What Is Microsoft Intune?
Microsoft Intune is a cloud-based endpoint management platform inside Microsoft 365. It handles enrolment, configuration, security policy, app deployment, and compliance reporting for Windows, macOS, iOS, Android, and Linux devices. Intune replaces older tools like Group Policy on AD-joined devices and removes the need for an on-premises MDM server.
If your business uses Microsoft 365 Business Premium, E3, or E5, you already have Intune. Most organisations pay for it and never turn it on.
Licensing
Microsoft 365 Business Premium
Full Intune for SMB (up to 300 users)
Microsoft 365 E3 / E5
Full Intune, no user cap
Intune Plan 1 (standalone)
Intune only, no M365 apps
Microsoft 365 Business Standard
No Intune. Upgrade required.
Intune Plan 2 (add-on) unlocks advanced app management, endpoint privilege management, and remote help. Most SMBs stay on Plan 1.
MDM vs MAM: Know the Difference
The single most confusing thing about Intune. Two completely different management models.
MDM (Device Management)
Full control over the device. Used for company-owned hardware.
- Device is enrolled and company-managed
- Push apps, enforce passcode, disk encryption
- Full remote wipe available
- Best for laptops, desktops, work phones
MAM (App Protection / BYOD)
Control only the work apps and data. Device stays personal.
- Device stays unenrolled and private
- Protects work data inside Outlook, Teams, OneDrive
- Selective wipe of work data only
- Best for personal phones and contractors
Enrolment Methods
Windows Autopilot
Ship devices direct from supplier. User signs in with work account and device configures itself. Zero-touch provisioning.
Apple Business Manager (ABM)
DEP enrolment for iPhones, iPads, Macs. Required for supervised iOS devices.
Android Enterprise
Fully managed, dedicated (kiosk), or corporate-owned with work profile. Pick one mode per use case.
Bulk enrolment token
For existing fleet. Use provisioning packages or CSV upload.
User-driven enrolment
User adds work account via Settings > Accounts > Access work or school. Lowest friction, least supervised.
Compliance Policies
Compliance policies define what a "healthy" device looks like. Conditional Access uses the compliance signal to decide whether to let a device access corporate resources.
Baseline compliance policy should require:
Configuration Profiles
Configuration profiles push settings to enrolled devices. Think of them as the Intune replacement for Group Policy.
Security baselines
Microsoft-maintained baseline for Windows, Edge, M365 Apps. Start here.
Endpoint security
Firewall, disk encryption, attack surface reduction rules, account protection.
Settings catalog
Granular per-setting control. Use for custom tweaks.
Administrative templates
ADMX-backed policy (like legacy GPO). Office, Edge, Chrome.
Device restrictions
Control camera, Bluetooth, USB, cloud account types, app store.
Custom (OMA-URI)
When nothing else works. Avoid unless required.
App Protection Policies (MAM)
App Protection Policies (APP) are the best-kept secret of Intune. They protect Microsoft 365 work data on any device (personal or corporate) without enrolling the device itself. Perfect for BYOD.
What APP can do:
- Require PIN to open Outlook, Teams, OneDrive, Word, Excel
- Block copy/paste from work apps into personal apps
- Block saving work files to personal iCloud or Google Drive
- Selectively wipe only the work data when someone leaves
- Require app version or OS version minimums
- Block screen capture, printing, or Siri indexing
Critical for BYOD
If staff use personal phones for work email, App Protection Policies are non-negotiable. Without them, work data sits on an unmanaged device forever. See our BYOD Guide.
Windows Autopilot
Autopilot lets you ship devices direct from Dell, HP, Lenovo, or Microsoft straight to the user. The device self-configures the first time it connects to the internet. No golden image, no imaging bench, no courier back to head office.
Typical Autopilot flow
- Supplier registers hardware hash to your Intune tenant
- Device ships direct to the employee
- Employee unboxes, connects to Wi-Fi, signs in with work account
- Intune applies compliance, configuration, apps, security baseline
- Device is ready in 30-60 minutes, fully joined to Entra ID
Conditional Access Integration
Intune on its own is just a manager. Combined with Conditional Access, it becomes a security gate.
Essential CA policies that use Intune signals:
- Require compliant device for access to Microsoft 365
- Require app protection policy for mobile access to Outlook, Teams, SharePoint
- Block unmanaged devices from downloading files in SharePoint / OneDrive
- Require hybrid join or Intune enrolment before high-risk apps open
See our Microsoft 365 Security Baseline for the full set of recommended Conditional Access policies.
Device identity matters
Whether a device is Entra Joined (corporate-owned) or Entra Registered (BYOD) changes what Conditional Access can actually enforce. See the Entra Joined vs Registered comparison for the decision logic.
Common Mistakes
Treating Intune as optional
If you have Business Premium or E3, you are paying for it. Not using it leaves a massive security gap.
Forcing MDM on personal phones
Staff resist enrolment of personal devices. Use App Protection Policies instead.
No compliance policy at all
Without a compliance policy, Conditional Access cannot differentiate managed from unmanaged devices.
Skipping security baselines
Microsoft ships tested baselines. Not starting from them costs weeks of tuning.
Breaking Autopilot with wrong profile scope
Autopilot profiles targeted to the wrong group cause devices to land in personal mode. Test carefully.
No deployment rings
Push every policy to everyone instantly. First Monday rollout usually goes badly.
Recommended Rollout Plan
Phase 1 (Week 1-2)
Apply security baselines to a pilot group of 5 IT / power users.
Phase 2 (Week 3)
Roll out App Protection Policies for mobile devices across the business.
Phase 3 (Week 4-6)
Enrol all Windows devices via Autopilot (new hires) and manual enrolment (existing fleet).
Phase 4 (Week 7-8)
Activate compliance policies. Tune reporting. Fix non-compliant devices.
Phase 5 (Week 9+)
Enable Conditional Access "require compliant device" in report-only mode, then enforce.
Need Intune Deployed Properly?
We run full Intune rollouts including Autopilot setup, Conditional Access, compliance baselines, and staff enrolment for Australian businesses.

Remote Support