Endpoint management

Intune

Microsoft Intune

Microsoft Intune is the cloud-based endpoint management platform at the centre of Microsoft's Unified Endpoint Management stack. It is used to enrol, configure, secure, and monitor Windows, macOS, iOS/iPadOS, Android, and increasingly Linux devices from a single admin console, the Intune admin center, without relying on on-premises infrastructure like Configuration Manager site servers.

Why Intune matters in a Microsoft estate

Intune matters for endpoint teams because device, app, compliance, update, and troubleshooting signals often sit across several Microsoft admin areas. Linking these terms back to Intune and device-reporting routes helps readers move from definition to action.

How Intune shows up in practice

It combines what were historically separate disciplines, Mobile Device Management for full device enrolment and Mobile Application Management for managing individual apps on unenrolled or BYOD devices, under one licence and one policy engine. It is delivered as part of Microsoft 365 E3/E5, Business Premium, and standalone Intune Suite licensing. In day-to-day operation Intune's work is expressed through several distinct but overlapping policy types that are easy to conflate. Configuration profiles push settings such as Wi-Fi, VPN, certificates, and device restrictions. Compliance policies define the minimum security posture a device must meet, feeding directly into Conditional Access decisions. Endpoint security policies handle more security-specific configuration such as disk encryption, firewall, and antivirus settings through a narrower, security-team-oriented interface.

App protection and app configuration policies manage the application layer independent of enrolment state. Intune's practical value in a Microsoft estate is less about any single feature and more about consolidation. Replacing Group Policy Objects, SCCM/ConfigMgr, and third-party MDM tools with one cloud-native control plane reduces the operational overhead of maintaining parallel management stacks. The migration path from Group Policy is rarely a clean lift-and-shift, though, since not every GPO setting has a direct CSP-backed Intune equivalent, and gaps are commonly closed with PowerShell scripts or Settings Catalog custom OMA-URI entries. Autopilot and Autopatch both build directly on top of Intune, using its enrolment and policy engine as the foundation for zero-touch provisioning and automated update management respectively.

This means a poorly organised Intune estate, with overlapping policy assignments, conflicting configuration profiles, or stale device groups, tends to surface as failures or unpredictable behaviour in those downstream services rather than in Intune itself. Reporting and cost visibility are persistent weak points in larger estates. Assignment failures, policy conflicts, and licence consumption against actual active, compliant devices are not always obvious from the native console. This is a common reason organisations pair Intune with third-party reporting or licence-reclaim tooling, to see where paid seats and applied policies have drifted away from what devices are actually enrolled, compliant, and in active use.

Glossary