Client Profile
The client is a global engineering and architectural services organization specializing in complex structural and civil engineering design. Its teams support large-scale infrastructure projects, including bridges, and depend on specialized engineering applications and high-performance computing environments.
With operations across 22 sites in the United States and one office in India, the client needed a consistent way to manage and secure endpoints across a geographically distributed workforce while maintaining the availability of business-critical engineering applications.
Challenges
- Inconsistent endpoint governance: Managing and securing endpoints across multiple locations required a standardized approach for consistent security and operational practices.
- Patching without disrupting productivity: Specialized engineering applications required patches to be carefully validated before deployment to minimize compatibility issues and user disruption.
- Limited patch management infrastructure: Following the transition from its previous service provider, the client no longer had access to the partner’s proprietary patch management solution.
- Maintaining security updates: The client needed endpoints to receive the latest security updates on a defined monthly schedule, rather than allowing patching gaps to accumulate.
Anunta’s Solution
Anunta integrated endpoint patching into its broader Managed Endpoint Services (MES) framework, using Microsoft Intune to create a structured, standardized approach to endpoint governance.
- Standardized endpoint governance: Anunta established a consistent patch management process across the client’s distributed endpoint environment, improving control and visibility over endpoint security.
- Microsoft Intune-based patching: Anunta leveraged the client’s existing Microsoft Intune investment to manage and deploy patches centrally, avoiding the need for an additional patch management platform.
- Phased patch deployment: Updates are introduced progressively, starting with UAT devices, then a controlled group of users, and finally the broader endpoint population. This reduces deployment risk and surfaces issues early.
- Application-aware validation: Sample devices and selected users validate updates before production rollout, ensuring that critical engineering applications continue to perform as expected.
- Monthly patch governance: Anunta aligned patching with Microsoft’s monthly release cycle to deploy the latest updates within the same cycle.
- Latest-patch approach: To avoid endpoint lag across one or more patch cycles, Anunta targets the latest available security updates each month. This reduces the time endpoints are exposed to known vulnerabilities.
- Consistent virtual desktop management: For the client’s high-performance virtual desktops, Anunta updated the master image, validated the environment, and then rolled it out to production, maintaining consistency across virtual desktops.
- Integrated managed operations: Endpoint and virtual desktop patching are managed as part of Anunta’s broader MES and infrastructure services, creating a unified operating model across endpoints, virtual desktops, network, data center, and related infrastructure.
Key Benefits:
- 100% patch compliance: 100% of endpoints are patched through the managed process, with manual remediation for exceptions.
- Stronger global endpoint governance: A standardized process ensures consistent patching across 22 US sites and the Chennai office, reducing location-specific variation.
- Reduced security exposure: Deploying the latest updates within the monthly cycle helps minimize the window in which endpoints remain exposed to known vulnerabilities.
- Improved application continuity: Phased deployment and user validation reduce the risk of patch-related disruption to specialized engineering applications while maintaining a consistent security baseline.