What Is Microsoft Intune?
Microsoft Intune is a cloud-based unified endpoint management service that secures, configures, and manages user devices and applications across Windows, macOS, iOS, Android, and Linux. It works alongside Microsoft Entra ID to enforce compliance and protect corporate data using a Zero Trust model.
Key features and capabilities:
- Mobile device management (MDM): Enrolls whole corporate or personal devices to push security policies, configure settings, and execute remote wipes.
- Mobile application management (MAM): Controls only corporate applications and data (like Outlook or Teams) on personal devices without touching personal user content.
- Endpoint security: Applies centralized policies for antivirus, firewall, encryption, attack surface reduction, and other endpoint security controls.
- Device compliance: Evaluates devices against defined security requirements and can use compliance status with conditional access to restrict access to corporate resources.
- Application deployment: Automates device setup using Windows Autopilot, Apple Automated Device Enrollment, and Android Enterprise.
In this article:
- How Does Microsoft Intune Work?
- Key Microsoft Intune Features
- Microsoft Intune Licensing and Plans
- Microsoft Intune Pricing
- Microsoft Intune Tutorial: Getting Started
How Does Microsoft Intune Work?
Microsoft Intune operates through a cloud-based admin console, where IT administrators configure policies and deploy them to enrolled devices. Devices are enrolled using various methods depending on the operating system, such as automatic enrollment through Azure AD for Windows devices or manual enrollment for iOS and Android.
Once a device is enrolled, Intune applies security policies, app configurations, and compliance requirements, ensuring devices adhere to organizational standards. This cloud-centric approach allows for real-time updates and centralized management, regardless of where devices are located.
Intune also leverages integration with Microsoft 365 and Azure AD to authenticate users and provide conditional access to corporate resources. This means access to apps and data can be restricted based on device compliance or user identity, enhancing security without hindering productivity. From the Intune portal, administrators can:
- Monitor device health
- Generate compliance reports
- Respond to incidents
This end-to-end management model simplifies IT operations while supporting a range of deployment scenarios, from bring-your-own-device (BYOD) to fully managed corporate devices.
Key Microsoft Intune Features
1. Mobile Device Management (MDM)
Mobile Device Management (MDM) is a core feature of Microsoft Intune, enabling organizations to manage and secure devices that access corporate resources. MDM allows IT administrators to:
- Configure device settings
- Enforce security policies
- Control access to data across various platforms, including Windows, iOS, Android, and macOS
Through MDM, organizations can ensure that all enrolled devices meet security standards, such as requiring passcodes, encryption, and regular software updates. MDM also supports remote actions like device wipe, lock, and password reset, which are crucial if a device is lost or stolen. These capabilities help protect sensitive corporate information and minimize potential data breaches.
The centralized management offered by Intune’s MDM features simplifies administration, reduces operational overhead, and ensures consistent policy enforcement across the entire device fleet. This is particularly important for organizations with a mix of company-owned and personal devices in their environment.
2. Mobile Application Management (MAM)
Mobile Application Management (MAM) in Microsoft Intune focuses on controlling and protecting corporate data within applications, rather than the entire device. With MAM, IT administrators can define policies for how apps handle data, including:
- Preventing data transfer between managed and unmanaged apps
- Encrypting app data
- Requiring authentication before accessing sensitive information
MAM is especially useful for bring-your-own-device (BYOD) scenarios where employees use personal devices for work but do not want full device management. MAM policies can be applied to both Microsoft and third-party apps, providing flexibility and granular control over data access. For example, organizations can restrict copy-paste functions, block screen captures, or enforce app-specific PIN requirements.
3. Endpoint Security
Endpoint Security in Microsoft Intune provides a set of tools for protecting devices from threats and ensuring compliance with organizational security standards. Administrators can configure and deploy security baselines, which are pre-defined sets of security settings based on Microsoft’s best practices. These baselines help ensure consistent security configurations across all managed endpoints, reducing the risk of vulnerabilities due to misconfiguration.
Intune integrates with Microsoft Defender for Endpoint, enabling:
- Advanced threat protection
- Vulnerability management
- Automated remediation
IT teams can monitor security posture, respond to incidents, and generate reports from a unified interface. Endpoint Security policies can address issues like malware protection, firewall configuration, and device encryption. This integrated security management helps organizations defend against evolving threats while simplifying the task of maintaining endpoint compliance.
Related content: Read our guide to ransomware protection
4. Device Compliance
Device Compliance in Microsoft Intune enables organizations to define and enforce policies that devices must meet to access corporate resources. Compliance policies can include requirements such as:
- Minimum operating system versions
- Encryption
- Password complexity
- The absence of jailbreaking or rooting
Devices that do not meet these standards can be automatically restricted from accessing sensitive information or applications, reducing security risks. Intune’s compliance engine integrates with conditional access policies in Azure AD, allowing organizations to enforce access controls based on device status. This means only compliant devices and users can access critical resources, minimizing exposure to threats.
Administrators can view compliance reports, identify non-compliant devices, and take corrective actions through the Intune portal. This approach provides a proactive way to maintain security and regulatory requirements across a diverse device landscape.
5. Application Deployment
Application Deployment in Microsoft Intune allows IT teams to distribute and manage applications across enrolled devices efficiently. Administrators can deploy a wide range of apps, including Microsoft 365 apps, line-of-business applications, and third-party software, to users based on their roles or device types. Intune supports multiple deployment methods, such as:
- Required installs
- Available apps for self-service installation
- App updates
The deployment process is simplified through the Intune admin console, where IT can configure app settings, assign licenses, and monitor installation status. Administrators can also set up app protection policies to secure corporate data within deployed applications. By centralizing app management, Intune reduces manual effort, ensures consistent app availability, and helps maintain software compliance across the organization’s device fleet.
Microsoft Intune Licensing and Plans
Microsoft Intune licensing is organized into three plans. Intune Plan 1 provides the base cloud service for managing devices and applications. Intune Plan 2 builds on Plan 1 with advanced endpoint management capabilities, including Remote Help and Advanced Analytics. The Microsoft Intune Suite also builds on Plan 1, includes Plan 2, and combines additional endpoint management and security capabilities. Many organizations receive Intune through Microsoft 365 bundles such as Microsoft 365 E3, E5, or E7 rather than purchasing it separately.
In general, an Intune license is required for any user or device that benefits directly or indirectly from the service. Microsoft also offers device-only subscriptions for devices that are not associated with individual users, such as kiosks, dedicated devices, IoT systems, and other shared or single-purpose endpoints. Device-only licensing supports device-targeted policies, applications, and management actions. However, it does not support app protection policies, Conditional Access, or user-based features such as email and calendaring.
Intune Plan 1 for Education is included with Microsoft 365 Education A3 and A5 licenses. Administrators may also be able to manage Intune without having an Intune license themselves. Unlicensed administrator access is enabled by default for tenants created after July 2021. Older tenants can enable it manually, although licenses required by other services or features, such as Microsoft Entra ID P1 or P2, still apply.
Microsoft Intune Pricing
Microsoft Intune can be purchased through Microsoft 365 licenses or through additional products that work with Intune Plan 1. Microsoft 365 E3 provides cloud-based device and application management, while Microsoft 365 E5 includes Intune and advanced endpoint management capabilities. Organizations that do not use Microsoft 365 E3 or E5 can purchase additional products as add-ons to Intune Plan 1.
Microsoft 365 E5 is listed at $60 per user per month when paid annually, with an annual subscription that automatically renews. Actual prices can vary depending on an organization’s Microsoft agreement. The E5 plan includes Microsoft 365 E3 capabilities along with endpoint security, identity security and threat detection and response, risk-based Conditional Access, extended detection and response, data security and compliance, and controls for managing and securing applications and endpoints.
Microsoft Intune Tutorial: Getting Started
Getting started with Microsoft Intune involves preparing your environment, configuring management policies, and then enrolling devices. The following steps provide a practical deployment sequence.
1. Prepare Your Intune Environment
Before configuring Intune, determine which devices and operating systems you need to manage. Confirm that you have an Intune subscription and any other required licenses.
Intune uses Microsoft Entra ID to manage identities for users, groups, and devices. Some capabilities, including Conditional Access, multifactor authentication (MFA), and dynamic groups, can require Microsoft Entra ID P1 or P2.
You should also check platform-specific requirements. Apple device management can require an Apple MDM push certificate and other Apple tokens. Android deployments might require a managed Google Play account. Certificate-based authentication can require SCEP or PKCS certificates.
Finally, verify the network endpoints required by Intune. Make sure your network allows the necessary IP addresses, ports, and domain names so managed devices can communicate with the service.
2. Set Up Microsoft Intune
Open the Microsoft Intune admin center and prepare the tenant for device management. Confirm that your devices are supported, add the required users and groups, and assign licenses.
Because Intune integrates with Microsoft Entra ID, your existing domains, users, and groups can be used when configuring access and assigning management policies.
3. Add and Protect Applications
Create a baseline containing the applications users need. You can assign these applications before device enrollment so they are automatically deployed during enrollment. Alternatively, enroll devices first and assign applications afterward.
For personal devices that access organizational data, configure mobile application management policies. These policies can protect data in applications such as Outlook, Teams, and SharePoint without requiring the entire device to be enrolled.
You can also enable MFA in Microsoft Entra ID and configure it for applications that require stronger authentication.
4. Configure Compliance and Conditional Access
Create compliance policies that define the security requirements devices must meet. These policies can be assigned during enrollment or after devices have already enrolled.
Intune reports whether managed devices meet these requirements. You can then combine compliance policies with Microsoft Entra Conditional Access so devices must satisfy specified security requirements before accessing organizational data.
After deployment, use Intune to identify devices that do not comply with your policies and address the reported issues.
5. Configure Device and Security Settings
Create device configuration and endpoint security profiles for the settings you want to enforce or block. Intune supports different profiles for Android, iOS/iPadOS, macOS, and Windows.
Where possible, assign important profiles during enrollment. Intune then applies the profiles automatically as devices enroll. You can also create and assign them later, in which case they are delivered when devices next check in with Intune.
6. Enroll Devices
Once your policies are ready, enroll devices in Intune. Enrollment enables devices to receive compliance, application, configuration, Conditional Access, and security policies.
Enrollment methods vary by platform and deployment scenario. Users can enroll some devices themselves, while other enrollment methods can be automated so users only need to sign in with their organization account.
During enrollment, the device receives a secure MDM certificate that it uses to communicate with Intune. After enrollment, verify that required applications and profiles have been deployed and check the device's compliance status.
If your organization also uses Microsoft Configuration Manager, you can connect it to Intune using tenant attach and co-management. Tenant attach makes Configuration Manager devices available through the Intune admin center, while co-management lets Configuration Manager and Intune manage different workloads on the same Windows devices.
Strengthening Intune-Managed Endpoints with Airlock Digital
Microsoft Intune gives IT teams centralized control over enrollment, configuration, and app deployment, but managing which applications are approved is different from enforcing what is actually allowed to execute. Airlock Digital adds that enforcement layer with application allowlisting, a core capability designed to be easy to manage and scalable across large endpoint estates. By enforcing a Deny by Default model, allowlisting ensures that only trusted applications, scripts, and processes are permitted to run, and Airlock Digital pairs this with the proven workflows and flexible tooling administrators need to sustain application control in production rather than abandon it after rollout.
Key capabilities of Airlock Digital allowlisting:
- Granular policy control: Define trusted applications at the file, path, publisher, or parent process level, providing complete control over what executes in your environment.
- Advanced exception management: Handle exceptions with flexible workflows, including rule-based overrides for specific scenarios, without compromising security.
- One-time passwords (OTPs): Permit temporary execution of untrusted applications through a secure OTP mechanism, preserving operational continuity while maintaining security integrity.
- Integrated file-level intelligence: Use VirusTotal intelligence to inform and refine allowlisting policy decisions.
- Enhanced visibility: Monitor application behavior and maintain comprehensive audit trails for compliance.
- Scalable across all environments: Apply policies consistently across IT, OT, and hybrid environments, including legacy systems.
- Practitioner-built management: Simplify policy creation, updates, and exceptions using workflows built by application control practitioners.
Airlock Digital gives you precision control of what runs and what doesn't, at enterprise scale. Learn more about Airlock Digital application allowlisting.