Wes Ellis./ a personal notebook
Technology. Stories. Side projects.
A few things worth writing down.
← Back to Engineering

Engineering

Microsoft Intune, Before You Enroll Anything: What It Does and What to Plan

Note 1 in the thread Getting devices into Intune

Intune gets sold as "manage everything from the cloud," and that's mostly true. The part the sales slide skips is that Intune is only as tidy as the identity setup underneath it. Get that wrong and you spend the next six months explaining why half your laptops show up twice.

This is the first post in a short series on getting devices into Intune. No clicking yet. Just what the thing does, where it stops, and what to decide before you enroll anything.

What Intune actually handles

Intune is Microsoft's cloud MDM and app management service. You run it from the Intune admin center at intune.microsoft.com (it used to live at endpoint.microsoft.com under the "Endpoint Manager" name, and you'll still see that in older docs). It covers Windows, macOS, iOS/iPadOS, Android, and a handful of Linux distros.

Day to day, that means:

  • Configuration. Settings catalog and configuration profiles for everything from BitLocker to Wi-Fi to which Start menu pins show up.
  • Updates. For Windows, update rings plus feature and quality update policies built on Windows Update for Business. There are update policies for macOS and iOS/iPadOS too. Intune tells the OS when and how to update; it doesn't host the patches itself.
  • Apps. Win32 apps, Microsoft 365 Apps, store apps, line-of-business packages for Mac and mobile, and app protection policies for phones you don't own.
  • Remote actions. Wipe, Retire (removes company data and management but leaves personal stuff), Fresh Start, remote lock, restart, and a sync button you'll press far more often than you'd like to admit.
  • Compliance. Rules like "BitLocker on, OS at least this version, Defender healthy." A device either passes or it doesn't.

Where it stops

Intune doesn't really do "quarantine" on its own, which trips people up. What you actually build is a chain: Intune marks a device non-compliant, and a Conditional Access policy in Entra ID blocks that device from company apps and data until it's fixed. If you want to cut a machine off the network because it's actively compromised, that's Defender for Endpoint's device isolation, not Intune.

It also isn't a replacement for Configuration Manager in every shop. If you've got complex task sequences or on-prem software distribution you rely on, co-management lets ConfigMgr and Intune split the workloads while you move things over one slider at a time.

Sort out identity first

This is the part that deserves a whiteboard.

Where do your users live? If they're in on-prem Active Directory, you need Entra Connect Sync (formerly Azure AD Connect) or Entra Cloud Sync pushing them into Entra ID (formerly Azure AD). Intune assigns everything to Entra users and groups, so if sync is flaky, Intune will be too.

How should devices join? You've got two realistic answers for Windows:

  • Entra joined. The device only knows Entra ID. This is Microsoft's recommended path for new or reimaged machines, and it pairs nicely with Windows Autopilot. Users can still reach on-prem file shares and apps through Kerberos, as long as they have line of sight to a domain controller.
  • Entra hybrid joined. The device is domain-joined and registered in Entra ID. It makes sense for existing domain machines you aren't ready to rebuild, and it's the path you'll use if Group Policy is still doing heavy lifting. The catch is more moving parts: the sync, the service connection point, and a GPO for auto-enrollment.

Try not to mix approaches on a whim. Pick a direction for new builds, and a plan for the existing fleet.

Pick your enrollment methods

A few that cover most situations:

  • Windows Autopilot for new hardware or reimaged machines. The device ships to the user and sets itself up.
  • Automatic enrollment (the MDM user scope setting) so any Entra-joined or registered Windows device enrolls on its own.
  • Group Policy auto-enrollment for hybrid joined machines already on the domain.
  • Co-management if ConfigMgr is already on the box.
  • Apple Automated Device Enrollment and Android Enterprise for phones and Macs you buy.

Check licensing before any of this. Intune Plan 1 comes with Microsoft 365 E3, E5 and Business Premium, but "we have Office" doesn't mean you have Intune.

Start small

My one piece of hard-won advice: pilot with a group of ten people who will actually tell you when something breaks. Assign policies to that group, not to "All devices," and leave the big switch for when you've watched a few enrollments go through cleanly.

Next up in the series: enrolling a single local device so you can see the whole flow end to end.