Skip to content
idMfocxD0h_logos

How Innocean improved Mac device management after transitioning from its previous MDM solution

The challenge

Innocean is the advertising agency behind national campaigns for Hyundai, Genesis, and Kia, operating from Huntington Beach with close to 1,000 employees and an IT team of fewer than 10 members. Managing endpoint devices is only one of many responsibilities handled by the IT team, which is one reason device management had historically been outsourced.

Before adopting Iru, Innocean's Mac environment was managed through a previous MDM platform that did not provide the administrative access necessary for a seamless transition. Without sufficient control over the existing environment, the IT team was required to manually integrate devices and rebuild management coverage across hundreds of Macs while continuing to support day-to-day business operations.

The challenge extended beyond migrating devices into a new platform. Innocean needed a more effective operating model that would provide clear visibility into device ownership, support consistent policy enforcement, and enable IT to respond quickly when employee status changed due to offboarding, leave of absence, or device transfers.

"We support a lot of proprietary client work, so we need to know where every device is and who has it. That was difficult to answer reliably with the access we had before."

For an organization managing sensitive client work, accurate device accountability was not simply an operational requirement. It was a foundational component of security, compliance, and risk management.

The solution

Centralizing Mac management after an MDM transition

With more than 500 Mac devices to transition, the IT team used the move to Iru as an opportunity to redesign its device management approach around visibility, consistency, and operational control.

Rather than relying on fragmented manual processes inherited from the previous environment, the team established a structured framework for device enrollment, assignment tracking, and policy deployment across the Mac fleet.

As the team refined its operational processes, one principle became central to device management:

"Knowing which user each device is assigned to, when it last checked in, and whether it is locked or erased gives us the visibility we need to manage the fleet effectively."

This visibility became particularly valuable during employee transitions, where delays in device recovery or gaps in management coverage can increase the risk of lost, misplaced, or unsecured equipment.

Applying policy while maintaining a practical user experience

Innocean also strengthened the way policies are enforced in day-to-day operations.

For offboarded employees and users on leave of absence, IT can remotely lock devices while equipment is being returned, stored, or shipped. This additional layer of control helps protect company information and reduces exposure during periods when devices are outside normal operational oversight.

The impact of this capability was immediate:

"When someone leaves, we can lock the device right away instead of waiting to see when it comes back. That closes a gap that used to stay open."

At the same time, Innocean wanted to ensure security improvements did not come at the expense of employee productivity.

To support that goal, commonly used business applications are available through the Self Service portal, allowing employees to install approved software without requiring unrestricted administrative access.

For situations requiring elevated privileges, IT can grant temporary administrator rights through approved scripted workflows. This approach gives employees the flexibility needed to complete legitimate business tasks while helping maintain control over software installation and system configuration.

The operational benefits extended to the IT team as well:

"We're not filing a request and waiting on someone else anymore. If something needs to change on a device, we can do it ourselves."

By reducing external dependencies, the team gained the ability to respond more quickly to business needs while maintaining governance standards.

Results

Innocean now has a more reliable and scalable way to manage its Mac fleet throughout the entire device lifecycle, from enrollment and daily support to employee status changes and device return processes.

The organization has improved visibility into device ownership and status, enabling policies to be applied more consistently while ensuring employees retain access to approved applications and support resources.

Compared with the previous MDM model, the IT team can now take direct action to secure devices, support employees, and enforce internal standards without relying on limited administrative access or extensive manual follow-up.

The result is a more efficient operating model with reduced operational friction, stronger accountability, and greater confidence in the security and management of the organization's Mac environment.

 

image1

Looking ahead

With its Mac fleet now under stronger internal management, Innocean is focused on continuing to refine the policies and workflows that balance security, usability, and operational efficiency.

The team also has greater flexibility to implement targeted controls for specific scenarios, including leave-of-absence management, device replacement programs, software access requests, and equipment return logistics, without reverting to labor-intensive manual processes.

For a small IT team supporting a fast-moving creative organization, the transition has created a foundation for stronger security, clearer accountability, and a better overall experience for employees using Mac devices.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.