Professional Services

Double the Workforce, Not the IT Team

A co-managed Essentials rollout for a national law firm — unified identity, modern device management, and centralized security

A national law firmIdentitySecurityMDM

At a Glance

Client
A national law firm
Industry
Legal — national practice
Problem
A rapidly growing firm needed to modernize identity, device management, and security — and streamline onboarding — without expanding its IT team.
Approach
A six-month, co-managed rollout of Macktez Management Essentials: JumpCloud identity, NinjaOne device management, Huntress MDR, and 1Password, designed and overseen by Macktez while the firm's IT team enrolled devices and users.
Outcome
141 managed identities, 117 monitored workstations, 116 protected endpoints, and 88 password vaults — with onboarding reduced to a low-touch, wave-based process and internal IT running the platforms day to day.

The Challenge

Growth outpacing manual IT

A national law firm needed a robust, scalable way to manage a growing workforce, modernize IT support, and streamline employee onboarding. Like many rapidly expanding organizations, it faced several operational hurdles at once.

  • Manual onboarding: setting up new hardware and provisioning software access was a slow, hands-on process for the IT team.
  • Poor device visibility: The firm needed better oversight and policy enforcement across its fleet of Windows and Mac workstations.
  • Security vulnerabilities: more frequent, more sophisticated phishing attempts made a unified multi-factor authentication (MFA) strategy and stronger endpoint security urgent.
  • Too many passwords: because every application required its own login, employees juggled multiple accounts — causing password fatigue and security gaps.

The Approach

A change of direction after the assessment

The firm has a skilled internal IT team and recognized the need to update its identity and device management tools ahead of growth. The firm initially reached out to Macktez to plan enrollment in Microsoft's Entra and Intune platforms.

But the work we did together during our Initial Assessment revealed a broader set of IT questions that we believed would be more comprehensively addressed with different tools. The firm's decision-makers were open to a change of direction after we reviewed the options together, and asked Macktez to design and oversee a six-month enrollment process.

Our scope of work included:

  • Setting up and configuring co-managed tenants in JumpCloud (identity and device management), 1Password (password management), Huntress (endpoint and managed detection and response — EDR/MDR), and NinjaOne (additional device monitoring).
  • Federating identities with the firm's existing single sign-on (SSO)-enabled services, working with third-party vendors where needed — including Microsoft 365, Zoom, 1Password, Airtable, Bonusly, Adobe, and Podium.
  • Setting up and configuring MDR security policies.
  • Configuring and enforcing JumpCloud MFA.
  • Documentation, demonstrations, and co-working sessions so the firm's IT team could confidently enroll employees and devices in the new tools.
  • Weekly progress meetings.

The Solution

Four pillars of modern IT infrastructure

Macktez designed a solution centered on our Management Essentials subscription and enrollment in 1Password, resting on four pillars.

1. Unified identity

Implementing JumpCloud gave the firm centralized user authentication and less login friction. A key federation with Microsoft 365 lets people use one set of credentials for their workstations and productivity suite, with additional SSO integrations across other critical applications.

2. Robust device management

To manage a hybrid fleet, Macktez implemented NinjaOne for remote monitoring and management (RMM). The rollout standardized security settings — 15-minute lock screens, BitLocker encryption — and automated deployment of common applications and extensions.

3. Proactive security

To defend against sophisticated threats, Macktez deployed Huntress across all endpoints for managed detection and response (MDR), so suspicious activity is caught and remediated by a 24/7 Security Operations Center (SOC).

4. Centralized password management

1Password was deployed firm-wide to secure credentials that fall outside SSO. Macktez configured a System for Cross-domain Identity Management (SCIM) bridge to automate user provisioning from JumpCloud to 1Password, and helped the firm set up granular vaults to support least-privilege access based on each user's needs.

By the Numbers

Six months, one platform

Managed identities
141
Monitored workstations
117
Protected endpoints
116
Password vaults
88
Timeline
Six months, all objectives met

Ongoing Consulting

A foundation to keep building on

Building on this foundation, we are exploring phase 2 initiatives — including HR system integrations to further automate onboarding, and device trust to further secure access to sensitive company data.

Macktez excels at co-management and augmentation for skilled IT teams that need additional expertise and resources. The firm's internal team runs the new systems day to day, with Macktez available remotely for new integrations and features.

Outcomes

What changed.

  • Enhanced security: unified MFA and federated identities across Microsoft and other platforms significantly reduced the firm's attack surface. It has already proven itself — when an employee was lured into downloading malicious code, Huntress detected and isolated the device within minutes, and the firm's IT team completed remediation the same day.
  • Streamlined operations: new-hire onboarding is now low touch, rolled out in a phased, wave-based process that brought the whole organization online over several months without disrupting casework — and set up for zero-touch configuration in phase 2, initiated directly by HR.
  • Improved user experience: employees get a consistent login across their desktop and web applications.
  • High enrollment success: the firm's internal IT team steadily enrolled every company device and migrated users to the new identity platform, with instructions and support from Macktez.
  • Co-managed IT platforms: internal IT continues to administer the systems day to day, with Macktez assisting remotely on new integrations and features.

Scale Without Scaling IT

Growing faster than your IT team can keep up?

We roll out identity, device management, and security as a co-managed foundation — so you can add people without adding overhead. Let's talk about where your team needs backup.

Let's Talk

Related

To roll out identity, device management, and security as one co-managed foundation, these are where to begin:

For the concepts behind this rollout, see our University guides on MFA, least privilege, and directory services:

More identity and device work in action: