The problem
The old antivirus depended on a local management server. Laptops outside the office network did not always get updates, and the console showed little about what actually happened on a device.
The approach
- Installed the EDR agent on every endpoint, replacing the old antivirus agent.
- Moved in two steps rather than straight to SaaS: the platform first ran from an on-premise console, and management was moved to the cloud console afterwards.
- Tuned detection policies to cut false positives, and added email and web security policies alongside.
The result
Around 1,000 endpoints moved to the cloud EDR over about two months, including laptops that rarely touch the office network. The dependency on a local management server is gone.