Workplace management that simply works. For everyone, everywhere.

Get new colleagues productive immediately and keep existing workplaces up to date. We manage your entire Microsoft 365 environment, Intune, Autopilot, and endpoint security.

Illustration of a managed and secured digital workplace.
24/7
Monitoring and support
150+
Happy customers
13
locations in the Netherlands
350+
Endpoints under management

Management throughout the entire lifecycle

From the moment a workplace is ordered until it is returned, we manage every phase.

  1. Ordering – The right device for each role, registered and shipped to the employee.
  2. Deployment – Zero-touch rollout via Autopilot. Sign in and get to work.
  3. In-life – Ongoing updates, security, support, and compliance.
  4. Refresh – Role changes or replacement without downtime.
  5. Offboarding – Remote wipe, return, and reuse or recycling.
Illustration of a centrally managed and secured device.

How we configure the Microsoft workplace

We configure and manage all four layers of the Microsoft ecosystem. No separate tools running alongside one another, but one cohesive setup.

Entra ID forms the foundation for all access. We configure role-based groups with dynamic membership, so new employees automatically receive the right licenses and applications. Conditional Access policies determine the conditions under which someone can gain access: only from compliant devices, with MFA, from trusted locations, or with a low sign-in risk. For passwordless sign-in, we deploy RSA, Windows Hello for Business, or FIDO2 keys. Privileged Identity Management protects admin accounts with just-in-time access and approval workflows. Read more about our identity governance services.

Microsoft Intune provides a single pane of glass for all endpoints: Windows, macOS, iOS, and Android. New devices are deployed through Autopilot with zero-touch deployment: the employee signs in and the device configures itself for their role. We manage configuration profiles, security baselines based on CIS or Microsoft standards, app deployment for Win32, MSI, and Microsoft Store apps, and update rings for Windows and Microsoft 365 apps. Updates are rolled out in stages through pilot and production groups to prevent disruption.

Microsoft Defender for Endpoint runs on every workplace and is centrally managed from Intune. We enable attack surface reduction rules, controlled folder access, and network protection. BitLocker encryption is enforced on all Windows devices, with recovery keys stored securely in Entra ID. For the data itself, we use Microsoft Purview: sensitivity labels, DLP policies to prevent data leaks, and app protection policies that containerize business data on personal devices (BYOD). All endpoints report to one central location, so suspicious behavior is immediately visible. For maximum protection, choose our endpoint detection and response (EDR) service.

Compliance policies in Intune continuously verify that devices meet the requirements: current OS version, active encryption, no jailbreak, and up-to-date antivirus protection. Conditional Access automatically blocks non-compliant devices from business resources until they have been remediated. You receive monthly reporting on compliance scores, vulnerabilities, and remediated issues. This directly supports ISO 27001 and NIS2 requirements for access control, asset management, and incident detection. Logs and audit trails are available for audits.

Illustration of the handover and management of a digital workplace.
The choice for your organization

Everything taken care of.

From provisioning to replacement, and from policies to warranty: everything involved in workplace management is handled by one partner.

Provisioning & configuration

Autopilot profiles by role, standard applications, and corporate branding.

Patch and update management

Controlled rollout of Windows and application updates.

Security policies

Conditional Access, MFA, BitLocker, Defender, and compliance rules.

Replacement & warranty

Device monitoring, timely replacement, and RMA handling.

Every workplace is an attack surface.

The modern workplace operates everywhere: at the office, at home, and on the road. That makes endpoints your largest attack surface. We secure them according to zero-trust principles: strong identity controls, encrypted devices, least privilege, and continuous monitoring.

EDR solutions for real-time threat response
MFA and passwordless authentication
Remote wipe in case of theft or loss
Device encryption (BitLocker) on every workplace
Illustration of Endpoint Detection and Response for securing endpoints.
The most critical companies trust us
Customer stories

Trusted by IT leaders in the Netherlands

The IT and security partner of Dutch organizations for more than 25 years.

These network improvements have ensured that Sint Jacob once again dares to trust their IT partner.

Ronald van Rossum

Sint Jacob

We don't have an in-house IT professional, but we still need to safeguard our quality and continuity.

Stefan Jansen

Uniglobe THL Travel

Before and during the transition to the cloud we were well supported. They trained our staff on working online. Even after the migration they continued to support us and provided excellent aftercare.

Tessa Schulte

Uniglobe THL Travel

Working fully in the cloud saves us costs and ensures we can serve our clients with maximum flexibility.

Will van der Zande

De Beer Accountants en Belastingadviseurs

An IT company with all expertise under one roof — that is a real USP for us.

Marloes van den Bersselaar

Mamaloes

Technology partners

Technology is powerful. Integration is crucial.

We work with leading technology partners, but technology alone won't protect you. The right configuration, monitoring, and governance make the difference.

View all partners
ISO 27001

Security according to demonstrably high standards

When it comes to security, you don't want to rely on separate agreements or good intentions. With our ISO 27001 certification, you know that information security is structurally organized, controlled and improved.

Careful handling of sensitive business data
Structural risk analyses and improvement measures
Independent audits of our security processes
Contact Sales
Illustration of Aumatics ISO certification.

Broad coverage with central expertise

You get one central point of contact, with the strength of a regional presence and specialized hubs across the country. This way, you benefit from local involvement and shared knowledge.

13
Locations in the Netherlands
Plan een security intake
Map of the Netherlands showing Aumatics locations.
Leeuwarden
Groningen
Rotterdam
Heeswijk-Dinther
Eindhoven
Tilburg
Utrecht
Amersfoort
Amsterdam
Alkmaar
Zwaagdijk
Purmerend
Zoetermeer

FAQ

Frequently asked questions about outsourcing workplace management

These are the questions that organizations often ask us. Do you have another question?

Is your question not listed?

No problem. Feel free to let us know what questions you have!

Ask your question in person

Workplace management covers the complete management of your employees’ digital workplaces: laptops, Microsoft 365, Intune, updates, security policies, and support. The goal is for everyone to work smoothly on any device and from any location. We manage it end to end.

We generally charge a price per workplace per month, depending on the scope—management only or including hardware—and the required SLA. During an intake, we assess your situation and provide a transparent proposal.

Every workplace receives Microsoft Defender for Endpoint, BitLocker encryption, Conditional Access policies, and compliance policies enforced through Intune. Each month, you receive a report on compliance scores, detected threats, and recommendations. Our approach is ISO 27001-ready.

Get in touch

Ready to outsource workplace management? Start with a conversation.