New hire, Day 1. IT never touched the laptop after imaging. The employee never installed anything. Everything Just Works — with full visibility and continuous policy enforcement.
Companion to /contractor-warp (contractor voluntarily installs WARP). This page shows the IT-pushed path: MDM deploys WARP silently, corp IdP handles SSO, tunnel is always-on, posture is continuous.
Cloudflare WARP (MDM-deployed)Device Posture (continuous)Access (SSO with corp IdP)Gateway (DNS + HTTP + AV)Cloudflare One
The scenario: Alex just joined Acme as a product manager. IT imaged their laptop and shipped it. Alex opens the box Monday morning. WARP is already there, invisible. Sign in once with SSO. Every corporate app is one click away. And if their device ever falls out of compliance — its EDR (Endpoint Detection & Response) agent stops, disk gets decrypted, OS goes stale — WARP knows immediately and access to private apps is restricted until IT can help.
Speed
Elapsed: 0s
IT Admin
Microsoft Intune → Cloudflare Zero Trust
Waiting…
1. Push WARP config profile via MDM
M
Intune → Configuration profiles
Assigned to: All Employees (14,203 devices)
Cloudflare WARP clientDeploying
Auto-connect on boottrue
Auth viaOkta SSO
Tunnel modeInclude (corp + gateway)
User can disablefalse
2. Configure continuous device posture
CF
Zero Trust → Settings → WARP → Device Posture
Rules apply continuously, every 5 min
Disk encryptionRequired
OS ≥ macOS 13 / Win 10Required
EDR (SentinelOne)Required
Firewall activeRequired
3. Bind Access + Gateway policies
All Employees group → grants access to Salesforce, Jira, wiki, GitHub Enterprise, internal HR portal. Gateway blocks known-malicious DNS, blocks Gambling/Adult categories, runs antivirus scan on downloads. Zero user configuration.
4. Alex's laptop enrollment complete
✓ Device seen by MDM. WARP config profile installed silently. Ready for first login.
5. Continuous posture — 4 hours later
⚠ Posture Fail · alex.rivera@acme.com
SentinelOne EDR stopped responding. Access to Finance, HR, and code repos restricted. User routed to remediation page. IT notified via webhook.
Employee
Alex's brand-new MacBook, Day 1
Waiting…
💻 First boot · macOS login
🔒
Alex Rivera
Enter password to log in
WARP is already there · menubar shows it
🍎FinderWARP · CONNECTED
Alex didn't install anything. Config profile from Intune deployed WARP during first boot. Tunnel is up before Alex opens any app.
🔐 SSO handshake · Okta
Okta
Sign in to acme.com
Cloudflare WARP is requesting access via your corporate identity.
Sign in with Okta
Posture check runs silently
Disk encryption (FileVault)—
macOS version—
EDR agent (SentinelOne)—
Firewall active—
🚀 Every corporate app · one click away
☁️
Salesforce
Access ✓
📋
Jira
Access ✓
📖
Wiki
Access ✓
🐙
GitHub
Access ✓
👤
HR portal
Access ✓
💰
Finance
Access ✓
No VPN icon. No "Connect" button. No captive portal. Alex just opens the app and it works.
⚠ Four hours later · EDR breaks
☁️
Salesforce
Access ✓
📋
Jira
Access ✓
🐙
GitHub
Blocked
👤
HR
Blocked
💰
Finance
Blocked
📖
Wiki
Access ✓
Posture fail detected. Sensitive apps blocked automatically. Public apps still work. Alex sees a friendly page: "Please contact IT — your EDR agent isn't running."
⏱ End-to-end timeline
Step 1
MDM pushes WARP
Step 2
Posture rules
Step 3
Employee logs in
Step 4
SSO handshake
Step 5
Posture check
Step 6
Apps just work
Step 7
Continuous check
What just happened: Alex opened a brand-new laptop. WARP was already there because Intune pushed the config profile during imaging. Alex signed in with Okta — the same login they use for email and Slack. Cloudflare checked the device: disk encrypted, EDR running, OS current, firewall on. All green. Access to every corporate app is automatic, no VPN dance. Four hours later, when the EDR agent stopped, WARP detected it and quietly restricted access to sensitive apps — not because IT typed a command, but because policy said "no EDR = no Finance." Compare to legacy: a VPN client the user has to remember to launch, an all-or-nothing tunnel that reveals nothing about device health, and remediation that happens hours or days after a compromise.