001/Company

Enterprise-grade discipline. None of the overhead.

Stonham Technology is a Sydney IT company. For most of our clients we're the IT department. For the rest we're the part their existing IT can't cover: the device fleet, the automation, the software nobody else will build.

What we actually do

We look after Microsoft 365 and identity, the laptops people work on all day, the security settings nobody ever sees, and the requests that come in while you're trying to run the business. That work is priced per user per month, so it shows up as a budget line rather than a surprise.

We're not an Apple-only shop, and not a Windows-only shop either. Mac, Windows and Linux each get managed with the tool built for them. Alongside the managed work we build software for businesses that have been quoted five figures elsewhere, and we automate the jobs somebody currently does by hand every week.

002/Method

How we run an IT department

Devices enrol themselves
A machine arrives, the user signs in, and apps, settings and disk encryption land without anyone unboxing it at a desk first.
One tool per platform
Jamf for Apple, Intune and Autopilot for Windows, Ansible for Linux. Pushing all three platforms through a single console is how environments end up half managed.
Licensing matched to the job
Business Premium where Windows users need it, Business Standard plus Jamf where a Mac fleet does. You're not paying for seats that do nothing.
Security applied as policy
Defender, BitLocker, FileVault, conditional access and CIS benchmarks, set as policy so a device can't quietly drift out of compliance.
Starters and leavers on our checklist
Accounts, licences, devices and access, created on day one and closed on the last day. Not a note in somebody's inbox.
Hardware planned a year out
Refresh planning, lifecycle tracking, a retirement process, and an annual cyber gap review with a roadmap you can act on.

003/Scale, proven

Twelve thousand devices.
Fifty-two countries.
One process.

The biggest number we can point at is a fleet of 12,000+ devices across 52 countries, Apple hardware run with Jamf for one of the world's largest advertising networks. Zero-touch enrolment, compliance and patching included. Before that and since, the same work inside regulated financial services and on large university campuses.

We hold every certification Jamf issues, plus RHCE and RHCSA on the Linux side, and the Windows work runs on Intune, Autopilot and Entra ID. Twenty-plus years of it has been the kind of enterprise work where a mistake pages somebody at 3 a.m. and "it works on my machine" isn't an answer.

Small environments get the same discipline. They just need less of it.

004/The standard

What you get that a bigger provider won't give you.

  1. 01 Your ticket doesn't start at tier one. It starts with a senior engineer who has run fleets at scale, so nobody asks you to reboot while they read the manual.
  2. 02 The brief lands with the engineer who does the work. No account managers in the middle, no juniors learning on your invoice.
  3. 03 Automation as a reflex. If it happened twice, it becomes a script. You stop paying for repetition.
  4. 04 Documentation as standard. Decisions, configs and runbooks are written down, so nothing important lives in one person's head.
  5. 05 Plain English. You'll always know what's being done, why, and what it costs, before it happens.

005/The toolbox

What we actually hold in our hands.

Microsoft 365 & identity

  • Exchange Online
  • Teams
  • SharePoint · OneDrive
  • Microsoft Entra ID
  • SSO / conditional access
  • Google Workspace

Windows

  • Intune
  • Autopilot
  • BitLocker
  • Defender
  • Windows 10 · 11

Apple

  • Jamf Pro
  • Jamf Protect
  • Jamf Connect
  • Apple Business Manager
  • macOS · iOS · iPadOS · tvOS
  • Zero-touch enrolment

Linux & automation

  • RHEL · Ubuntu · Debian
  • Ansible
  • Bash
  • Python
  • REST APIs

Security & infrastructure

  • CIS benchmarks
  • Endpoint security
  • Patch compliance
  • AWS
  • DigitalOcean
  • Cloud & on-prem servers