Scenario B: Knowledge Workers & Enterprise Fleet
Who this fits
Standard fleet employees who need a managed, consistent Windows experience, with line-of-business apps delivered centrally rather than installed by hand.
Architecture at a glance
Same architecture as described in Overview & Decision Matrix: the Management Portal sources Windows declaratively, Jamf Pro installs and configures Parallels Desktop, and the resulting VM enrolls in Intune.
Deployment method and why
Declarative. This group runs a standard fleet image, and Intune delivers line-of-business apps after enrollment — no need to bake apps into a custom .pvmp.
Management Portal policy settings
Create a policy for the knowledge workers' user group with a Golden Image set to Declarative / Windows Enterprise. Recommended settings for this group:
Security Controls: Limit users to provisioned VMs only · Do not allow removing provisioned VMs · Do not allow editing Parallels Desktop preferences.
VM Settings: Clipboard/Drag-and-drop: Bidirectional · VM startup: Ready in background · Do not allow external devices.
See Stage 3: Management Portal & Remote Policy Setup for how to create the policy, and the full comparison across scenarios.
Role handoffs
Portal Admin — creates the policy and Golden Image, assigns the knowledge workers group, applies the Security Controls above.
Mac Admin — confirms Parallels Desktop is deployed via the Jamf app profile.
Windows-Identity Admin — confirms Intune app assignment policies deliver the required line-of-business apps to the enrolled VM.
Verification
In the Management Portal, open the Golden Image card and confirm the fleet's VMs show as provisioned. Ask a sample user to confirm Windows completes first boot, signs in with their corporate account, and receives the assigned line-of-business apps automatically.
Where to go next
Continue to Stage 1: Account, SSO & Licensing Configuration to set up the knowledge workers group's sublicense and activation.
Last updated