1. Endpoints
Laptops, phones, peripherals, and everything else an individual uses. Provisioning, patching, configuration, and recovery when something breaks.
What hybrid changed: the device is no longer on your network or in your building.
That breaks three things at once. Patching now happens over connections you do not control, so a machine that misses a cycle can sit unpatched for weeks without anyone noticing. Hardware replacement stops being a walk to a desk and becomes a courier, a return label and several days of someone working on a personal device or not working at all. And diagnosis moves from watching a fault to hearing a description of it, which is where most of the extra time goes.
What actually helps: zero-touch provisioning so a new machine can be shipped directly to a person and configure itself, and a spares pool sized for shipping time rather than walking distance. Both cost money up front and both pay back the first time someone's laptop dies on a Monday.
What does not: asking users to bring devices in. The whole point of the arrangement is that they are not coming in.
2. Systems and software
Applications, identity, access, storage, and the integrations between them. Keeping services available and permissions correct as people join, move and leave.
What hybrid changed: surprisingly little, and this is the area people over-plan for.
Cloud services behave the same wherever the user sits. What grew is volume, because work that used to happen in rooms and corridors now runs through tools, and every one of those tools needs accounts, permissions and an integration to something else.
Where it actually bites is identity. When everyone was in a building, physical presence did some of the work of access control. Remove that and the access model has to carry the full weight on its own. Joiners, movers and leavers become higher-stakes processes, because a leaver who keeps access is not going to be spotted by someone noticing them at a desk.
What actually helps: single sign-on and a leaver process that runs automatically from the HR system rather than from someone remembering to file a ticket. The second one is the more common gap.
3. Network and connectivity
Corporate network, VPN, bandwidth, and the assumption that a user's connection is adequate.
What hybrid changed: you now support people on home broadband, hotel wifi and mobile tethering, none of which you can configure, monitor or fix.
The awkward part is that you still receive the ticket. Someone whose video keeps freezing files it with IT, because IT is who they file things with, and the honest answer is that their connection cannot carry it. That answer is correct, unwelcome, and difficult to prove.
Upload is the specific thing to check. Home connections are sold on download speed, and video conferencing depends on upload. A connection advertised at 100 down may have 10 up, shared with everyone else in the house. That single fact resolves a large share of "my video is bad" tickets, and most users have never been told it.
What actually helps: a short self-check users can run before filing, covering upload speed, wired versus wifi, and what else is using the connection. It will not fix anyone's broadband, but it moves the diagnosis to before the ticket rather than after it.
Bandwidth is one of five common causes of poor meeting quality, and two of the five cost nothing to fix. Our guide to
hybrid meeting tech problems covers how to tell them apart.
4. Shared spaces
Meeting rooms, huddle spaces, and the equipment in them. Cameras, microphones, speakers, displays and whatever is connecting them.
What hybrid changed: Everything. A meeting room used to need a screen and a cable. Now it is a small AV deployment that fails in front of an audience, and gets escalated within minutes because people are sitting there waiting.
This is also the only one of the four with no clear owner. Facilities buys the equipment as part of a fit-out, or a department picks something, or it arrived years ago and nobody remembers. IT operations rarely selects it and always inherits it, which is why room tickets are harder to close than endpoint tickets: the hardware is undocumented, several vendors are often involved in one room, the ticket is urgent by definition, and the fix is frequently a purchase somebody else has to authorise.
Component count is the one lever that does not need a budget conversation. A room with a separate camera, microphone, speaker and display has four things that can fail, four firmware paths and four vendors to contact. Fewer components means a smaller ticket surface, with nothing changing about how the room is used.
Choose room equipment that removes work rather than adding it. See the
Coolpo AI Huddle PANA, which puts the camera, microphone and speaker in one USB device with no drivers to maintain.
Conclusion
IT operations still mean what it always meant, keeping running technology running, but the perimeter moved: endpoints scattered, the network fragmented into connections you cannot control, and shared spaces turned from a screen and a cable into small AV deployments that fail in public. The first three at least have clear owners, while shared spaces do not, which is why they generate the tickets that are hardest to close and where limited attention is best spent. Knowing what is in each room, and reducing how many things each room contains, does more for ticket volume than anything else available without a budget.
Every tool you keep is one you maintain