What is Microsoft Intune? (2024)

By

  • Peter van der Woude,KPN ICT Consulting
  • John Moore,Industry Editor

What is Microsoft Intune?

Microsoft Intune is a cloud-based unified endpoint management (UEM) tool that aims to help organizations manage the mobile devices employees use to access corporate data and applications, such as email.

It is a component of Microsoft's Enterprise Mobility + Security (EMS) offering, a mobile device management and mobile application management (MAM) platform. Intune is designed to integrate with other parts of the EMS offering, including Azure Active Directory (Azure AD) and Microsoft Azure Information Protection. Intune's app protection policy component uses the Azure AD identity to separate corporate and personal data.

Microsoft Intune features and capabilities

Over the years, Microsoft Intune has evolved into a cross-platform tool for managing devices and apps. The most important features and capabilities include the following:

  • Manage personally owned and company-owned devices of the most common platforms and provide secure access to company data on those devices. Microsoft Intune currently supports management for Android, iOS and iPadOS, Linux, macOS, Windows and ChromeOS devices.
  • Manage the lifecycle of apps on managed devices, including the deployment, update and removal of apps.
  • Manage apps on mobile devices and securely provide access to company data via those apps.
  • Enable self-service functionalities, such as resetting PIN or password, installing apps and removing devices, via the Company Portal app.
  • Integrate with mobile threat defense services for a real focus on endpoint security.
  • Provide report capabilities that provide insights into your environment. This includes reports with insights about policies, profiles, updates, apps and more.
What is Microsoft Intune? (1)

How it works

In Microsoft's approach to managing mobile devices, Intune mainly uses protocols or APIs available in mobile OSes to execute tasks, such as enrolling devices. Enrollment lets IT personnel maintain an inventory of devices that can access enterprise services. Other tasks include mobile device configuration, certificates, Wi-Fi and VPN profiles, and compliance reporting concerning corporate standards. Intune integrates with Azure AD to provide access control capabilities. That provides the required tool set for working toward a zero-trust environment.

This article is part of

What is unified endpoint management (UEM)? A complete guide

  • Which also includes:
  • 7 key benefits of mobile device management for businesses
  • Compare capabilities of Office 365 MDM vs. Intune
  • How to successfully implement MDM for BYOD

Meanwhile, Microsoft's Intune app management approach covers areas such as assigning mobile apps to the workforce, configuring those apps with standard settings and removing enterprise data from mobile apps. When used with other EMS suite services, Intune lets an organization provide apps that can access additional mobile app and data security features, such as single sign-on (SSO) and multifactor authentication.

Benefits of Microsoft Intune

Intune provides organizations with the features and capabilities to manage their devices and apps and protect company data. With the integrations of Intune with Azure AD, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft 365 and Windows Autopatch, it's an important part of the zero-trust strategy in a Microsoft cloud environment.

Intune can provide an IT department with the required features for managing enrollments, configurations, security, compliance, apps and updates on any supported device. That enables IT admins to securely provide access to company data on nearly any device.

With direct integration with Conditional Access via Azure AD, Intune can enable IT administrators to check if a device complies with company policies and only allow access to company data and apps when that device is compliant.

Challenges of Microsoft Intune

Intune excels within a Microsoft environment because it integrates well with other Microsoft products. While Intune can manage non-Windows platforms, it won't be at the same level as specialized products. For example, a product like Jamf provides more options for managing devices in the Apple ecosystem.

Additionally, organizations that use Linux devices may want to look at alternative UEM platforms. Except for verifying compliance and securely providing access to company data, no other management capabilities are currently available for Linux distributions.

History and development

Microsoft Intune launched in 2011 as Windows Intune, with the name change to Microsoft Intune announced in 2014. A key development since then was the migration of Microsoft Intune to the Microsoft Azure public cloud. In December 2016, Microsoft unveiled a preview where administrators could access and manage Microsoft Intune using the Azure portal. In June 2017, Microsoft announced the general availability of Intune management through the Azure portal.

Microsoft's Conditional Access feature became available via the Azure portal in 2017. Conditional Access works across the EMS suite, letting organizations control access to enterprise data based on considerations such as location and the sensitivity of a given application.

In 2018, Microsoft announced that the Intune Managed Browser application on iOS and Android could utilize SSO to access all web applications, both SaaS and on premises, provided those applications connect to Azure AD.

Another name change came in 2019 when Microsoft rebranded the suite that contains endpoint management. The new suite, which includes products like Configuration Manager, Intune and Windows Autopilot, was named Microsoft Endpoint Manager.

In 2022, Microsoft rebranded Microsoft Endpoint Manager back to Microsoft Intune with several new product announcements, including Remote Help, Endpoint Privilege Management, advanced endpoint analytics and Microsoft Tunnel for MAM. The first batch of expanded tools launched on March 1, 2023, and more features are planned for release later in 2023.

Microsoft Intune pricing

Intune is priced per user, per month, and organizations can purchase it as a standalone plan or a component of another subscription. The following are the three individual plans:

  1. Microsoft Intune Plan 1. Plan 1 includes basic UEM functionality and is included with subscriptions to Microsoft 365 E3, E5, F1, F3, EMS E3 and E5, and Business Premium plans. Notably, the expanded tools in Microsoft Intune Suite are purchasable as add-ons for Plan 1. The price for Plan 1 is $8 per user, per month.
  2. Microsoft Intune Plan 2. Plan 2 is an add-on to Plan 1 and features additional tools, such as Microsoft Intune Tunnel for MAM and endpoint management for specialty devices. The price for Plan 2 is $4 -- in addition to the $8 for Plan 1 -- per user, per month.
  3. Microsoft Intune Suite. Intune Suite is the highest-tier plan for Intune as a standalone service. It's an add-on to Plan 1, includes the add-ons from Plan 2 and features even more tools. The additional tools found in Intune Suite include Remote Help, Endpoint Privilege Management, advanced endpoint analytics and more tools set for release later in 2023. The price for Intune Suite is $10 -- in addition to the $8 for Plan 1 -- per user, per month.

This was last updated in March 2023

Continue Reading About Microsoft Intune

Related Terms

AWS CloudFormation (Amazon Web Services CloudFormation)
AWS CloudFormation is a free service that provides Amazon Web Services customers with the tools they need to create and manage ...Seecompletedefinition
Google App Engine
Google App Engine (GAE) is a platform-as-a-service (PaaS) product that enables web app developers and enterprises to build, ...Seecompletedefinition
What is BCDR? Business continuity and disaster recovery guide
Business continuity (BC) and disaster recovery (DR) are closely related practices that support an organization's ability to ...Seecompletedefinition

Dig Deeper on MSP technology services

  • Using the Intune management extension for PowerShell scriptsBy: Petervan der Woude
  • A guide to Intune Suite licensing for endpoint managementBy: RobertSheldon
  • Understanding Microsoft Intune Suite vs. Endpoint ManagerBy: Petervan der Woude
  • Deploying Intune's Microsoft configuration manager consoleBy: Petervan der Woude
What is Microsoft Intune? (2024)

FAQs

What is the purpose of Microsoft Intune? ›

Microsoft Intune is a cloud-based endpoint management solution. It manages user access to organizational resources and simplifies app and device management across your many devices, including mobile devices, desktop computers, and virtual endpoints.

Can Microsoft Intune see browsing history? ›

Your organization can't see: Calling and web browsing history. Email and text messages. Contacts.

Why is Intune required? ›

In conclusion, businesses require Microsoft Intune for centralized device management, application deployment, and secure corporate and personal device management. Without Intune, managing and tracking multiple devices across different platforms would be complex and time-consuming.

Is Microsoft Intune good or bad? ›

A very useful MDM with its easy onboarding, management, monitoring, and security features. I have been working with Azure AD and Intune MDM for about 6 years, and I am so glad to use these great services for device, application and user management.

Does Intune track user activity? ›

What Are Microsoft Intune Logs? Audit Logs: These logs track and monitor activities such as policy changes, device enrollment, and app management. They provide a record of actions taken by users and administrators, offering insights into who did what and when.

Can Intune wipe a personal device? ›

Supported platforms for Wipe device action

Wipe is supported on the following platforms: Android Enterprise Dedicated, Fully Managed, and Corporate-Owned Work Profile devices. Android Open Source Project (AOSP) devices. iOS/iPadOS.

Is Microsoft Intune a monitoring tool? ›

In this article

Endpoint Analytics analyzes this data, and can recommend software, help improve startup performance, and fix common support issues. In Intune, you can create a Windows Health Monitoring device configuration profile to enable this data collection, and then deploy this profile to your devices.

What is monitored in Intune? ›

Compliance Monitoring and Reporting

Intune provides robust tools to continuously assess the compliance status of devices, applications, and data within the organization. Through its comprehensive reporting capabilities, administrators can gain real-time insights into the security posture of their environment.

Can you track devices with Intune? ›

When you use the Locate device action for an Android Enterprise dedicated device that is off-line and unable to respond with its current location, Intune attempts to display its last known location. This capability uses data submitted by the device when it checks in with Intune.

Can Intune access personal data? ›

Intune doesn't collect nor allow an Admin to see the following data: An end users' calling or web browsing history. Personal email. Text messages.

Can Intune track location? ›

Let's see how to locate device with Intune. Microsoft Intune has locate device remote action to get the geographical location of Windows 10 devices. The locate device remote action for Windows 10 devices can get the location for managed Windows 10 from the Intune portal on a map.

What happens if I delete Intune? ›

The most important and direct effect of removing a user from Intune is that the user isn't able to access corporate data via that device. Besides that, that device is no longer available in the Company Portal app for the user, and the user isn't able to install any corporate apps on it.

Can you turn off Intune? ›

Go to PC Settings > Network > Workplace. Under Workplace Join, select Leave. Under Turn on device management, select Turn off. On the popup window that opens, select Turn off.

Is Intune part of Office 365? ›

Microsoft Intune is a standalone product included with certain Microsoft 365 plans, while Basic Mobility and Security is part of the Microsoft 365 plans.

What do you need to know about Microsoft Intune? ›

Intune is a cloud-based tool for unified endpoint management (UEM) by Microsoft. Its main purpose is to help companies monitor and protect their mobile devices and data from a single pane. As a quite powerful MDM and UEM tool, Intune helps organizations of all sizes that need to protect their moving devices.

What is the difference between MDM and Intune? ›

The main difference of MDM for Office 365 versus Intune is that Intune is not limited to Office 365-related scenarios. For most organizations, the management boundaries must expand to include all apps and data that can be exposed via AAD and all apps on devices that can use modern authentication.

What is the advantage of Intune over SCCM? ›

Intune is a cloud-native solution that needs minimal infrastructure and is easy to scale and deploy. Intune can be deployed quickly and managed from any location with internet access. SCCM is an on-premises solution that requires its server as well as additional infrastructure.

Top Articles
Latest Posts
Article information

Author: Nathanial Hackett

Last Updated:

Views: 6277

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Nathanial Hackett

Birthday: 1997-10-09

Address: Apt. 935 264 Abshire Canyon, South Nerissachester, NM 01800

Phone: +9752624861224

Job: Forward Technology Assistant

Hobby: Listening to music, Shopping, Vacation, Baton twirling, Flower arranging, Blacksmithing, Do it yourself

Introduction: My name is Nathanial Hackett, I am a lovely, curious, smiling, lively, thoughtful, courageous, lively person who loves writing and wants to share my knowledge and understanding with you.