The world's most popular platform to manage giant ass windows envrionments is made by microsoft, it's called System Center Configuration Manager. Now called MEMCM, Microsoft Endpoint.
Before I became a dev I was a consultant setting up ConfigMgr for big companies for years.
This was good but was mostly built for managing devices the company owns, it didn't really support managing devices the user brought in, like a personal cell phone or personal laptop scenario.
So Microsoft made a new product that can handle that scenario, like how we joined Azure AD on our laptops to set them up. that's called MDM management. It uses a different channel to configure devices than SCCM did.