/* Senior Platform Manager at Patagonia */
Hi, I'm Colton Fouch. I keep 2,000+ people working.
I run endpoint strategy, identity, and live production infrastructure for a global hybrid workforce. Zero-touch deployment, passwordless sign-in, and town halls that don't drop.
~ $ whoami --verbose
- role
- Sr. Platform Manager, Patagonia
- fleet
- 2,000+ endpoints
- mdm
- Jamf Pro + Intune
- provisioning
- < 20 min, zero-touch
- auth
- Platform SSO, passwordless
- location
- Ventura, CA
~ $
Featured work
Zero-Touch Deployments
A fully automated macOS deployment workflow that replaced manual imaging across 2,000+ endpoints.
- Jamf Pro
- Apple Business Manager
- macOS
- Bash
// Provisioning cut from hours to under 20 minutes
Platform SSO & Identity
Secure Enclave-backed Platform SSO and Jamf Connect least-privilege admin, replacing password-based sign-in.
- Jamf Connect
- Platform SSO
- Entra ID
// Passwordless sign-in, enterprise-wide
Live Streaming Infrastructure
Broadcast-grade streaming for company-wide town halls, integrating OBS, ProPresenter, and Microsoft Teams.
- OBS Studio
- ProPresenter
- Teams
// Hybrid events reaching thousands of employees
Patch Automation
macOS and iOS patch strategy in Jamf Pro with automated compliance reporting and remediation.
- Jamf Pro
- macOS
- iOS
// Hands-off patch compliance across the fleet
Content Caching
Apple Content Caching servers across key network segments to keep software delivery local.
- Content Caching
- DNS/DHCP
- Networking
// Lower WAN bandwidth, faster installs
Architecture decisions
The reasoning behind key infrastructure choices: context, the decision, what I turned down, and what it cost.
ADR-001 Jamf Pro + Intune hybrid over Intune-only for macOS Accepted
context
When Microsoft began expanding Intune's macOS capabilities, we faced a decision: consolidate all endpoint management under Intune (reducing vendor count) or maintain a best-of-breed hybrid with Jamf Pro for macOS and Intune for Windows. The fleet included 1,500+ Macs and 500+ Windows devices, with deep investment in Jamf Pro automation and zero-touch workflows.
decision
Maintained Jamf Pro as the primary macOS MDM with Intune for Windows, integrated through Entra ID for unified identity. Kept platform-specific tooling where it provided measurable advantage rather than forcing consolidation at the expense of capability.
alternatives considered
- Intune-only: Would have required rebuilding zero-touch workflows from scratch with fewer macOS-specific controls. Estimated 6-12 month migration with degraded macOS management during transition.
- Jamf-only with Intune connector: Lighter touch but would have left Windows devices without mature management, creating a gap for the 25% of fleet on Windows.
- Third-party unified MDM (Workspace ONE, Kandji): Evaluated but would have required migrating both platforms simultaneously — high risk, uncertain ROI.
consequences
Mac management remains best-in-class with Jamf Pro's Apple-specific feature set (Setup Manager, Patch Management, Platform SSO integration). Windows devices managed through Intune with co-management where needed. Entra ID provides unified identity across both platforms. Ongoing cost of two MDM platforms is offset by reduced IT labor and faster incident resolution on macOS — our primary platform.
ADR-002 Platform SSO with Secure Enclave over password-based sign-in Accepted
context
Patagonia's macOS fleet relied on traditional password-based authentication synced through Jamf Connect. Password resets were a top IT ticket driver, and shared credentials created security risks. When Apple introduced Platform SSO with Secure Enclave support in macOS Ventura, we saw an opportunity to eliminate passwords entirely for device login.
decision
Adopted Platform SSO with Secure Enclave-backed authentication via Jamf Connect + Entra ID, phased across the fleet. Users authenticate once with biometrics (Touch ID) or local account, and the Secure Enclave handles token exchange with Entra ID — no passwords stored or transmitted.
alternatives considered
- Status quo (Jamf Connect password sync): Functional but perpetuated password-based vulnerabilities and IT ticket volume.
- Conditional Access + MFA only: Added friction without eliminating the underlying password problem.
- Full Entra ID Join: Not supported on macOS at the time and would have required Intune migration for Mac management.
consequences
Password reset tickets dropped significantly. Zero credentials stored on-device outside the Secure Enclave. Users authenticate with Touch ID — faster and more secure. However, the initial rollout required careful change management; users accustomed to password login needed training on the new biometric flow. Platform SSO adoption also required macOS Ventura minimum, creating a short-term OS upgrade push.
About
Most platform managers come from software engineering. My path runs through the trenches, and that's the advantage.
I started in IT at Guitar Center, managing the Mac fleet across 280+ retail locations. Hands-on support, hardware repair, Jamf Pro administration. I learned that infrastructure isn't abstract: it's the thing that lets a store manager open in the morning.
At Patagonia, I grew from Systems Analyst to System Administrator II to Platform Manager and now Senior Platform Manager, where I now own enterprise endpoint strategy and live production infrastructure.
Each role expanded what I was responsible for. Helpdesk taught me empathy for the end user. Systems administration taught me automation as leverage. Platform management taught me architecture as strategy. I've done every job in the chain, from imaging a single Mac to architecting zero-touch for 2,000+.
Experience
- Jul 2026 — Present
Senior Platform Manager
Patagonia · Ventura, CA
Own enterprise endpoint strategy and live production infrastructure supporting a global hybrid workforce. Lead MDM architecture across Jamf Pro and Intune for 2,000+ endpoints.
- Jamf Pro
- Intune
- Entra ID
- OBS
- Palo Alto
- Oct 2023 — Jul 2026
Platform Manager
Patagonia · Ventura, CA
Engineered zero-touch deployment workflows that cut provisioning from hours to under 20 minutes. Rolled out Platform SSO for passwordless sign-in and built the live streaming setup for company-wide town halls.
- Jamf Pro
- Intune
- OBS
- PowerShell
- Bash
- Oct 2022 — Oct 2023
IT System Administrator II
Patagonia · Ventura, CA
Managed a hybrid Windows and macOS environment spanning 2,000+ endpoints. Developed automated deployment scripts, configuration profiles, and patch workflows.
- Jamf Pro
- SCCM
- Intune
- PowerShell
- Bash
- Sep 2018 — Oct 2022
IT Systems Analyst
Patagonia · Ventura, CA
Provided end-user support for headquarters and remote employees across North America. Supported rapid pandemic-driven expansion of the hybrid work model.
- Zendesk
- Jamf Pro
- SCCM
- Oct 2016 — Sep 2018
IT Helpdesk Technician
Guitar Center · Westlake Village, CA
Delivered technical support for corporate headquarters and 280+ retail locations nationwide. Managed the Mac fleet using Jamf Pro.
- Active Directory
- Jamf Pro
- Hardware
Stack
- mdm:
- [Jamf Pro, Jamf Connect, Intune, SCCM, Apple Business Manager]
- platforms:
- [macOS, iOS/iPadOS, Windows, Apple Silicon]
- identity:
- [Entra ID, Active Directory, Platform SSO, Secure Enclave]
- network:
- [Palo Alto, DNS/DHCP, SSL Inspection, Content Caching]
- automation:
- [PowerShell, Bash, Copilot Studio, 1Password CLI]
- production:
- [OBS Studio, ProPresenter, Microsoft Teams, A/V Hardware]
certifications
- Jamf Certified Tech
- Jamf Certified Admin
- CompTIA Network+
Teaching & community
-
Workshop
Zero-Touch Deployment Workshop
Internal training for IT staff on the zero-touch workflow: Jamf Setup Manager, ABM integration, and troubleshooting common provisioning scenarios.
-
Mentorship
IT Career Mentorship
Mentoring early-career IT professionals at Patagonia through the move from helpdesk to systems administration and beyond.
-
Community
Jamf Nation
Sharing deployment patterns and troubleshooting insights with fellow Mac administrators.
Contact
Let's talk.
Open to conversations with infrastructure teams, recruiters, and anyone working on endpoint strategy, identity, or live production at scale.