1Create one group
A directory group holding the people who get the platform. Everything below is assigned to that one group, so adding a person later is adding a person to a group.
2Assign the service
The signed Windows package in Intune, or the plain MSI in any other MDM, and the signed and notarised macOS package with its system extension profile. Both silent, both per machine.
3Force-install the extension
One extension ID on the Chrome or Edge policy list, with the tenant preconfigured by the same policy. There is no setup screen for anyone to walk through.
4Publish the two Microsoft pieces
The Outlook add-in from the Microsoft 365 admin center and the Teams app from the Teams admin center, both to the same group. Salesforce takes a managed package and a permission set; SAP connects over REST, so there is no transport to schedule.
5Point identity at your directory
One federation to Active Directory, Entra ID or any OIDC or SAML provider. Or skip it entirely and use the built-in directory, which is ready on day one and can be federated later.
AND NOBODY DOES THIS
No user installs, approves or configures anything.
No local admin rights, and no reboot.
No inbound firewall rule and no VPN dependency.
Nobody but your own IT touches your MDM, on any of the four buying motions.
Frontline people without a managed desktop need none of it. They get the same identity, chat, approvals, tasks and signing on a mobile or shared device.