A hand-built machine is a snowflake: the settings depend on who built it and how tired they were. A managed device gets its configuration from policy — encryption on, updates enforced, antivirus configured, standard applications installed, screen lock set — so a replacement laptop is a thirty-minute task, not a day.
Microsoft Intune is the usual tool where the business already owns Business Premium. Devices enrol during setup (Windows Autopilot) or afterwards; compliance policies define what 'healthy' means; configuration profiles set the details; and conditional access can then require a compliant device before granting access to company data.
macOS fits the same model through Apple Business Manager and automated device enrolment, with Intune or another Mobile Device Management (MDM) platform applying profiles, FileVault encryption, and application deployment. A creative studio full of Macs is not an excuse to skip management.
Start with a small policy set: encryption, updates, antivirus, screen lock, local admin removal. Layer more later. An over-configured first attempt generates support tickets and gets the whole project cancelled.