To set up Microsoft Intune, assign Intune and Microsoft Entra ID P1 licenses, confirm the MDM authority in the Microsoft Intune admin center, turn on Windows automatic enrollment, connect Apple and Android, build compliance policies, enroll a pilot group, then enforce with Conditional Access. A small tenant can reach a working pilot in a week; a phased production rollout typically takes 6 to 10 weeks.
This guide covers each of those steps with current admin center paths, the settings we use on real deployments, and the gotchas that generate help desk tickets. Intune is the cloud-native endpoint management platform in the Microsoft ecosystem, and if you already run Microsoft 365 it plugs straight into Microsoft Entra ID (formerly Azure AD), Conditional Access, and Defender for Endpoint. For broader context, see our guide on endpoint management solutions, and if you are still weighing Intune against on-premises tooling, read Intune vs SCCM first.
How to Set Up Intune Step by Step (Quick Version)
If you are setting up Intune from scratch, follow this sequence. It minimizes risk and lets each layer build on the previous one. The sections below unpack every step.
- Confirm licensing. Every user with a managed device needs an Intune license; Conditional Access and automatic enrollment need Entra ID P1.
- Check tenant status and MDM authority: Tenant administration > Tenant status should show the MDM authority as Microsoft Intune.
- Set enrollment restrictions: Devices > Device onboarding > Enrollment, then device platform and device limit restrictions.
- Turn on Windows automatic enrollment: Devices > Device onboarding > Enrollment > Windows tab > Automatic Enrollment, set the MDM user scope.
- Connect Apple and Android: upload the Apple MDM Push certificate and link Managed Google Play.
- Create compliance policies (Devices > Manage devices > Compliance > Create policy) with a grace period before enforcement.
- Deploy security baselines and configuration profiles to a pilot group.
- Configure app protection policies (MAM) to protect data on BYOD phones, even before enrollment.
- Enroll pilot devices: Windows Autopilot or Autopilot device preparation for new PCs, Company Portal for BYOD.
- Deploy apps and Windows update rings.
- Enable Conditional Access in Report-only, then enforce “require compliant device”. See our Conditional Access setup guide for the full policy set.
- Connect Defender for Endpoint and expand to production in phases.
Microsoft Intune Requirements and Licensing
Before you touch the Intune portal, get the licenses and identity foundation right. Skipping this step leads to enrollment failures, missing menus, and wasted time chasing licensing issues.
Intune License Requirements
Intune comes in three plans:
- Microsoft Intune Plan 1: the base service for device and app management. This is what most bundles include.
- Microsoft Intune Plan 2: an add-on to Plan 1 with advanced endpoint management capabilities.
- Microsoft Intune Suite: an add-on to Plan 1 that unifies advanced endpoint management and security capabilities (Remote Help, Advanced Analytics, Endpoint Privilege Management, Enterprise App Management, Cloud PKI). It includes Plan 2.
Most organizations get Intune Plan 1 through a bundle:
- Microsoft 365 Business Premium: includes Intune Plan 1 and Entra ID P1, capped at 300 users. The usual choice for SMBs.
- Microsoft 365 E3 / E5: include Intune Plan 1 and Entra ID P1 (E5 adds P2).
- Microsoft 365 F1 / F3: include Intune for frontline workers.
- Enterprise Mobility + Security E3 / E5: Intune plus Entra ID for organizations not on a Microsoft 365 suite.
What changed in 2026: starting July 1, 2026, Microsoft began adding Intune Suite capabilities to enterprise bundles at no separate add-on cost. Microsoft 365 E3 picks up Remote Help, Advanced Analytics, Microsoft Tunnel for Mobile Application Management, and specialty device management. Microsoft 365 E5 adds Endpoint Privilege Management, Enterprise App Management, and Microsoft Cloud PKI on top of that. The rollout was scheduled to finish by August 1, 2026. The announcement covered the E3 and E5 enterprise suites; if you are on Business Premium, assume these features are still add-ons until your tenant shows otherwise. Check Tenant administration > Tenant status before buying anything new.
Two more licensing facts worth knowing:
- Admins don’t need an Intune license. Unlicensed admin access is on by default for tenants created after July 2021. Older tenants can turn it on under Tenant administration > Roles > Administrator Licensing (it can’t be undone).
- Device-only licenses exist for kiosks and shared devices with no user affinity, but devices enrolled that way can’t use app protection policies or Conditional Access.
Licensing checklist:
- Confirm you have enough Intune licenses for every user who will enroll a device
- Assign licenses to users, ideally through group-based licensing in Entra ID
- Confirm Entra ID P1 is available (required for Conditional Access, automatic enrollment, and dynamic groups)
- Verify under Tenant administration > Tenant status: the Tenant details tab shows MDM authority, total licensed users, and total Intune licenses
Infrastructure Prerequisites
- Global Administrator (for automatic enrollment setup) or Intune Administrator role access
- Users exist in Entra ID; if you sync from on-premises AD with Entra Connect, sync is healthy (our guide to fixing Azure AD sync errors helps if it isn’t)
- A verified custom domain in Entra ID
- For Apple devices: an Apple MDM Push certificate, created with a company Apple ID that more than one person can access
- For Android Enterprise: a Managed Google Play connection
- DNS CNAME records for
EnterpriseEnrollment.yourdomain.comandEnterpriseRegistration.yourdomain.compointing to Microsoft’s enrollment endpoints, so users aren’t asked for a server address
Intune Tenant Setup in the Microsoft Intune Admin Center
The Microsoft Intune admin center at intune.microsoft.com is where all device management happens. If you have old bookmarks or documentation that point to the Microsoft Endpoint Manager admin center at endpoint.microsoft.com, that is the same console under its previous name; use intune.microsoft.com going forward.
Tenant Administration
- Tenant administration > Tenant status: verify tenant details, MDM authority (should be “Microsoft Intune”), and service health
- Tenant administration > Roles: review built-in roles and create custom roles if you need to delegate without granting full Intune Administrator
- Tenant administration > Terms and conditions: add enrollment terms if your industry requires users to accept them
- Tenant administration > Customization: add your company name, logo, and support contact details to the Company Portal
Device Enrollment Restrictions
Define which devices can enroll before you open enrollment to users. Go to Devices > Device onboarding > Enrollment.
- Under Enrollment options, select Device platform restriction. Allow or block each platform (Windows, iOS/iPadOS, macOS, Android), set minimum and maximum OS versions, and decide whether personally owned devices may enroll.
- Select Device limit restriction and lower the per-user limit to match your policy (5 or fewer is typical). Intune ships a default policy for both restriction types that applies to everyone until you assign a higher-priority one.
- If you don’t support BYOD on a platform, block personally owned devices in the platform restriction. For Windows, use corporate identifiers so legitimate corporate devices aren’t blocked.
Intune Device Enrollment by Platform
Enrollment is how devices come under Intune management. The method you pick affects the user experience, the level of control, and ongoing management.
Windows Enrollment
Step 1: Turn on automatic enrollment. This is the switch most “Intune isn’t enrolling my devices” tickets come back to.
- In the Intune admin center, go to Devices > Device onboarding > Enrollment.
- On the Windows tab, select Automatic Enrollment.
- Set MDM user scope to All (or Some with a pilot group for the rollout).
- Leave the MDM terms of use, discovery, and compliance URLs at their defaults.
- Set WIP user scope to None, then select Save.
Automatic enrollment requires Entra ID P1. With it in place, devices enroll when they join Entra ID or when a user adds a work account.
Step 2: Pick an enrollment method.
Windows Autopilot (new devices, classic):
Autopilot transforms the out-of-box experience. A user opens a new laptop, connects to Wi-Fi, signs in with their work account, and Intune handles the rest: apps, policies, and settings. No technician touches the device.
- Register device hardware hashes: have your OEM or reseller upload them, or collect them with PowerShell from existing devices
- Create an Autopilot deployment profile and choose User-driven or Self-deploying (shared devices and kiosks)
- Configure OOBE settings to hide license terms, privacy settings, and account change options
- Assign the profile to a device group
- Create an Enrollment Status Page (ESP) that blocks device use until required apps and policies are applied
- Supports Microsoft Entra join and Microsoft Entra hybrid join
Windows Autopilot device preparation (new devices, simpler):
Autopilot device preparation is the newer, streamlined version. It doesn’t require you to upload hardware hashes, uses a single policy for deployment and OOBE settings, adds the device to a security group at enrollment time (so apps and scripts start installing immediately), and gives near real-time deployment reporting.
- Requires Windows 11 22H2 or 23H2 with KB5035942 or later, or Windows 11 24H2 and later
- Supports Microsoft Entra join only (no hybrid join)
- Create the policy under Devices > By platform > Windows > Device onboarding > Enrollment > Device preparation policies > Create
- Choose the device security group, then select the apps and PowerShell scripts that must install during OOBE
- If you block personal Windows enrollment, upload corporate identifiers so device preparation isn’t blocked
Which one to use: if your fleet is all Windows 11, cloud-only, and you’d rather not manage hardware hashes, start with device preparation. If you need hybrid join, self-deploying mode, or pre-provisioning, use classic Autopilot.
Microsoft Entra join (existing devices):
- On the device, open Settings > Accounts > Access work or school > Connect
- Choose to join the device to Microsoft Entra ID
- The user signs in with their work account; with automatic enrollment on, the device enrolls in Intune
Group Policy (hybrid joined devices):
For organizations still running on-premises Active Directory, you can trigger automatic MDM enrollment for Microsoft Entra hybrid joined devices with a Group Policy object, or move them via co-management with Configuration Manager.
iOS and iPadOS Enrollment
Apple enrollment requires an Apple MDM Push certificate. Without it, iOS and macOS enrollment will not work.
- Go to Devices > Device onboarding > Enrollment, select the Apple tab, then Apple MDM Push Certificate
- Download the CSR, create the certificate in the Apple Push Certificates Portal, and upload the .pem file
- Renew it every year with the same Apple ID. There’s a 30-day grace period after expiry; miss that and enrolled Apple devices lose management
Apple Business Manager / Automated Device Enrollment (corporate devices):
- Link Apple Business Manager to Intune with an enrollment program token (on the same Apple tab)
- Create an enrollment profile that enables supervision (supervised devices allow silent app installs and single app mode)
- Assign the profile to devices in Apple Business Manager
User Enrollment (BYOD):
- Configure a user enrollment profile for personally owned iPhones and iPads
- User enrollment separates work data from personal data at the OS level
- Users install the Company Portal app from the App Store and follow the prompts
For guidance on securing personal devices, see our article on mobile device security in the workplace.
Android Enrollment
Android enrollment depends on ownership. Android device administrator mode is deprecated and no longer available on devices with Google Mobile Services, so use Android Enterprise for everything new.
Android Enterprise, corporate-owned fully managed:
- Connect Managed Google Play under Tenant administration > Connectors and tokens > Managed Google Play
- Create a corporate-owned, fully managed enrollment profile
- Enroll with QR code, NFC, zero-touch, or token
Android Enterprise, personally owned work profile (BYOD):
- Users install the Intune Company Portal app from Google Play
- Enrollment creates a separate work profile that isolates corporate apps and data
- You manage only the work profile: you can’t wipe personal data or see personal apps
BYOD vs Corporate-Owned: Choosing the Right Approach
Organizations that support BYOD policies need to balance security requirements with employee privacy.
| Factor | Corporate-Owned | BYOD (Personal) |
|---|---|---|
| Management level | Full device management | Work profile / app-level only |
| Wipe capability | Full device wipe | Selective wipe (work data only) |
| App visibility | All apps visible to IT | Only work apps visible |
| Privacy | Company owns the device | Personal data stays private |
| Cost | Organization purchases devices | Employee provides device |
| User experience | IT controls the full device | Work and personal are separated |
For most organizations, a mixed approach works best: corporate-owned devices for people who handle sensitive data, and BYOD with work profiles or app protection for everyone else.
How to Configure Intune Compliance Policies
Compliance policies define the minimum security bar a device must meet to be “compliant.” On their own, they only report. Paired with Conditional Access, a non-compliant device is blocked from corporate resources. That combination is how Intune and Entra ID enforce Zero Trust principles.
Creating Compliance Policies
- Go to Devices > Manage devices > Compliance > Create policy.
- Pick the platform: Android Enterprise, iOS/iPadOS, macOS, Windows 10 and later, or Linux (Ubuntu Desktop 24.04/26.04 LTS and Red Hat Enterprise Linux 9/10 are supported).
- Name it clearly (for example, “Windows: baseline compliance”).
- Configure settings on the Compliance settings tab.
- Configure Actions for noncompliance (see below).
- Assign to a pilot group first, then Review + create.
Windows compliance settings:
- Device Health: require BitLocker, Secure Boot, and code integrity
- Device Properties: minimum OS version (block Windows versions that no longer get security updates)
- System Security: require a password, minimum length, firewall, antivirus, and antispyware
- Microsoft Defender for Endpoint: require the machine risk score to be at or under “Low” (requires the Defender for Endpoint integration)
iOS/iPadOS compliance settings:
- Require a passcode with a minimum length of 6
- Block jailbroken devices
- Set a minimum OS version
- Encryption is on by default when a passcode is set
Android Enterprise compliance settings:
- Block rooted devices
- Require Play Integrity checks and a recent security patch level
- Set a minimum OS version
- Require encryption and a screen lock with minimum complexity
Actions for Noncompliance
Don’t block access the moment a device falls out of compliance. Give users time to fix it.
- Day 0: mark the device noncompliant (you can delay this default action) and email the user explaining the issue
- Day 3: send a reminder
- Day 7: device stays noncompliant, so Conditional Access blocks corporate resources
- Day 14 (optional): retire the device (remove corporate data)
Also check compliance policy settings at the tenant level and set “mark devices with no compliance policy assigned” to Not compliant, so an unassigned device can’t slip through as compliant.
Configuration Profiles
Compliance policies check the minimum bar; configuration profiles push settings to devices: Wi-Fi, VPN, email, restrictions, and security baselines.
Go to Devices > Manage devices > Configuration > Create > New policy, choose a platform, then choose the Settings catalog (recommended for most new policies) or a template.
Security baselines:
Microsoft publishes security baselines for Windows, Defender for Endpoint, and Microsoft Edge. They configure hundreds of settings in one pass.
- Deploy the Microsoft Edge security baseline
- Deploy the Windows security baseline (review settings first; some defaults are too restrictive for some environments)
- Deploy the Microsoft Defender for Endpoint baseline
Device restrictions:
- Configure password policy, screen lock timeouts, and camera restrictions where appropriate
- Block USB storage on devices that handle sensitive data
- If you are moving off Group Policy, use Group Policy analytics to import GPOs and see which settings exist in Intune
Wi-Fi and VPN profiles:
- Create Wi-Fi profiles so devices connect automatically
- Configure VPN profiles (or Microsoft Tunnel for mobile devices)
- Use certificate-based authentication for Wi-Fi and VPN where possible
Email profiles:
- Configure Outlook for iOS and Android with app configuration policies
- Use app protection policies to stop corporate email being copied into unmanaged apps
For hardening the rest of Microsoft 365 alongside Intune, see our Microsoft 365 security hardening checklist.
Application Deployment
If users can’t get the tools they need, they find workarounds that bypass your controls. Get app deployment right early.
Microsoft Store Apps
The simplest method. Store apps update themselves.
- In Apps > All apps, add a Microsoft Store app (new)
- Search the Microsoft Store catalog for the app
- Assign as Required (auto-install), Available (user installs from Company Portal), or Uninstall
Win32 Apps
For traditional desktop applications, Intune uses the .intunewin package format.
- Download the Microsoft Win32 Content Prep Tool
- Package the app:
IntuneWinAppUtil.exe -c <source_folder> -s <setup_file> -o <output_folder> - Add a Windows app (Win32) and upload the
.intunewinfile - Set install and uninstall commands (for example,
setup.exe /quiet /norestartandmsiexec /x {ProductCode} /quiet) - Define detection rules (registry key, file, or MSI product code)
- Set requirements (OS version, disk space, architecture)
- Configure dependencies and supersedence if needed
- Assign as Required or Available
Line-of-Business (LOB) Apps
Custom apps packaged as .msi, .appx, .ipa, or .apk:
- In Apps > All apps, add the matching line-of-business app type
- Upload the package and fill in name, description, and publisher
- Assign to user or device groups
Managed Google Play and Apple Volume Purchasing Apps
- Approve apps in Managed Google Play, or buy licenses through Apple Business Manager
- Sync the apps to Intune
- Assign to device or user groups
App Protection Policies (MAM)
App protection policies protect corporate data inside apps, even on devices you don’t manage. This is essential for BYOD users who won’t enroll a personal phone.
- Create policies under Apps > App protection policies
- Data protection: block copy/paste to unmanaged apps, require encryption, block screen capture
- Access requirements: require a PIN or biometric to open work apps
- Conditional launch: block jailbroken or rooted devices, require a minimum OS version, set an offline grace period
Windows Update Rings
Intune manages Windows updates with update ring policies, replacing WSUS and Group Policy update settings for cloud-managed devices.
Configuring Update Rings
Go to Devices > By platform > Windows > Manage updates > Windows updates, select the Update rings tab, then Create profile.
- Quality update deferral: 0 days for a pilot ring, 7 days for the general population
- Feature update deferral: 30 to 90 days, depending on your testing capacity
- Active hours: prevent restarts during the working day
- Automatic update behavior: “Auto install and restart at a scheduled time” for most users
- Deadlines: force installation within a set window (for example, 5 days for quality updates, 14 days for feature updates)
- Assign rings to device groups, so policy applies without a user signing in
You can pause a ring for up to 35 days if a bad update ships, and roll back the latest update with Uninstall.
Feature Update Policies
To pin devices to a specific Windows version, use a feature update policy from the same Windows updates page:
- Select the target version (for example, Windows 11, version 25H2)
- Assign to device groups to control which devices move and when
If you’d rather not run rings by hand, Windows Autopatch can manage the ring structure for you. Don’t assign your own rings to Autopatch-managed devices.
Conditional Access Integration
Conditional Access is where Intune compliance data becomes enforcement. Without it, a non-compliant device is flagged but not blocked.
Key Conditional Access Policies for Intune
In the Microsoft Entra admin center, go to Entra ID > Conditional Access > Policies.
Require a compliant device for Microsoft 365:
- New policy targeting all users (exclude break-glass accounts)
- Target resources: Office 365
- Grant: “Require device to be marked as compliant”
- Start in Report-only and review impact before switching to On
Block unknown or unsupported device platforms:
- Block platforms you don’t manage, if they aren’t part of your endpoint strategy
Require app protection for mobile access:
- For unenrolled BYOD phones, require an app protection policy as the grant control
- This protects Outlook and Teams data on devices you don’t manage
Integrate Microsoft Defender for Endpoint:
- Connect Intune to Defender for Endpoint under Endpoint security > Microsoft Defender for Endpoint
- Turn on the compliance connection so device risk flows into compliance evaluation
- Require a machine risk score of “Low” or better in compliance policies
- Conditional Access then blocks high-risk devices automatically
Our Conditional Access policies setup guide covers the full baseline, including MFA, legacy authentication, and break-glass accounts. This integration is a core part of a Zero Trust security model, where device health is checked on every access decision.
Endpoint Security Policies
The Endpoint security node in the Intune admin center groups security policies separately from general configuration.
- Antivirus: Microsoft Defender Antivirus real-time protection, cloud-delivered protection, and scan schedules. See our guide on the benefits of endpoint protection.
- Disk encryption: BitLocker for Windows, FileVault for macOS
- Firewall: manage Windows Firewall rules in Intune instead of local Group Policy
- Endpoint detection and response (EDR): onboard devices to Defender for Endpoint
- Attack surface reduction (ASR): turn on ASR rules to block Office macro abuse, credential theft, and ransomware behavior
Reporting and Monitoring
Deployment isn’t the finish line. Monitoring is how you catch problems before they become incidents.
Key Reports to Monitor
- Device compliance: investigate devices stuck in “Not compliant” or “Not evaluated”
- App install status: Win32 failures usually trace back to detection rules
- Configuration profile status: failing profiles often mean conflicts between profiles
- Windows update reports: find devices falling behind on patches
- Enrollment failures: track enrollment issues by platform and error code
- Autopilot device preparation deployments: per-device app and script status during OOBE
Most of these live under Reports and Devices > Monitor in the Intune admin center.
Setting Up Alerts
- Send Intune diagnostic logs to a Log Analytics workspace for retention and querying
- Alert on enrollment failures, compliance changes, and policy assignment failures
- Use Troubleshooting + support for individual user and device issues
Common Pitfalls and How to Avoid Them
After deploying Intune across many organizations, the same mistakes come up again and again.
1. Not testing policies before broad deployment. Deploy new compliance policies and configuration profiles to a pilot group first. An untested compliance policy enforced through Conditional Access can lock the whole company out of email.
2. Conflicting configuration profiles. When two profiles set the same setting to different values, Intune reports a conflict and the result is unpredictable. Use the Settings catalog for visibility and audit profiles regularly.
3. Letting the Apple MDM Push certificate expire. Renew with the same Apple ID that created it. Set a calendar reminder 30 days before expiry, and use a shared mailbox for the Apple ID.
4. Forgetting automatic enrollment. If the MDM user scope is None, Entra-joined devices never enroll. Check it first when enrollment “doesn’t work.”
5. Overly aggressive compliance timelines. Blocking on day one floods the help desk. Notify first, then escalate.
6. Skipping the Enrollment Status Page for Autopilot. Without an ESP, users can start working before security policies and apps land.
7. Weak Win32 detection rules. A bad detection rule means endless reinstalls or false “success.” Test them.
8. Skipping app protection for BYOD. Many users won’t enroll a personal phone. App protection policies give you a fallback for mobile device security.
9. Not connecting Defender for Endpoint. A device can be “compliant” on encryption and passwords while running malware. The Defender integration closes that gap.
Intune Implementation Checklist
Use this as a project plan. Each phase should be stable before the next one starts.
Phase 1: Foundation (week 1)
- Licenses assigned; Entra ID P1 confirmed
- MDM authority confirmed; roles, branding, and terms configured
- Enrollment restrictions and Windows automatic enrollment configured
- Apple MDM Push certificate and Managed Google Play connected
Phase 2: Policies in pilot (weeks 2 to 3)
- Compliance policies assigned to a pilot group with grace periods
- Security baselines and configuration profiles assigned to the pilot
- App protection policies live for mobile
Phase 3: Pilot enrollment (weeks 4 to 5)
- Autopilot or Autopilot device preparation tested on new hardware
- BYOD enrollment tested on iOS and Android
- Core apps deployed; update rings created
Phase 4: Enforcement and rollout (weeks 6 to 10)
- Conditional Access in Report-only, reviewed, then switched to On
- Defender for Endpoint connected
- Production rollout group by group, never big-bang
Frequently Asked Questions
How do I set up Intune from scratch?
Assign Intune and Entra ID P1 licenses, confirm the MDM authority under Tenant administration, set enrollment restrictions, turn on Windows automatic enrollment, connect Apple and Android, create compliance and configuration policies for a pilot group, enroll pilot devices, then enforce with Conditional Access and roll out in phases.
How long does it take to deploy Intune in production?
A typical greenfield deployment takes 6 to 10 weeks: about a week for licensing and tenant setup, two weeks for policies in pilot, two weeks of pilot enrollment, and two to four weeks of phased rollout. Migrations from another MDM product often take three to six months, depending on device and app counts.
Is endpoint.microsoft.com still the Intune portal?
The Microsoft Endpoint Manager admin center at endpoint.microsoft.com is the old name for the same console. Microsoft now calls it the Microsoft Intune admin center, and the current address is intune.microsoft.com.
What are the Microsoft Intune requirements?
You need an Intune license for each user with a managed device (Intune Plan 1 is included in Microsoft 365 Business Premium, E3, and E5), Entra ID P1 for Conditional Access and automatic enrollment, users in Entra ID, an Apple MDM Push certificate for Apple devices, and a Managed Google Play connection for Android Enterprise. Admins don’t need an Intune license on tenants created after July 2021.
What is the difference between Windows Autopilot and Autopilot device preparation?
Classic Windows Autopilot needs device hardware hashes registered in advance and supports Entra join, hybrid join, self-deploying mode, and pre-provisioning. Autopilot device preparation needs no hardware hash upload, uses one policy for all settings, adds the device to a security group during enrollment, and has better real-time reporting, but it requires Windows 11 and supports only Microsoft Entra join.
Do I need Intune if I already use Group Policy?
Group Policy only manages domain-joined Windows devices that can reach a domain controller. Intune manages Windows, macOS, iOS, Android, and Linux devices from anywhere, supports BYOD, and works with Conditional Access. Most organizations move Group Policy settings into Intune as part of a cloud-first strategy, using Group Policy analytics to see what translates.
What is the difference between MDM and MAM in Intune?
MDM (mobile device management) enrolls and manages the whole device. MAM (mobile application management, or app protection policies) protects corporate data inside specific apps without managing the device. MAM is the right fit for BYOD users who won’t enroll a personal phone but still need email and files.
Can Intune replace Microsoft Defender for Endpoint?
No. Intune handles configuration and compliance; Defender for Endpoint handles threat detection and response. They work together: Intune deploys and configures Defender, and Defender sends device risk back into Intune compliance. Deploy both.
How do Conditional Access policies relate to Intune compliance?
Intune decides whether a device meets your requirements (encryption, OS version, no jailbreak) and reports the result to Entra ID. A Conditional Access policy then enforces it, for example by blocking Microsoft 365 access from noncompliant devices. Without Conditional Access, compliance policies report but don’t enforce anything.
What licensing do I need for full Intune functionality?
Microsoft 365 Business Premium covers organizations up to 300 users with Intune Plan 1 and Entra ID P1. Microsoft 365 E3 adds no user cap and, since July 2026, includes Remote Help and Advanced Analytics. Microsoft 365 E5 adds Entra ID P2, Defender for Endpoint Plan 2, and Intune Suite features such as Endpoint Privilege Management. On Business Premium, treat Intune Suite features as add-ons unless your tenant shows them as included.
How Exodata Helps
Intune isn’t a one-time project. New OS versions, new apps, and new Microsoft features mean policies need regular attention. Build a monthly review to check compliance trends, look for profile conflicts, and confirm enrollment and app deployment are healthy.
Intune is one piece of a larger security picture. Pair it with the Microsoft 365 security hardening checklist, enforce it with Conditional Access, apply Zero Trust principles across the environment, and make sure your endpoint protection strategy covers threat detection and response, not just device management.
If you want help designing, deploying, or running Intune, contact Exodata. We set up endpoint management for SMBs and mid-market teams that is secure, scalable, and doesn’t bury your help desk.