Apple Endpoint Management
Designed and deployed a complete Mobile Device Management (MDM) solution alongside my business partner for Project Optimism, a California-based nonprofit dedicated to strengthening local communities through community engagement events, educational consulting, and college preparedness initiatives. We transformed their individually configured MacBooks into a centrally managed, secure, and standardized fleet across their Long Beach and Sacramento offices, implementing zero-touch enrollment to simplify device provisioning. We also developed comprehensive documentation to support ongoing IT operations, ensuring consistent security policies, streamlined application deployment, and a scalable device management framework that can grow alongside the organization.

The challenge
Our client had 24 MacBooks with no centralized management and no access to Apple Business Manager. The lack of an Apple Business Manager account meant our options for direct control were limited. Each device had to be configured by hand, security posture was inconsistent, and there was no efficient way to push applications, enforce encryption, or onboard new machines.
On top of this, they needed something affordable for an organization their size, light on ongoing overhead, and simple enough to hand off to a non-technical team to run day to day.
What we did
We built the fleet from scratch and handed back a system the team could run on their own:
- Set up and configured the Mosyle Business account for automated, zero-touch enrollment.
- Built the Mosyle tenant from the ground up with device groups, naming conventions, enrollment profiles, and admin structure.
- Configured Automated Device Enrollment (ADE) so devices provision themselves on first boot, with no manual per-machine setup.
- Hardened security with configuration profiles enforcing FileVault encryption, firewall, system-update policies, and device restrictions for a consistent baseline.
- Packaged and pushed core business applications to every device automatically, removing the need for users to install software by hand.
- Enrolled and validated all 24 devices, verifying policy application, encryption status, and app delivery on each machine.
- Produced admin documentation and trained the internal team to operate the system independently.
The outcome
The business went from 24 individually managed laptops to a unified, secure fleet with:
- Enterprise-grade device management at a cost that fit a small company, with room to scale as the business grows.
- Zero-touch onboarding — new devices provision automatically with no manual setup.
- A consistent security baseline, with encryption and policies enforced fleet-wide.
- Automated app delivery pushed centrally instead of installed by hand.
- A self-serviceable system, documented and handed off for the internal team to manage.