network only Anywhere
No site server or appliance to phone home to.

And it isn't Windows-only: at both employers macOS came under the same Conditional Access posture through Jamf — that build is written up separately.

Get in touch

Let's talk.

I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.