MDM/Endpoint Management Setup
Only freelancers located in the U.S. may apply.U.S. located freelancers only
About Us We're a multi-site behavioral health services company operating clinics in California and Georgia, with approximately 60 employees across five locations. We issue company-owned laptops and iPads to clinical and administrative staff. Our environment: Google Workspace Business Plus for email, identity, and file storage. Our fleet is roughly 3 Windows laptops, 20 MacBooks, and 8 iPads. Because we operate in healthcare, our devices may touch protected health information (PHI), so HIPAA-appropriate safeguards are a requirement, not a nice-to-have. The Problem We are paying for Google Workspace Business Plus, which includes advanced endpoint management — and none of it is configured. There is no enrollment process, no enforced passcodes or disk encryption, no app control, no remote wipe capability, and no reliable visibility into who has which device or what's installed on it. Devices are handed out and tracked informally. We want this built out properly, once, using what we already own wherever possible, with documentation clear enough that our operations and HR staff can maintain it in-house afterward. Scope of Work 1. Assessment and gap analysis Inventory our existing devices and audit our current Google Admin console endpoint management configuration Tell us specifically what Business Plus covers for each device type — Windows, macOS, iPadOS — and what it does not Verify all device-using staff hold Business Plus licenses, since endpoint policies are licensed per user Recommend what, if anything, we need to buy on top of Google to close the remaining gaps, with cost per device or per user. We expect the honest answer may involve a dedicated Apple MDM and an endpoint protection product; make the case either way Confirm Business Associate Agreement coverage for anything you recommend, and verify our Google Workspace BAA has been accepted in our Admin console 2. Google Workspace build-out Configure Google Admin console endpoint management: organizational units by role and location, device approval workflow, and context-aware access where appropriate Enable advanced mobile management and configure the Apple push certificate for our iPads Configure Windows device management and BitLocker policy Set up Apple Business Manager so our iPads can be supervised and future purchases enroll automatically Stand up any supplemental MDM or security tooling identified in step 1, with identity anchored to our Google accounts — we do not want a second directory to maintain 3. Security baseline Enforce disk encryption on laptops (BitLocker on Windows, FileVault on Mac) and confirm encryption is actually active on each machine, not merely configured in a console Enforce device passcodes and screen-lock timeouts across all device types Configure remote lock and full remote wipe Deploy endpoint protection / antivirus Application allow/block controls and restrictions on personal cloud storage or unapproved apps OS patch and update enforcement 4. Application deployment Package and push our standard app set to the correct device groups (list provided after hire; includes clinical data collection and productivity applications) 5. Enrollment of the existing fleet Enroll our currently deployed devices Identify which devices require a wipe and reset to enroll properly, and propose a sequencing plan that minimizes disruption to clinic operations across two time zones 6. Monitoring and reporting Compliance dashboard and alerting for out-of-policy devices Asset inventory report we can reconcile against our HR records 7. Policy, documentation, and handoff Written device use / acceptable use policy suitable for inclusion in our employee handbook Device assignment and return acknowledgment form Standard operating procedures for: issuing a new device, onboarding a new hire, offboarding a departing employee including remote wipe, and responding to a lost or stolen device Live training session (recorded) for our operations and HR staff so we can administer this going forward without ongoing contractor support Deliverables Fully configured endpoint management environment with all existing devices enrolled and reporting compliant Documented security baseline and configuration profiles Written device policy plus assignment and return forms Admin SOP runbook Recorded training session and 30 days of post-launch support for questions Required Experience Hands-on MDM/UEM deployments for small to mid-size organizations — tell us how many and on which platforms Direct, current experience configuring Google Workspace endpoint management on Business Plus, including its real limitations Integrating a third-party MDM with Google Workspace as the identity provider Both Apple (macOS/iPadOS) and Windows management Apple Business Manager and Automated Device Enrollment Windows encryption and update enforcement in a Google-identity environment, not Microsoft 365 Experience with HIPAA-regulated or otherwise compliance-sensitive environments Clear written communication — we need documentation a non-technical operations manager can actually follow Nice to Have Prior work with healthcare, behavioral health, or multi-site clinical organizations Familiarity with BambooHR for reconciling device assignment against employee records Multi-state operations experience Engagement Details Type: Fixed-price with milestones preferred; open to hourly for the right candidate Timeline: Kickoff within two weeks, initial rollout complete within [4–6] weeks Availability: Some work must align with U.S. Pacific and Eastern business hours to coordinate with clinic staff Please Include in Your Proposal What can we accomplish using only what Business Plus already includes, and where will we genuinely need to add tooling? What are the top three things Google Workspace endpoint management cannot do that we should be aware of? How would you handle our MacBooks specifically? Two or three comparable projects you've completed, with device counts and platforms Any additional per-device or per-user monthly cost your approach would introduce Your fixed-price quote and proposed milestones Your experience with HIPAA safeguards as they apply to endpoint devices Start your proposal with the word "ENROLLED" so we know you read the full posting.
- Less than 30 hrs/weekHourly
- 1-3 monthsDuration
- IntermediateExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:2 days ago
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- USARancho Cucamonga3:18 AM
- $56K total spent5 hires, 0 active
- 677 hours
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by