What if the biggest risk to your endpoint strategy is not a security breach - but the device itself?

Over the past months - for years really - I have been talking about Windows in the cloud with customers, partners, and public sector organizations. This post is primarily about Windows devices - and Windows 11 specifically - because that is where the vast majority of enterprise endpoints sit. macOS has its place in the mix, and I will touch on that. But the strategic pressures I am seeing - pricing, supply chain, architecture shifts, provisioning debt - are most acute in the Windows ecosystem.

One thing is clear: the conversation has fundamentally changed. Organizations are no longer asking if they should rethink their device strategy. They are asking how fast they can move without increasing complexity, support burden, or user frustration. Windows Autopilot has been around for close to ten years, and still many organizations treat device provisioning as a manual, hardware-dependent process.

However, while these conversations are happening, a different kind of pressure is building underneath. Hardware prices are rising. Supply chains are unreliable. Procurement cycles are getting longer. And IT teams are still expected to deliver a consistent, secure experience to every user - regardless of what device they happen to be sitting in front of.

This post explores why the commodity mindset is holding organizations back, what rising hardware costs and delivery failures are really signaling, and why the answer might be to stop fighting the device problem altogether.

The commodity trap

For years, the dominant approach to endpoint management has treated devices as interchangeable units. Pick a model, negotiate a volume deal, image it, ship it, replace it on a cycle. Rinse and repeat. This model worked when hardware was predictable, affordable, and available. That is no longer the case.

The assumption that devices are a commodity - something to be purchased in bulk and managed identically - is one of the most persistent and damaging misconceptions in modern IT. It reduces a strategic decision to a procurement exercise and ignores the role that devices play in productivity, security, and employee satisfaction.

A device is not just a cost line. It is the primary interface between your users and your organization. When that interface fails - because the hardware is underpowered, delayed, or wrong for the user’s work pattern - the cost is measured in lost productivity, frustrated employees, and overwhelmed support teams.

Devices are not interchangeable units - they are the interface between users and the organization
Devices are not interchangeable units - they are the interface between users and the organization

What makes this trap harder to escape is that multiple parties have a business interest in keeping it alive. Service partners profit from legacy deployment methods - imaging, manual configuration, on-premises tooling - because that is their revenue model. As long as customers stay on that path, the billable hours keep flowing. OEMs reinforce the same dependency from a different angle: volume purchase agreements, multi-year refresh commitments, and hardware-centric support contracts that all assume the device is the center of the strategy. Both steer organizations away from cloud-native provisioning - not because it is the wrong choice for the customer, but because it threatens established revenue streams. That is a conflict of interest worth naming.

Breaking out starts with reclaiming ownership of the deployment model. Move to Windows Autopilot and Microsoft Intune so that provisioning is cloud-native, hardware-agnostic, and fully controlled by your own IT team - not by a partner’s engagement scope.

Decouple procurement from deployment services. Buy hardware from any OEM or reseller without requiring bundled imaging or configuration work. Resist multi-year volume commitments tied to a single vendor or model - cloud-native provisioning means any Windows device that meets your security baseline can be enrolled with zero dependency on a specific hardware partner.

For roles where the physical device matters less than the experience, Windows 365 removes the OEM dependency entirely. The path out of the lock-in is not switching platforms. It is making the platform irrelevant by moving the experience to the cloud and treating the device as what it should be: a replaceable access point.

Rising prices, shrinking options

Hardware prices are climbing, and the trend is not slowing down. Global tariffs, semiconductor supply constraints, and shifting trade policies are driving costs higher across the board.

For organizations that rely on bulk procurement of physical endpoints, this creates a compounding problem. Budgets are fixed. Prices are rising. And the gap between what IT needs to deliver and what it can afford is growing.

What makes this worse is that the price increases are not uniform. The devices organizations need most - modern, secure, AI-capable hardware like Copilot+ PCs - are often the ones hit hardest by price pressure. Older, less capable hardware may still be available at lower price points, but deploying it creates a different kind of debt. Security gaps widen. User experience suffers. And the features that modern Windows and Microsoft 365 depend on become impossible to support.

Rising hardware costs and shrinking options are forcing IT teams to rethink endpoint procurement
Rising hardware costs and shrinking options are forcing IT teams to rethink endpoint procurement

The traditional response to rising prices has been to extend refresh cycles, negotiate harder, or downgrade specifications. All three approaches carry hidden costs. Extended cycles mean older hardware running in production longer. Harder negotiations delay procurement. Downgraded specifications lead to performance complaints and increased support volume.

A fourth option is gaining traction: refurbished devices. On paper, it looks like a sensible way to stretch budgets. In practice, it is a false economy. Refurbished hardware often lacks the components that modern Windows requires - TPM 2.0, Secure Boot, supported CPU generations - meaning these devices may not even qualify for Windows 11. They will not support Copilot+ PC capabilities. And they introduce security gaps that directly conflict with a Zero Trust baseline.

There is also the question of ongoing support. OEMs stop releasing driver and firmware updates long before the hardware physically fails. A refurbished device may power on and run, but without current firmware it becomes a liability. The Secure Boot certificate expiration  issues this summer are a clear example - devices with outdated UEFI firmware that cannot receive certificate updates risk failing Secure Boot validation entirely. That kind of risk is invisible in a procurement spreadsheet. It only becomes visible when devices start breaking.

The upfront savings are real, but they are offset by shorter remaining lifespans, higher support costs, and an endpoint fleet that cannot keep pace with where the platform is heading. Every device in the fleet should meet the Windows 11 hardware requirements as a non-negotiable minimum - not as a target to negotiate down from.

The delivery problem no one talks about

Rising prices would be manageable if delivery were reliable. It is not.

Supply chain uncertainty has become a recurring theme in endpoint planning. Lead times stretch. Orders arrive late - or not at all. Specific models become unavailable mid-cycle, forcing IT teams to scramble for alternatives that may not match their existing configuration baselines.

For organizations with distributed workforces, this is particularly damaging. A new hire in one region might wait weeks for a device while a colleague elsewhere gets theirs on day one. The experience is inconsistent, the onboarding is delayed, and IT spends time managing logistics instead of managing outcomes.

This is not a temporary disruption. Supply chain volatility is a structural reality, and any endpoint strategy that depends on predictable hardware availability is building on unstable ground.

The architecture is splitting

On top of rising prices and delivery challenges, the device landscape itself is fragmenting. Windows now runs on ARM64 - and Microsoft is making it clear that the future of AI on the endpoint is built around this architecture. Copilot+ PCs with dedicated NPUs, features like Recall, Click to Do, and Studio Effects - these are not optional extras. They represent Microsoft’s Frontier philosophy: pushing intelligence to the edge, closer to the user, closer to the data.

However, this creates a new reality for IT. Not all devices are equal anymore - and they are not meant to be. ARM64-based Copilot+ PCs deliver capabilities that x64 hardware simply cannot match. On-device AI workloads, longer battery life, and tighter integration with Windows 11 are architecture-dependent. Organizations that continue to treat every laptop as identical will find that some users get the full experience while others are left behind.

The device is just the access point - the experience lives in the cloud
The device is just the access point - the experience lives in the cloud

This is where the provisioning model matters. Devices built for AI and cloud-native work should be treated as Windows Autopilot-only from day one. No imaging. No manual setup. No legacy deployment tooling. These devices are designed for cloud-native management through Microsoft Intune, and any other approach adds complexity without adding value.

The shift to ARM64 is not a niche concern. It is the direction Microsoft and its hardware partners are investing in. Organizations that ignore it will find themselves managing two increasingly divergent device fleets - one that supports the future and one that does not.

Let users choose the device - not IT

Here is the uncomfortable truth: most users do not care about the device. They care about the experience.

They want to open their laptop and get to work. They want their apps, their files, their settings - ready and waiting. They want performance that does not get in the way. And they want this regardless of whether they are sitting at a desk, working from home, or borrowing someone else’s machine.

When the experience is decoupled from the device, something powerful happens. The device becomes a window into the workspace - not the workspace itself. And that changes everything about how you think about procurement, deployment, and support.

This is exactly what Windows 365 and the Windows 365 Cloud PC category enable.

With a Windows 365 Cloud PC, the full Windows desktop is streamed securely from the Microsoft Cloud to any device. Apps, settings, data, and identity - everything follows the user, not the hardware. A lost laptop is an inconvenience, not an incident. A delayed shipment does not mean a delayed start date. And a user who needs a different device for a different context can switch without losing a single thing.

In this model, users can choose the device that fits their work style and their context - and that includes macOS. A Mac user with the Windows App gets a full, native Windows 365 Cloud PC experience without needing a Windows device at all. The same apps, the same desktop, the same data - streamed to their Mac and managed by IT through Microsoft Intune. For organizations with mixed fleets, this eliminates the need to force a platform choice on users who are more productive on macOS while still maintaining a consistent Windows workspace for business applications.

Windows laptop, Mac, or phone - the Windows 365 Cloud PC remains the constant
Windows laptop, Mac, or phone - the Windows 365 Cloud PC remains the constant

The strategy extends beyond laptops. As I explored in Your phone is already a Windows 365 workstation, a modern smartphone connected to a dock, keyboard, and mouse can deliver the same Windows 365 Cloud PC experience. Whether it is a Windows laptop as the primary platform, a Mac for day-to-day work, or a phone as a disaster recovery fallback - the Windows 365 Cloud PC remains the constant. What the user holds in their hands does not.

IT does not need to standardize on a single hardware platform to maintain control. The control lives in the cloud - in Microsoft Intune, in Microsoft Entra ID, and in the security baselines that govern the Windows 365 Cloud PC. Not the physical endpoint.

This shift changes the operating model entirely. Instead of managing physical devices - imaging, patching, recovering broken PCs - IT manages the experience. Windows 365 Cloud PCs are always updated, centrally managed, and monitored with built-in analytics. IT teams can detect issues before users report them and right-size resources instead of over-provisioning. The result is fewer performance-related tickets and a support model that does not depend on which device a user has or where it was shipped from.

There is another angle worth considering. Windows 365 also supports Windows 10 - and that matters more than it might seem. Organizations still running Windows 10 workloads due to app compatibility, hardware constraints, or migration timelines can move those workloads to a Windows 365 Cloud PC and stay fully patched and secure without purchasing Extended Security Update  licenses. The OS upgrade and the hardware refresh become two separate decisions instead of one forced march. Security exposure disappears without rushing a Windows 11 rollout, and the organization buys time to migrate on its own terms.

For organizations further along the cloud-native maturity curve, Windows 365 Reserve  takes this model even further - but that is a topic for a future post.

Devices are strategic - treat them that way

Many organizations are still trying to solve modern challenges with legacy endpoint models. That gap is growing - and so is the cost. With Windows 365, hardware age matters less. Recovery becomes minutes instead of days. Device loss stops being a crisis. Windows 11 adoption is no longer tied to buying new hardware. These are not future promises. They are available now.

The device conversation needs to change. It is not about finding the cheapest hardware or locking in a vendor deal for the next three years. It is about designing an endpoint strategy where the device is a flexible, replaceable component - not the load-bearing wall.

When the experience lives in the cloud, the device becomes a choice, not a constraint. Users can pick what works for them. IT can focus on security, governance, and experience quality. And the organization stops being held hostage by hardware prices, delivery timelines, and refresh cycles.

A simple recommendation: consider Windows 365 first, then work backwards. Evaluate which users truly need a physical PC. Identify where cloud-based Windows reduces cost and risk. And look at how device lifecycle, support, and security can be simplified.

The organizations that move fastest will not be the ones with the best procurement deals. They will be the ones that stopped treating devices as a commodity - and started treating them as a strategic decision.

–Jesper

Header image attribution: Image created with help from Microsoft Copilot