
Microsoft Surface, Apple, and Intune-managed. Devices arrive provisioned to the user's desk. We refresh on a 36-month cycle. We collect the old one.

Devices arrive provisioned. Refresh in 36 months. We collect the old one. The Microsoft Customer Agreement covers the device. Microsoft Intune provisions it before it lands. The user opens the box, signs in, gets their apps and policies. Three lines of effort from your IT lead. Not three days.
Surface Pro, Surface Laptop, Surface Hub. Designed for Windows, built for Microsoft Intune, sold under your Microsoft Customer Agreement.
MacBook, iPad, iPhone. Microsoft Customer Agreement procurement via Braintree. Same Microsoft Intune-managed plane as Surface.
Unified endpoint management. Autopilot zero-touch enrolment. Policy push, compliance, app deployment across Windows, macOS, iOS and Android.
Threat detection and response on every fleet device. EDR with automated investigation. Microsoft-direct security feed.
Custom fleet automations and procurement playbooks where Microsoft does not ship a named one. Monthly per-device subscription, refresh built in.
From purchase to disposal, the device fleet runs on Microsoft-named products. We deploy them where the TCO case is proven. Not by default. The refresh cycle is built into the price.
Surface, Apple, monitors, peripherals. Sourced under your Microsoft Customer Agreement. Negotiated price per device.
One agreement covers every form factor. One commercial relationship, not a stack of supplier accounts.
Zero-touch enrolment. The device arrives provisioned to the user. They sign in, get apps and policies, productive in 15 minutes.
Microsoft Intune Autopilot enrols the device into your tenant before it lands at the user’s desk.
Endpoint management, compliance, security. One Microsoft Intune dashboard for the whole fleet. Microsoft Defender on every device.
Policies, applications, compliance rules and security baselines push across Windows, macOS, iOS and Android from one console.
Refresh trigger at month 33. We deliver the new device provisioned. We collect the old one for decommission.
The refresh is automated against warranty triggers. It is built into the price, not a separate CapEx event.
Remote wipe via Microsoft Intune. Asset retired from the fleet. POPIA-aligned e-waste compliance via certified disposal partner.
Microsoft 365 Compliance Manager records the wipe event for the audit trail. Devices with residual value enter the refurbishment pipeline.
Four stages. Business case first. The full TCO modelled. Deployed only where the case proves out.
Audit your current device estate. Form factors, OS mix, warranty coverage, refresh cycles. Map the gaps.
DaaS vs CapEx TCO model presented. Microsoft Customer Agreement procurement structure proposed. Sign-off before any device order.
TCO sign-off gateMicrosoft Customer Agreement signed. First device order placed. Microsoft Intune Autopilot enrolment templated. First user receives a provisioned device inside two weeks.
Custom procurement playbooks and refresh-trigger automations where Microsoft does not yet ship a named one. Fleet managed against the agreement.

Braintree doesn't deploy by default. We deploy where the TCO case is proven.
Devices-as-a-Service or CapEx purchase. Different commercial appetites need different scoping work. Read the column that applies. Both arrive at the same place: a provisioned, managed device fleet.
Best when you want monthly subscription, fully managed, refresh built in.
Best when you want to own the devices outright. CapEx on the balance sheet.
Timeline: first devices provisioned to users in week three, either path.
How the commercial model changes when every device runs on one agreement, one refresh cycle, one IT-lead view. One Microsoft partner. One agreement. One unified, secure solution.

Hundreds of millions of devices run under Microsoft Intune management worldwide, the management plane behind every Braintree fleet. Forrester's commissioned Total Economic Impact study models the return over a three-year horizon. Braintree is a Microsoft Surface partner and an Apple Authorised Enterprise Reseller, with 220+ South African businesses on the books.
We match you to the right specialist when you book the scoping call. Names land in your calendar invite, not on a page you scrolled past.
8 questions, benchmarked against 220+ SA clients. You get a tier, above median through to below median fixable in 12 months, plus the actions to close the gap.

Device estate, form-factor mix, Microsoft Intune maturity, warranty coverage, refresh cycle. Five to ten minutes on your side.
Braintree returns scoped device-fleet findings, the DaaS vs CapEx TCO model and the opportunity map. Inside five business days.
Review scope, shortlist the device platforms, choose the fork, discuss refresh cadence and the SA-resident e-waste compliance answer. No sales pitch.
DaaS is a monthly per-device subscription that bundles the hardware, the Microsoft Intune management, the warranty coverage, and the 36-month refresh cycle into one commercial agreement. The Microsoft Customer Agreement covers procurement. Braintree handles provisioning, lifecycle management, refresh logistics, and end-of-life decommission. Your IT lead deals with one invoice and one escalation path. The user opens the box, signs in, and is productive in 15 minutes via Microsoft Intune Autopilot zero-touch enrolment. End of term, we collect the old device.
Surface fits businesses with deep Microsoft 365 and Windows tooling, especially where Teams, Copilot for Microsoft 365, and Intune-policy enforcement matter most. Apple fits creative-leaning roles, marketing teams, and users who already operate on macOS or iOS. The two are not exclusive. We manage mixed fleets under one Microsoft Intune plane. Both run Microsoft Customer Agreement procurement. Both inherit Microsoft Defender for Endpoint security. We model the device mix in the scoping call based on your role taxonomy.
Three jobs. Provision: Microsoft Intune Autopilot enrols every new device into your tenant before it lands at the user's desk. Manage: Microsoft Intune pushes policies, applications, compliance rules, security baselines, and patch updates across Windows, macOS, iOS, and Android. One console, one fleet. Protect: Microsoft Intune integrates with Microsoft Defender for Endpoint for threat detection and response. Lost or stolen device. One Intune click triggers remote wipe. POPIA-aligned. Audit-ready by default.
Three reasons. One: Microsoft and Apple device warranty terms align with 36 months for most enterprise SKUs. After month 36, warranty-extension premiums rise sharply. Two: Windows and macOS major-version support tends to expire 36 to 48 months after device launch. Devices older than 36 months start dropping out of OS support. Three: performance erosion. The user productivity dip on a 4+ year device is measurable and predictable. 36 months is the inflection point where refresh pays back faster than the new-device cost.
Microsoft Intune handles both. Corporate-owned devices enrol via Microsoft Intune Autopilot for full management. BYOD devices enrol via Microsoft Intune App Protection Policies for app-level management without device-level intrusion. The corporate Microsoft 365 apps inherit your security policies. The user's personal apps and data stay private. Lost or stolen BYOD device: corporate data is wiped without touching personal photos or files. POPIA and corporate-IT separation both honoured.
Three layers. Encryption: every fleet device runs BitLocker (Surface and Windows) or FileVault (Apple) by default, policy-enforced via Microsoft Intune. Conditional Access: Microsoft Entra ID Conditional Access blocks corporate data on non-compliant or unfamiliar devices. Remote wipe: a lost or stolen device triggers immediate Microsoft Intune remote wipe. POPIA notification obligations are tracked in Microsoft Purview Compliance Manager. If the device is BYOD, only the corporate data zone is wiped. Personal data stays intact.
Four steps. One: Microsoft Intune remote wipe is triggered on the day the device is returned or replaced. Two: Microsoft 365 Compliance Manager records the wipe event for the audit trail. Three: the physical device is collected by a Braintree-managed certified disposal partner. Four: a POPIA-aligned data destruction certificate plus an e-waste compliance certificate are issued back to your IT lead. Devices that retain residual value enter our refurbishment pipeline for resale, with the proceeds netting against your next DaaS invoice if you elect.
Three answers. Credentials: Braintree is a Microsoft Surface partner and an Apple Authorised Enterprise Reseller, with 220+ SA clients and 100+ Microsoft-certified professionals. Operations: SA-resident provisioning, SA-resident logistics, SA-resident certified e-waste disposal partner. Method: every device deployment is gated against the TCO case. We are paid for the work, not for hardware markup. Our incentive aligns with your fleet operational predictability, not your device-count growth.
TCOOpEx monthly versus CapEx outright. The scorecard across 36 months including refresh, warranty, e-waste compliance and productivity uplift.
ProvisioningZero-touch enrolment via Microsoft Intune Autopilot. How a new device gets from box to productive in 15 minutes, not 2 to 4 hours.
RefreshWarranty terms, OS support windows and a measurable productivity dip all turn at month 36. The inflection point that beats average device age.
Microsoft 365, Teams and Copilot licensing rolls with your device fleet. Per-device, per-user licensing aligned, on one Microsoft Customer Agreement.
Visit Modern WorkplaceMicrosoft Defender for Endpoint runs on every fleet device. Microsoft Sentinel correlates device-side threat signals. POPIA-aligned, SA-resident SOC operations.
Visit SecurityManaged support operates on the device fleet. Tier-3 escalations route through Microsoft-direct lanes. SA-resident engineers, on one agreement.
Visit SupportBook the 30-minute scoping call. We audit your current fleet, model the DaaS vs CapEx TCO, and tell you whether a managed device fleet is the right move. No pitch deck.