The border your zero-touch stops at | The IT Ops Brief

Table of contents

The border your zero-touch stops at



Enrollment before shipping came up in 22% of the customer conversations we analysed — the third most-raised topic out of nearly four thousand. What surprised me was not the frequency. It was that almost every person raising it believed they were describing a configuration problem. They were describing a supply-chain problem, and the distinction changes who can actually fix it.

Global device deployment fails at the border because zero-touch isn’t a setting you enable — it’s a supply chain you either have or don’t, per country and per platform. Autopilot and Apple Business Manager don’t enroll devices; they receive devices that whoever bought the machine registered into your tenant, in the country where they bought it. That makes enrollment before shipping a purchasing question rather than a configuration one, and it is why global device deployment can work in one market and quietly fail in the next. In 3,977 customer conversations, 22.0% of buyers raised it before we did.

The signal: the tools buyers already run

We analysed 3,977 customer conversations from April 2024 to August 2026, counting only what the buyer raised before we did. Getting devices enrolled before they ship: 22.0% — effectively tied with storage (22.8%) and offboarding (22.6%) at the top of the corpus.

The second thing in that data matters more for anyone evaluating vendors in this space. The most-mentioned names are not competitors. They are the tools our customers already run: Intune in 479 conversations, Apple Business Manager in 274, Jamf in 190, CDW in 118. Every direct competitor combined sits well below that.

So the real question in most evaluations is not which lifecycle vendor. It is do we need one, given we already have an MDM and a reseller. That is a reasonable question, and the answer has nothing to do with those tools falling short. They do precisely what they are built to do.

The problem: registered is not enrolled

Here is the sentence I wish someone had said to me earlier:

Autopilot and Apple Business Manager do not enroll devices. They receive devices that somebody else registered.

A serial number or hardware hash has to be pushed into your tenant by whoever physically purchased the machine, in the country where they purchased it. That is a supply-chain action. Your MDM sits downstream of it, waiting to be handed something.

Once you see it that way, a set of otherwise baffling patterns resolves into one cause.

Your enrollment map is not your country map

Same company, same tenant, same configuration profile — and automatic enrollment available in two markets, a manual hardware-hash extraction required in the one next door, and nothing at all in a handful of others. Nothing about the company changed across those borders. The purchasing channel did. Most IT teams have never seen their own enrollment matrix written down, because nobody thinks to ask for a document that describes a capability they assume is global.

Published availability is not provisionable availability

A platform vendor’s own documentation can state that a capability is supported in a market where teams on the ground cannot actually provision it. Both facts are true simultaneously — the documentation describes policy, the market describes operations — and only one of them is discoverable before you have designed a deployment model around it. This is not a criticism of any vendor. It is a warning about which source to trust when you are planning.

Registered is not enrolled, and enrolled is not provisioned

This is the failure I would most want IT leaders to internalise, because it is invisible. A hardware hash uploads successfully. The device appears in your console. Registration genuinely completed. And the deployment profile still shows as unassigned, because a dynamic group never picked the device up. The chain runs: hash uploaded → group identifies the device → device joins the group → profile assigns → device receives your configured setup. Five links. The breaks at links two and three generate no error, no alert and no ticket. The first person to discover the problem is a new hire in another time zone, opening a box and getting a consumer setup screen.

The pipeline was built for onboarding and quietly does not cover refreshes

Enrollment instructions present correctly on a new deployment and get skipped on a swap or a refresh, because the process was designed around new hires. Refresh volume is usually larger than hiring volume, and it is the lane nobody tested.

Somebody outside your IT team needs keys to your tenant

Automatic enrollment requires delegated access — an enrollment administrator account, a tenant ID, credentials. That is an access-control decision about who holds it, scoped how, and revoked when. It consistently arrives disguised as a technical prerequisite, and it stalls deployments for weeks because no one has been assigned to answer it.

And your reseller is probably not holding stock for you

Payment can be released and the unit still never reserved, because distributors do not hold inventory outside high-volume commitments. Availability quoted at order time is not availability held. Most IT teams assume ordering means holding. It generally does not.

Put those together and the conclusion is uncomfortable but clarifying:

Zero-touch is not a setting you enable. It is a supply chain you either have or do not have, per country, per platform.

Which produces the part I find genuinely unfair. When the laptop arrives unconfigured, the ticket goes to IT. It reads like an IT failure. It was determined months earlier on a purchase order, by someone optimising for unit price who was never told the choice had anything to do with device configuration.

The operator takeaway: five moves before your next vendor call

  1. Get your enrollment matrix in writing. Country by country, platform by platform, and — critically — distinguishing automatic from manual. “We support enrollment there” and “we support automatic enrollment there” are different claims. Make whoever supplies your hardware put it in a document.
  2. Verify profile assignment, not registration. Most teams check whether a device is registered. The query that predicts the employee’s actual experience is whether a deployment profile is assigned. Same console, different question, and only one of them tells you what will happen when the box opens.
  3. Test your enrollment path on a refresh, not a new hire. The onboarding lane is the one that gets attention and the one that works. Run a swap through the process and see whether the configuration steps still apply.
  4. Treat delegated MDM access as an access-control decision, and make it before you need it. Decide who holds enrollment credentials, at what scope, with what revocation path. Deciding this under time pressure, mid-deployment, is how it gets scoped badly.
  5. Re-audit on every market expansion. Adding a country silently creates an unconfigured lane. The standard you wrote does not automatically extend to a market it was never written for.

Before your next vendor conversation, five questions worth asking:

  • Which countries support fully automatic enrollment for our platforms, and which require manual steps?
  • Who registers the serial into our tenant, and what access do they need?
  • What happens when a device is registered but no profile attaches — who notices, and how?
  • Does this process apply to refreshes and swaps, or only new deployments?
  • What is your time from order to enrolled and shipped, not order to shipped?

One GroWrk lens

This is the part of the stack we operate, and the honest framing is that we are one link in a chain rather than a replacement for any of it. Modern IT runs on three layers.

  • Identity — Okta, Entra — governs who someone is.
  • Digital endpoint management — Intune, Jamf, Kandji — governs what a device is allowed to do.
  • The physical layer — procure, deploy, store, retrieve, repair, redeploy, retire — is the one that never got automated.

Layers one and two were solved years ago. The third still runs on email, spreadsheets, and whoever happens to be in the right country.

ITAM records the asset. MDM controls the asset. GroWrk executes the physical lifecycle.

Buying in-country and registering the serial into the customer’s tenant before the device ships is that handoff, done deliberately, in markets where it is possible — and said plainly where it is not. I would be wary of anyone claiming automatic enrollment everywhere. The honest answer to “which countries?” is a matrix, not a number, and the vendors worth working with will show you theirs.

One stat

22.0%. The share of 3,977 customer conversations in which the buyer raised enrollment before shipping unprompted — the third most-raised topic in the corpus, behind storage (22.8%) and offboarding (22.6%). All three sit in the middle of the device lifecycle.

(GroWrk Call Intelligence — analysis of 3,977 customer calls, April 2024 – August 2026. Buyer-led mentions only.)

The tools were never the missing piece. A sophisticated company with the right MDM, a real budget and a careful configuration profile can still fail to get a laptop to arrive ready — because the step that makes it possible happens before IT is involved, in a country somebody else chose.

Ask for the matrix.

If you want to see what that matrix looks like when one team runs the physical layer, we would be glad to show you.

Book a demo →

Carlos N. Escutia

Written by Carlos N. Escutia. Carlos is the Founder and CEO at GroWrk. He has spent the last 7 years building GroWrk into a platform that specializes in managing the entire IT device lifecycle.