Elektroantriebssystem-Maschine in Betrieb als Symbol für die Maxon Case Study baseVISION

Case Study Feintool

Client: Feintool

Feintool is an internationally operating technology and market leader in the technologies of electrical sheet stamping, fineblanking, and forming for the production of high-quality precision parts. These technologies are characterized by efficiency, quality, and productivity. With its innovative approach, Feintool continuously pushes the boundaries of these technologies and develops intelligent solutions, innovative tools, and state-of-the-art manufacturing processes for the needs of its customers around sheet steel in large quantities for automotive and industrial applications as well as renewable energies. The processes used support the megatrends in the generation, storage, and application of green energy. Founded in 1959, the company is headquartered in Switzerland and is represented with 17 production plants in Europe, the USA, China, and Japan. Around 3,300 employees and 100 trainees worldwide work on new solutions. The publicly traded Feintool is majority-owned by the Artemis Group.

The situation before baseVISION: Inflexible environment

The Feintool Group operates in the industrial sector and faces the challenge of integrating new technologies with numerous technical requirements. Feintool had been using a Configuration Manager (ConfigMgr) environment for some time. However, with the introduction of Windows 11, the company decided on a new approach and transitioned from a conventional IT environment to a more dynamic and adaptable framework.


The network structures and other associated limitations hindered the development of a new workplace concept. For this reason, the strategic decision was made to centralize device management and rely on Entra ID and Microsoft Intune. However, it was necessary to first analyze the potential impacts of this transition on the current IT environment and business processes.

The biggest challenges for Feintool:

  • Inefficient traditional workplace management with ConfigMgr.
  • Use of manual procedures for Endpoint Management, leading to complexity throughout the entire lifecycle of the endpoints.
  • Dependency on local Active Directory and network infrastructure.
  • Windows 10 and the need for an upgrade to Windows 11.
  • Imbalance between security and user-friendliness due to the absence of Windows Hello for Business.
  • Increased demands on endpoint security.

The Vision: Establishing a Secure and Efficient Employee Platform

The vision of the Feintool Group was to create a robust and secure platform for its employees. With a greenfield approach, the company aimed to create a standardized workplace that enables end users to perform their daily tasks smoothly. This vision included the following main objectives:

  • Strengthening IT through Innovative Services: With the introduction of the latest endpoint and security solutions from Microsoft, Feintool aimed to equip its IT infrastructure with advanced tools and services.
  • Introduction of Entra ID Joined Devices: The vision included the introduction of devices exclusively connected with Entra ID while enabling seamless access to local resources and the existing environment.
  • Enhancing Security with Microsoft Security Configuration Framework: Feintool aimed to strengthen its security measures by introducing the Microsoft Security Configuration Framework, thereby improving its defense against potential threats.
  • Security of Endpoints and Attack Mitigation: To enhance the security of endpoints with Microsoft Defender for Endpoint, the company aimed to minimize attack vectors, pursue a passwordless approach, and proactively prevent Pass-the-Hash and lateral traversal attacks.
  • Automation of Update Processes: The vision focuses on automating update processes to optimize performance and reliability while reducing the need for manual interventions.

Feintool’s vision was to create an environment where both security and operational efficiency are prioritized while leveraging the latest technological advancements to drive these goals.

Blick auf Maschine im Elektroblechstanzen von Feintool als Symbol für die Case Study baseVISION

Our solution

Concept phase

In the initial phase, a workshop was conducted to define the vision and design a corresponding roadmap. The guiding principle was to create a flexible, secure, and modern workplace that aligns with Feintool’s overall vision. In this phase, the Microsoft technologies that should drive the company’s future initiatives were also selected.

Implementation

The transition to modern Endpoint Management provided the opportunity to renew the environment and make it automated, adaptable, and user-friendly. This underscored the benefits of Feintool’s perspective to implement a pure Intune Managed Solution.

Proof of Concept

The Proof-of-Concept phase included a thorough examination of the device lifecycles, with adjustments specifically tailored to Feintool’s requirements.

Further projects

Furthermore, Feintool recognized the performance and aging limitations of the existing Citrix infrastructure and began implementing the Azure Virtual Desktop (AVD) as part of a Proof of Concept (PoC). The goal was to achieve a high degree of automation, with baseVISION’s expertise supporting the successful setup of the AVD environment through the use of the Azure Image Builder.

Outlook

After the successful completion of the Proof of Concept at the end of 2022, the roadmap foresees the rollout of the Azure Virtual Desktop (AVD) across the entire Feintool environment in the second quarter of 2023. The overarching goal is to structure the entire AVD environment, including the network, with an Infrastructure as Code (IaC) template. This approach accelerates the resolution of misconfigurations and the automated documentation of changes. Endpoint Manager (Intune) is used for deploying applications and configurations on AVD machines. With FSLogix, each user has personalized profiles and data that can be accessed via virtual machines.

«We were very satisfied with the company’s services and results. The interaction with the engineers is conducted on an equal level and one can clearly perceive the team’s extensive experience and broad knowledge. Each question or challenge is answered or resolved promptly and competently. We feel completely well cared for. As a manufacturing company, the transformation from traditional endpoint management with ConfigMgr to Intune and Autopilot was an exciting project for us. During the course of the project, all uncertainties were dispelled. Thanks to our collaboration with baseVISION, we have been able to create a modern workplace with the latest Microsoft technologies. Due to the short project duration, we will soon be able to test the new Windows 11 client in remote locations.»
Michael HeinrichIT Solution Engineer Cloud, Feintool Group

Most beneficial Microsoft technologies used

  • Microsoft Intune
  • Windows Autopilot
  • Microsoft Security Baselines
  • Windows Hello for Business
  • Windows LAPS
  • Intune Certificate Connector
  • Azure Virtual Desktop
  • Azure Image Builder
  • Defender for Endpoint

Leading companies rely on us.

Don’t hesitate.
Take action!

Do you have questions about Security, Cloud, or Modern Workplaces? Our team of experts is happy to support you personally and without obligation in the next steps.

We look forward to hearing from you and engaging in discussions. Anytime.

Alex Verboon
CTO & Senior Expert Security Consultant

Contact now