Intune and Configuration Manager (MECM) (SCCM) | Selecting the Best Technology to Manage Your Company Devices — Mobile Mentor (2024)

Over the years, Microsoft has released several iterations of technology aimed at streamlining the security and management of enterprise endpoints. Distinguishing the pros and cons of each tool can be a challenge. In recent years, endpoint management has changed a lot. There are now tools made to handle the new situations that come with modern work.

In this article, we will explore how Microsoft tools, both legacy and modern, address device management challenges and endpoint security.

What is Unified Endpoint Management?

The commonality between most MDM (mobile device management) tools is that each attempts to achieve Unified Endpoint Management (UEM).UEMis a concept that often gets conflated with others such asMDM(mobile device management) and EMM (Enterprise Mobility Management). However, at its core, it is a fairly simple construct to understand.

Simply put, Unified Endpoint Management is the idea that all enterprise devices, whether they be Windows, MacOS, iOS or Android, can be viewed and managed within the same portal. Interestingly, UEM was not possible until Windows effectively became a mobile operating system, which happened with Windows 10.

What is Endpoint Manager?

Intune and Configuration Manager (MECM) (SCCM) | Selecting the Best Technology to Manage Your Company Devices — Mobile Mentor (1)

Microsoft’s Endpoint Manager (now absorbed by the Intune umbrella) is what makes UEM possible. It is the most modern tool for device management. Endpoint Manager is an umbrella technology that houses both Microsoft Intune and Microsoft’s Configuration Manager (SCCM).

Endpoint Manager combines technologies and works with tools such as Windows Autopilot, Azure AD, and Microsoft Defender. It aims to enhance security and improve the overall experience for both users and administrators.

The result is a technology that makes modern device management possible for on-premises, hybrid, and remote workers – all from a single pane of glass.

Endpoint Manager operates to achieve the following:

  • Cloud-based security of enterprise data in the cloud and on-premises
  • Management of “mobile” devices (macOS, iOS, iPadOS, Windows 10/11, Windows 365, Android), virtual machines, desktop and laptop computers
  • Streamlined devices deployment
  • In-depth endpoint analytics including compliance and usage reporting

What is Configuration Manager (SCCM)?

Microsoft’s Configuration Manager (SCCM) is the Microsoft’s legacy tool to manage Windows devices. It existed prior to a time when device management became necessary in the cloud. SCCM is based largely on device imaging and is predominately designed for domain models (which use the castle-and-moat strategy).

The tool is largely used to manage, deploy, and secure Windows devices in an enterprise in addition to launching patches and updates. However, SCCM is designed to work best with on-premises devices. It can achieve functionality external to the network, but it does require a good deal of additional configurations to get it up and running in this capacity.

Further, it cannot manage operating systems other than Windows. Also, because it relies on device imaging, there is no roll-back or wipe capability other than completely re-imaging the device again. This can take hours and often involves manual effort from IT to bring the device up to a point where a user can take over.

One advantage of Configuration Manager is that it manages Windows servers. There is no equivalent (yet) in Microsoft Intune. For those with a heavy server footprint, Configuration Manager may need to be part of your device management strategy.

What is Microsoft Intune?

Intune is the next step in Microsoft’s evolution of device management. The tool manages and secures devices in the cloud.

It works for all operating systems except Unix/Linux, Chromebooks, and servers. It is similar to SCCM. It is an incredibly effective tool for endpoint management and recently emerged as the clear leader in theGartner 2021 Magic Quadrant for Unified Endpoint Management.

Intune is designed from the ground up for remote management. In fact, it is the only way to manage Windows 365 devices (virtual machines). That considered, many admins are finding SCCM less beneficial in the modern landscape because they can’t manage non-Windows devices, and can’t effectively manage remote devices.

One of the paramount advantages of Intune is its capability to revert devices to a “golden state.” This feature, known as rapid replacement, means that if an employee leaves a company, an administrator is able to wipe the device over the air and return it to the original configuration without reimaging. The process makes onboarding and offboarding employees significantly more efficient, especially for those who work in a remote or hybrid capacity.

There is simply no equivalent to rapid replacement inSCCM, and it is only available withModern Management. This makes Intune a more scalable and versatile option for teams looking to bolster the security and employee experience via endpoint management.

Additionally, Intune can streamline the management of your apps, conditional access policies, and compliance policies. These rules make for a more manageable and secure endpoint ecosystem.

What Technology is best for my business?

Consider the current and future state of modern work when choosing an endpoint management tool, as each has its own advantages. Exacerbated by the Covid-19 pandemic, hybrid and remote work have become the norm, and this trend is likely to continue. That considered, it is important to consider that a large portion of your workforce will regularly be off premises, making device updates, patches and replacements challenging with a tool like SCCM.

Endpoint Manager is a great option to integrate a legacy tool like SCCM into your endpoint ecosystem while contributing the option of leveraging the modern advantages ofIntune. With the right configuration in place, you’ll position your business to effectively manage all devices for the foreseeable future.

Intune and Configuration Manager (MECM) (SCCM) | Selecting the Best Technology to Manage Your Company Devices — Mobile Mentor (2024)

FAQs

What are the advantages of Intune vs SCCM? ›

Intune is a cloud-native solution that needs minimal infrastructure and is easy to scale and deploy. Intune can be deployed quickly and managed from any location with internet access. SCCM is an on-premises solution that requires its server as well as additional infrastructure.

What are the benefits of MECM? ›

It ensures that devices are secure, up-to-date, and compliant with company policies, simplifies application deployment, manages patches, and assists with device troubleshooting and problem resolution. MECM helps businesses save time, reduce manual tasks, and enhance overall IT management and security.

What is the difference between SCCM and MECM? ›

The System Center Configuration Manager (SCCM), now (since 2020) known as Microsoft Endpoint Configuration Manager (MECM), is a software developed by Microsoft to help system administrators manage the servers and workstations in large Active Directory environments.

Can Intune and SCCM be used at the same time to manage devices? ›

It helps you unlock more cloud-powered capabilities like conditional access. Co-management enables you to concurrently manage Windows 10 or later devices by using both Configuration Manager and Microsoft Intune. It lets you cloud-attach your existing investment in Configuration Manager by adding new functionality.

Is Intune the replacement for SCCM? ›

So even if your ultimate goal may be to remove SCCM altogether, and your organizational requirements align with that, it does not mean that SCCM is obsolete today. For many organizations, adding Intune together with SCCM can be a better alternative.

What is the main purpose of SCCM? ›

Microsoft System Center Configuration Manager (SCCM) is a Windows product that enables the management, deployment and security of devices and applications across an enterprise.

What are the benefits of Microsoft System Center? ›

Benefits of Microsoft System Center

The System Center suite provides anywhere access to Azure management services with Azure Arc, which eases hybrid management. It also includes multiple automated workflow processes and self-service options. System Center products also streamline infrastructure and workload monitoring.

Which of the following is SCCM/MECM used for? ›

System Center Configuration Manager (SCCM) is a powerful tool for managing and deploying software on Windows-based computers. It allows administrators to manage large numbers of computers from a central location and automate the deployment of software and updates.

Is Microsoft getting rid of SCCM? ›

Version 2207 of Microsoft Configuration Manager (formerly Microsoft Endpoint Configuration Manager, System Center Configuration Manager, or SCCM) will go end of life on the 12th of February, 2024.

What is Microsoft SCCM called now? ›

This change also helped reduce confusion of the oft-used initialism SCCM that is common in other industries such as The Society of Critical Care Medicine (SCCM). In 2023 the term "endpoint" was removed to rename the product to Microsoft Configuration Manager.

What is the alternative to SCCM Configuration Manager? ›

Tools like SolarWinds Patch Manager, NinjaOne Patch Manager, and ManageEngine Desktop Central stand out as alternatives that offer you a complete patch management experience at a competitive price point.

Is Intune just for mobile devices? ›

Microsoft Intune allows management of a network of devices via the cloud. It allows monitoring of user access while simplifying app management across your many devices, including mobile devices, desktop computers, and virtual endpoints.

Can SCCM control mobile devices? ›

Configuration Manager can manage two broad categories of devices: Clients are devices like workstations, laptops, servers, and mobile devices where you install the Configuration Manager client software. Some management functions, like hardware inventory, require this client software.

How many devices can I manage with Intune? ›

Configure Intune device limit restrictions to limit the number of devices a user can enroll in Microsoft Intune. You can allow a user to enroll up to 15 devices. To create a device limit restriction, sign in to the Microsoft Intune admin center and go to Devices > Enrollment.

What is the difference between autopilot, Intune, and SCCM? ›

SCCM and WSUS are to deploy applications, Windows Updates and management of the endpoints and if you want you can even go to help-desk. Intune and Autopilot is for Cloud Management of the endpoints as an MDM and they can deploy configuration for it directly from the cloud.

Which 3 features does Microsoft Intune support? ›

Microsoft Intune Features
  • Device Management. With Intune, you manage devices using an approach that's right for you. ...
  • Application Management. ...
  • Compliance and Conditional Access. ...
  • Intune Solves Common Business Problems. ...
  • Autopilot. ...
  • Windows Update for Business. ...
  • Self Service Capabilities. ...
  • Security Baselines.
17 hours ago

What is the difference between Intune and EMS? ›

How does it integrate with Enterprise Mobility + Security? Microsoft Intune, included with Enterprise Mobility + Security, lets you manage Microsoft 365 mobile apps so you can maintain the rich, productive Microsoft 365 user experience while Intune helps keep your corporate data secure.

What is the difference between Intune and GPO? ›

In summary, both Microsoft InTune and Microsoft Group Policy have their own unique benefits. Microsoft InTune is better suited for managing devices in a cloud-based environment, while Microsoft Group Policy is better suited for managing policies on Windows devices joined to a domain.

Top Articles
Latest Posts
Article information

Author: Stevie Stamm

Last Updated:

Views: 6290

Rating: 5 / 5 (80 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Stevie Stamm

Birthday: 1996-06-22

Address: Apt. 419 4200 Sipes Estate, East Delmerview, WY 05617

Phone: +342332224300

Job: Future Advertising Analyst

Hobby: Leather crafting, Puzzles, Leather crafting, scrapbook, Urban exploration, Cabaret, Skateboarding

Introduction: My name is Stevie Stamm, I am a colorful, sparkling, splendid, vast, open, hilarious, tender person who loves writing and wants to share my knowledge and understanding with you.