All Guides
Microsoft Intune

Microsoft Intune detailed look

Mobile device management, application protection, compliance policies, Autopilot, and Conditional Access. Everything an Australian business needs to manage endpoints properly.

What Is Microsoft Intune?

Microsoft Intune is a cloud-based endpoint management platform inside Microsoft 365. It handles enrolment, configuration, security policy, app deployment, and compliance reporting for Windows, macOS, iOS, Android, and Linux devices. Intune replaces older tools like Group Policy on AD-joined devices and removes the need for an on-premises MDM server.

If your business uses Microsoft 365 Business Premium, E3, or E5, you already have Intune. Most organisations pay for it and never turn it on.

Licensing

Microsoft 365 Business Premium

Full Intune for SMB (up to 300 users)

Microsoft 365 E3 / E5

Full Intune, no user cap

Intune Plan 1 (standalone)

Intune only, no M365 apps

Microsoft 365 Business Standard

No Intune. Upgrade required.

Intune Plan 2 (add-on) unlocks advanced app management, endpoint privilege management, and remote help. Most SMBs stay on Plan 1.

MDM vs MAM: Know the Difference

The single most confusing thing about Intune. Two completely different management models.

MDM (Device Management)

Full control over the device. Used for company-owned hardware.

  • Device is enrolled and company-managed
  • Push apps, enforce passcode, disk encryption
  • Full remote wipe available
  • Best for laptops, desktops, work phones

MAM (App Protection / BYOD)

Control only the work apps and data. Device stays personal.

  • Device stays unenrolled and private
  • Protects work data inside Outlook, Teams, OneDrive
  • Selective wipe of work data only
  • Best for personal phones and contractors

Enrolment Methods

Windows Autopilot

Ship devices direct from supplier. User signs in with work account and device configures itself. Zero-touch provisioning.

Apple Business Manager (ABM)

DEP enrolment for iPhones, iPads, Macs. Required for supervised iOS devices.

Android Enterprise

Fully managed, dedicated (kiosk), or corporate-owned with work profile. Pick one mode per use case.

Bulk enrolment token

For existing fleet. Use provisioning packages or CSV upload.

User-driven enrolment

User adds work account via Settings > Accounts > Access work or school. Lowest friction, least supervised.

Compliance Policies

Compliance policies define what a "healthy" device looks like. Conditional Access uses the compliance signal to decide whether to let a device access corporate resources.

Baseline compliance policy should require:

Minimum OS version (current build)
Disk encryption (BitLocker / FileVault)
Firewall enabled
Antivirus active and up to date
Secure Boot (Windows)
No jailbreak / root detected
Passcode required (6+ digits, biometric)
Screen lock timeout
EDR signal healthy (via Defender for Endpoint)
Device inactive for 30 days = non-compliant

Configuration Profiles

Configuration profiles push settings to enrolled devices. Think of them as the Intune replacement for Group Policy.

Security baselines

Microsoft-maintained baseline for Windows, Edge, M365 Apps. Start here.

Endpoint security

Firewall, disk encryption, attack surface reduction rules, account protection.

Settings catalog

Granular per-setting control. Use for custom tweaks.

Administrative templates

ADMX-backed policy (like legacy GPO). Office, Edge, Chrome.

Device restrictions

Control camera, Bluetooth, USB, cloud account types, app store.

Custom (OMA-URI)

When nothing else works. Avoid unless required.

App Protection Policies (MAM)

App Protection Policies (APP) are the best-kept secret of Intune. They protect Microsoft 365 work data on any device (personal or corporate) without enrolling the device itself. Perfect for BYOD.

What APP can do:

  • Require PIN to open Outlook, Teams, OneDrive, Word, Excel
  • Block copy/paste from work apps into personal apps
  • Block saving work files to personal iCloud or Google Drive
  • Selectively wipe only the work data when someone leaves
  • Require app version or OS version minimums
  • Block screen capture, printing, or Siri indexing

Critical for BYOD

If staff use personal phones for work email, App Protection Policies are non-negotiable. Without them, work data sits on an unmanaged device forever. See our BYOD Guide.

Windows Autopilot

Autopilot lets you ship devices direct from Dell, HP, Lenovo, or Microsoft straight to the user. The device self-configures the first time it connects to the internet. No golden image, no imaging bench, no courier back to head office.

Typical Autopilot flow

  1. Supplier registers hardware hash to your Intune tenant
  2. Device ships direct to the employee
  3. Employee unboxes, connects to Wi-Fi, signs in with work account
  4. Intune applies compliance, configuration, apps, security baseline
  5. Device is ready in 30-60 minutes, fully joined to Entra ID

Conditional Access Integration

Intune on its own is just a manager. Combined with Conditional Access, it becomes a security gate.

Essential CA policies that use Intune signals:

  • Require compliant device for access to Microsoft 365
  • Require app protection policy for mobile access to Outlook, Teams, SharePoint
  • Block unmanaged devices from downloading files in SharePoint / OneDrive
  • Require hybrid join or Intune enrolment before high-risk apps open

See our Microsoft 365 Security Baseline for the full set of recommended Conditional Access policies.

Device identity matters

Whether a device is Entra Joined (corporate-owned) or Entra Registered (BYOD) changes what Conditional Access can actually enforce. See the Entra Joined vs Registered comparison for the decision logic.

Common Mistakes

Treating Intune as optional

If you have Business Premium or E3, you are paying for it. Not using it leaves a massive security gap.

Forcing MDM on personal phones

Staff resist enrolment of personal devices. Use App Protection Policies instead.

No compliance policy at all

Without a compliance policy, Conditional Access cannot differentiate managed from unmanaged devices.

Skipping security baselines

Microsoft ships tested baselines. Not starting from them costs weeks of tuning.

Breaking Autopilot with wrong profile scope

Autopilot profiles targeted to the wrong group cause devices to land in personal mode. Test carefully.

No deployment rings

Push every policy to everyone instantly. First Monday rollout usually goes badly.

Recommended Rollout Plan

Phase 1 (Week 1-2)

Apply security baselines to a pilot group of 5 IT / power users.

Phase 2 (Week 3)

Roll out App Protection Policies for mobile devices across the business.

Phase 3 (Week 4-6)

Enrol all Windows devices via Autopilot (new hires) and manual enrolment (existing fleet).

Phase 4 (Week 7-8)

Activate compliance policies. Tune reporting. Fix non-compliant devices.

Phase 5 (Week 9+)

Enable Conditional Access "require compliant device" in report-only mode, then enforce.

Need Intune Deployed Properly?

We run full Intune rollouts including Autopilot setup, Conditional Access, compliance baselines, and staff enrolment for Australian businesses.