SCCM at one employer, KACE at another — the same cloud-native destination, reached by a different migration strategy each time. ~8,000 endpoints, both now on Autopilot zero-touch.
Two employers, two legacy on-prem management stacks, one target: cloud-native Intune. The interesting part isn't the destination — anyone can say they moved a tool to Intune. It's that each estate needed a different migration strategy, and choosing the right one is the actual job.
At the SCCM shop the answer was co-management: build Intune to run alongside a mature SCCM estate and move workloads over gradually. At the KACE shop the answer was the opposite: a KACE appliance with no coexistence path, so a clean replacement and decommission. Below is each, and why.
This employer ran an established SCCM estate that I didn't own. A big-bang cutover was off the table — too much depended on it, and disruption wasn't acceptable. So I built the Intune side to coexist: enable co-management, then move one workload at a time (compliance, then configuration, then updates, then apps) as each proved out, until Intune could stand on its own.
This was also a from-zero Intune build. Autopilot enrollment, EAP-TLS certificate Wi-Fi via ADCS, and 600+ Win32 apps packaged to a repeatable standard — consistent detection rules, silent installers, and deployment rings that the team still builds against.
This employer ran an on-prem Quest KACE appliance: software distribution, scripting, patching, inventory, and a bench imaging workflow all tied to a box on the network. There was no gradual coexistence path the way SCCM offers — so the strategy was replacement, not coexistence. Stand up Intune, cut cohorts over ring by ring, remove the KACE agent, and decommission.
Imaging was the sharpest win. It took over a day to set up a machine and steps were regularly missed. Autopilot — now live — replaced it outright: a device registers to the tenant and provisions itself on first boot, with nothing left to miss. In parallel, a self-service software catalog replaced a request queue where a single app could take weeks.
And it isn't Windows-only: at both employers macOS came under the same Conditional Access posture through Jamf — that build is written up separately.
I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.