How to Manage Company Laptops in a Small Business
This post contains affiliate links. If you buy through them, we may earn a small commission at no extra cost to you.
Company laptops are one of the most valuable and highest-risk assets a small business owns. They hold client data, email, financial info, sometimes physical access credentials. Managing them well means the difference between a stolen laptop being a minor incident and being a data breach with reporting obligations. Here’s how to manage company laptops in a small business — the practical playbook without enterprise complexity.
The fundamentals
Laptop management has three layers:
- Provisioning and asset tracking — who has what
- Configuration management — what’s installed, secured, and how
- Ongoing management — updates, monitoring, incident response
Small businesses often ad-hoc all three, which works until the first stolen laptop, ransomware event, or departing employee walking off with the device. Systematizing pays back the first incident.
Provisioning: what to set up before handing a laptop to a new hire
Standard configuration checklist
- Full disk encryption enabled (BitLocker on Windows, FileVault on Mac)
- Local admin password known only to IT (users are standard users)
- Screen lock timeout (10-15 minutes maximum)
- Automatic OS updates enabled
- Antivirus/EDR installed and enrolled (Microsoft Defender for Business, SentinelOne, CrowdStrike)
- Password manager installed and provisioned (1Password, Bitwarden Business)
- VPN client for remote access (if applicable)
- Business email configured
- Standard business applications installed
- Company-approved browser with security extensions
- Removable storage restrictions if data-sensitive
Asset registration
Every laptop gets logged with:
- Make/model/serial number
- Assigned user
- Purchase date and warranty expiration
- OS version and license
- Installed software list
- Notes on any special configuration
An IT asset tracker like the Veteran Forge IT Asset & Inventory Tracker spreadsheet template covers this cleanly for small businesses.
Hardware picks
Business-grade laptops
- Dell Latitude — enterprise reliability, good keyboards, 3-year warranty options
- Lenovo ThinkPad T series — the classic business laptop, excellent keyboards, robust build
- HP EliteBook — good build, competitive pricing
- Apple MacBook Pro — creative/development teams, excellent hardware, premium price
Avoid consumer-tier laptops (Dell Inspiron, HP Pavilion) for business use — they lack corporate warranty options, remote support, and often have lower build quality.
Docking and accessories
- USB-C docking station per desk — one cable for power, monitors, network
- 27-inch monitors — productivity multiplier
- Kensington laptop locks for shared spaces
- Padded laptop bags for employees who travel
- Privacy screens for employees working in public spaces
Mobile Device Management (MDM)
Modern MDM tools let you manage laptops centrally. The main options:
- Microsoft Intune — the default for Microsoft 365 shops. Windows-first, growing Mac and mobile support. Included in some M365 Business Premium plans.
- Jamf — the Mac-focused MDM. Best-in-class for Apple environments.
- Kandji — modern Mac MDM alternative. Cleaner interface than older tools.
- JumpCloud — cross-platform (Windows, Mac, Linux) with directory and SSO features included. Good for mixed environments.
- NinjaOne / Atera — RMM tools with device management overlap. See our Atera vs NinjaOne comparison.
What MDM does:
- Push standard configuration to all devices
- Enforce security policies (encryption, screen lock, password requirements)
- Deploy software updates automatically
- Remote wipe lost or stolen devices
- Track compliance (which devices are up-to-date, which aren’t)
Ongoing management
Patching and updates
- OS updates automatic, monthly at minimum
- Third-party application updates (Chrome, Adobe, Zoom) via MDM or Chocolatey/winget
- Firmware updates as available (many laptops have quarterly firmware releases)
Monitoring
- MDM dashboard reviewed weekly for compliance drift
- Antivirus/EDR alerts monitored — configure email/SMS alerts for critical events
- Backup verification (are backups actually working?)
Access reviews
Quarterly review of who has what access. Departing employees, role changes, and inactive devices all need attention.
Incident response
Lost or stolen laptop
- Report immediately to IT (or whoever manages devices)
- Change passwords on all accounts the user had access to
- Trigger remote wipe from MDM
- Report to insurance (cyber insurance often covers lost hardware and breach response)
- Assess data exposure — was full disk encryption enabled? What data was on the device?
- Notify affected parties if data breach thresholds are met
- File police report if theft is suspected
Compromise (malware, unauthorized access)
- Isolate the device from the network immediately
- Preserve for forensics if the incident is serious
- Wipe and reimage — do NOT try to clean and reuse
- Reset all passwords the user had
- Review MDM/EDR logs to understand what happened
Offboarding: getting laptops back
The often-forgotten side of laptop management:
- Same-day account disablement when employees depart
- Immediate device return coordination
- Physical inspection on return (any damage, all accessories)
- Data preservation if needed (backup user files before wiping)
- Wipe and reimage for the next user
- Update asset tracker
Getting laptops back after departures is a common failure point. Written policy + prepaid shipping labels for remote workers reduces the problem.
Backup and file preservation on laptops
Laptop backup is a specific challenge — devices come and go from the network, users work from coffee shops, and cloud backup is essential:
- OneDrive or Google Drive for user files. Automatic cloud sync of Documents, Desktop, Pictures.
- {vendor(“Backblaze”)} or {vendor(“IDrive”)} for full-image backup. Continuous cloud backup runs in the background. See our Backblaze vs IDrive comparison.
- Version history. Both OneDrive and Google Drive keep 30+ days of file versions — real value against ransomware.
- Restore testing. Actually restore a laptop from backup quarterly. Backup you haven’t tested isn’t backup.
BYOD considerations
Bring-your-own-device policies save on hardware but complicate management:
- Written BYOD policy signed by employees
- Reimbursement for business use
- MDM enrollment required for access to business systems
- Right to remote-wipe business data (not personal data)
- Clear separation of business and personal data
Many small businesses land on a hybrid: laptops are company-owned; phones are BYOD with MDM enrollment.
The bottom line
Managing company laptops in a small business comes down to standardization: standard configuration, standard MDM enrollment, standard patching, standard incident response. An MDM tool like Intune, JumpCloud, or an RMM platform (NinjaOne / Atera) makes this scalable. Full disk encryption is non-negotiable — it’s the difference between a lost laptop being an inconvenience and being a data breach. Track every device from purchase to disposal in an asset tracker. The systems that seem like overkill for a 10-person company pay back the first time a laptop goes missing.
IT Onboarding and Offboarding Checklist Pack
Stop rebuilding this from memory every hire and every departure. Day 0 through 90-day onboarding checklist, same-day access-removal offboarding checklist, Manager-to-IT handoff form, and a 5-tab Access & Asset Tracker — built by an IT operations veteran for small-business IT teams.
Get the Onboarding & Offboarding Pack — $19 →