Runs on
Microsoft Surface
Apple
Intune
Defender
Pre-delivery
Enrolled before it lands at the desk
Day one
Policies applied. Productive in 15 minutes.
Month 33
Refresh triggered. We collect the old one.
Surface Pro, Surface Laptop, Surface Hub. Designed for Windows, built for Microsoft Intune, sold under your Microsoft Customer Agreement.
Provisioned before it reaches the desk
36-month refresh built into the price
One warranty escalation path
MacBook, iPad, iPhone. Microsoft Customer Agreement procurement via Braintree. Same Microsoft Intune-managed plane as Surface.
Unified endpoint management. Autopilot zero-touch enrolment. Policy push, compliance, app deployment across Windows, macOS, iOS and Android.
Threat detection and response on every fleet device. EDR with automated investigation. Microsoft-direct security feed.
Custom fleet automations and procurement playbooks where Microsoft does not ship a named one. Monthly per-device subscription, refresh built in.
One agreement
Procure, Enrol, Manage, Refresh and Decommission. One Microsoft Customer Agreement covers the whole lifecycle. One IT-lead view. One escalation path.
Audit your current device estate. Form factors, OS mix, warranty coverage, refresh cycles. Map the gaps.
02
HaaS vs CapEx TCO model presented. Microsoft Customer Agreement procurement structure proposed. Sign-off before any device order.
TCO sign-off gate
03
Microsoft Customer Agreement signed. First device order placed. Microsoft Intune Autopilot enrolment templated. First user receives a provisioned device in week three.
04
Custom procurement playbooks and refresh-trigger automations where Microsoft does not yet ship a named one. Fleet managed against the agreement.
Surface procurement, provisioning and warranty under one agreement.
MacBook, iPad and iPhone on the same Intune-managed plane.
| What matters | Ad-hoc CapEx buying | Device-as-a-Service with Braintree |
|---|---|---|
| Day one | Device arrives blank. IT lead spends two to four hours per device |
✓
Zero-touch via Intune Autopilot. 15 minutes to productive
|
| Warranty | Per-vendor warranty term. Mixed claim processes |
✓
Rolled into the subscription. One escalation path
|
| Fleet view | Per-vendor spreadsheets. Manual asset tracking |
✓
One Intune dashboard. Every device, user and policy in one view
|
| Refresh | Refresh paid separately each cycle. A CapEx event |
✓
36-month refresh built into the monthly subscription
|
| End of life | Disposal happens when it happens. POPIA and e-waste variable |
✓
Intune remote wipe, POPIA-aligned e-waste, auditable
|
| Ownership | Winner You own the asset. Resale or retention discretionary |
DaaS retains the asset for refurbishment. Off your balance sheet |
| 5 to 1 in Device-as-a-Service's favour. Ad-hoc CapEx wins on asset ownership. Honest. | ||
FL
Surface & Apple procurement
EM
Intune, Autopilot & compliance
CL
HaaS, CapEx & the commercial spine
Device estate, form-factor mix, Microsoft Intune maturity, warranty coverage, refresh cycle. Five to ten minutes on your side.
02
Braintree returns scoped device-fleet findings, the HaaS vs CapEx TCO model and the opportunity map. Inside five business days.
03
Review scope, shortlist the device platforms, choose the fork, discuss refresh cadence and the SA-resident e-waste compliance answer. No sales pitch.
Three jobs. Provision. Microsoft Intune Autopilot enrols every new device into your tenant before it lands at the user’s desk. Manage. Microsoft Intune pushes policies, applications, compliance rules, security baselines, and patch updates across Windows, macOS, iOS, and Android. One console, one fleet. Protect. Microsoft Intune integrates with Microsoft Defender for Endpoint for threat detection and response. Lost or stolen device. One Intune click triggers remote wipe. POPIA-aligned. Audit-ready by default.
Microsoft Intune handles both. Corporate-owned devices enrol via Microsoft Intune Autopilot for full management. BYOD devices enrol via Microsoft Intune App Protection Policies for app-level management without device-level intrusion. The corporate Microsoft 365 apps inherit your security policies. The user’s personal apps and data stay private. Lost or stolen BYOD device: corporate data is wiped without touching personal photos or files. POPIA and corporate-IT separation both honoured. Best fit. Mid-market and enterprise businesses with hybrid workforce models.
Four steps. One. Microsoft Intune remote wipe is triggered on the day the device is returned or replaced. Two. Microsoft Purview Compliance Manager records the wipe event for audit trail. Three. The physical device is collected by Braintree-managed certified disposal partner. Four. POPIA-aligned data destruction certificate plus e-waste compliance certificate are issued back to your IT lead. Devices that retain residual value enter our refurbishment pipeline for resale, with the proceeds netting against your next DaaS invoice if you elect.
The productivity stack on the same fleet. Microsoft 365, Teams and Copilot licensing rolls with your device fleet. Per-device, per-user licensing aligned, on one Microsoft Customer Agreement.
The security layer on every device. Microsoft Defender for Endpoint runs on every fleet device. Microsoft Sentinel correlates device-side threat signals. POPIA-aligned, SA-resident SOC operations.
The team that runs the fleet. Managed support operates on the device fleet. Tier-3 escalations route through Microsoft-direct lanes. SA-resident engineers, on one agreement.
Book the 30-minute scoping call. We audit your current fleet, model the HaaS vs CapEx TCO,
and tell you whether a managed device fleet is the right move. No pitch deck.