What is Intune? (2024)

Intune is Microsoft’s cloud-based mobile device management (MDM) solution. It provides agentless management for devices and is hosted in Azure – which means it doesn’t require on-prem infrastructure nor will it need VPNs to manage devices.

How does Intune work?

Intune is hosted in the Azure cloud and its management console can be accessed via a web browser, like Edge or Chrome. Much of the Intune functionality is policy-driven, which includes the following:

  • Device profiles for initial deployment and configuration

  • Configuration policies for devices and applications

  • Compliance policies that work with Azure Active Directory (Azure AD) to help vet conditional access to application and company data

Furthermore, policies and profiles can be deployed over the air to groups of devices or users based on what the administrator specifies. Also, profiles for initial device configuration and deployment can be distributed to Windows devices through Autopilot (or to Apple devices through Apple Business or School Manager).

What OSes are covered with Intune?

Intune can manage the following OSes:

Does Intune work with third-party software?

Intune is geared toward making it easy to patch Microsoft products. While there are some ways to update third-party apps, it costs time and/or money to make it happen.

Since Intune doesn't patch third-party applications natively, users often purchase add-on products from third-party providers to extend Intune capabilities to cover third-party application patching.

Also, Intune doesn’t support Linux operating systems nor does it help with Windows Server. This leaves organizations running SCCM (or another tool) to manage Windows Server and Linux, which usually means they have duplicative workflows and require on-prem infrastructure.

What can Intune do?

Intune’s primary use case is for more modern device management over SCCM, as it eliminates some of the requirements SCCM has like a VPN connection to the domain and (typically) on-prem infrastructure. Many organizations run both Intune and SCCM together since not all operating systems commonly seen in the enterprise are covered by just one of these tools.

But Intune can also manage bring your own device (BYOD) endpoints without requiring an agent to be installed – something that may not be permitted or possible for non-corporate owned devices.

Additionally, organizations can use Intune to deploy software to devices that use OS-specific app stores (like Apple, Google (for Android), or Microsoft stores).

However, getting a comprehensive inventory of applications on a Windows device can be tricky. That’s because Intune only detects MSI-installed applications. So other methods (like .exe) might not be reflected in device inventory and may be more difficult to manage as a result.

Now, Intune does integrate with Azure Active Directory. That means administrators can create and enforce compliance rules, such as enforcing an updated operating system (OS) version, via conditional access for users and devices. In other words, Intune can restrict access to company applications and data if the compliance criteria are not met.

Remember, Intune is an MDM, which means it can also provision Windows and Apple devices “over the air” without an agent, using Windows Autopilot or Apple Business/School Manager. This ensures new devices are ready for an employee’s first day, without the IT team ever touching the device.

Intune can also help with patching and reboots for Windows devices. But it falls short with Apple – specifically macOS. Administrators can modify update visibility in macOS with Intune, but Intune doesn’t have tools to enforce updates and reboots with macOS. So if timely update compliance with macOS is an important part of your IT and security program, you should absolutely consider other solutions.

What are the licensing requirements?

To license Intune, you’ll need to have purchased one of the following bundles from Microsoft.

  • Microsoft 365 E5

  • Microsoft 365 E3

  • Enterprise Mobility + Security (EMS) E5

  • Enterprise Mobility + Security (EMS) E3

  • Microsoft 365 Business Premium

  • Microsoft 365 F1

  • Microsoft 365 F3

  • Microsoft 365 Government G5

  • Microsoft 365 Government G3

  • Intune for Education

Do you need other software to use Intune?

To use Intune, your computers must be connected to Azure Active Directory, which is a cloud-hosted Active Directory. Historically, this has only existed on-prem. Thus, your devices must either be purely Azure AD-joined, or Hybrid Azure AD-joined (a combination of on-prem AD and Azure AD).

To use features like automatic MDM enrollment in Intune, you’ll need Azure AD Premium, which requires the purchase of an Enterprise Mobility + Security (EMS) subscription.

Should you use Intune?

The most important thing to understand is that Intune is an agentless solution, this is generally what mobile device managers (MDMs) are. So you have to consider if it’s reasonable to manage your entire estate with an agentless solution, or if a blend of agent-based and agentless management is best. Agentless solutions can be helpful for BYOD devices or for touchless provisioning, but the level of control an agent-based solution offers is greater than agentless solutions.

With Intune (and other agentless solutions), you’re restricted to what controls the OS has made available through Windows Autopilot or Apple Business/School Manager, as well as what the MDM solution has enabled in their UI for control.

For example, Intune doesn’t have a control available for reboots and shutdown of macOS yet. But an agent-based solution may be flexible enough to easily script such an action.

Also, if you have servers, Linux-based or Windows Server, you won’t be able to manage them with Intune. So you might want to consider other solutions. If you opt for Intune anyway, just be prepared to manage servers and laptops/desktops with other tools.

However, if managing and enforcing third-party updates is a priority, you’ll definitely need another solution or a third-party add-on purchase to accompany Intune.

In the end, Intune can be a great tool to help modernize your device management capabilities and eliminate some on-prem infrastructure. But the solution itself likely won’t meet all needs of a modern organization that requires control over servers, third-party apps, and more via the cloud.

Automox for Easy IT Operations

Automox is the cloud-native IT operations platform for modern organizations. It makes it easy to keep every endpoint automatically configured, patched, and secured – anywhere in the world. With the push of a button, IT admins can fix critical vulnerabilities faster, slash cost and complexity, and win back hours in their day.

Grab your free trial of Automox and join thousands of companies transforming IT operations into a strategic business driver.

What is Intune? (2024)

FAQs

How do you explain Intune? ›

Intune can isolate organization data from personal data. The idea is to protect your company information using policies that you configure and deploy. For organization-owned devices, you want full control over the devices, especially security. When devices enroll, they receive your security rules and settings.

What is Intune in layman terms? ›

Put simply, Microsoft Intune is a cloud-based unified endpoint management (UEM) platform. It makes the admin process easier for organisations by providing one place from which admins can protect data, manage end user access, and support end users.

Can Intune track browsing history? ›

Intune doesn't collect nor allow an Admin to see the following data: An end users' calling or web browsing history. Personal email. Text messages.

Is Intune legit? ›

Microsoft Intune is a versatile mobile device management solution that offers numerous advantages for individuals and organizations alike. With its centralized device management, it provides control and ease of use for those on the move, while also addressing security and compliance requirements.

What is Intune doing? ›

That enables IT admins to securely provide access to company data on nearly any device. With direct integration with Conditional Access via Azure AD, Intune can enable IT administrators to check if a device complies with company policies and only allow access to company data and apps when that device is compliant.

What is monitored in Intune? ›

Microsoft Intune reports allow you to more effectively and proactively monitor the health and activity of endpoints across your organization, and also provides other reporting data across Intune. For example, you'll be able to see reports about device compliance, device health, and device trends.

What is Intune called now? ›

Effective October 12, 2022, Microsoft Intune becomes the name of the endpoint management family with the name Microsoft Endpoint Manager no longer being used. Going forward, Microsoft will refer to cloud management as Microsoft Intune and on-premises management as Microsoft Configuration Manager.

Who uses Intune? ›

Who uses Microsoft Intune?
CompanyWebsiteRevenue
uShipuship.com10M-50M
improveit 360improveit360.com1M-10M
PicPaypicpay.com>1000M
The Goatlcgoat.com10M-50M
1 more row

Which of the following best describes Microsoft Intune? ›

Question: Which of the following BEST describes Microsoft Intune? answerIntune is a tool that focuses on blocking user access to features such as transferring data between apps. Intune is a tool that focuses on limiting device access to a single app and restricting access to all other features and apps.

Can Intune see my photos? ›

Things your organization can never see

Contacts. Calendar. Passwords. Pictures, including what's in the photos app or camera roll.

Does Intune track user activity? ›

In Microsoft Intune, there are audit logs that include a record of activities that generate a change. For example, the create, update (edit), delete, assign, and remote actions all create audit events.

Can my employer see what websites I visit on my personal phone? ›

Although the law does not allow your employer to monitor your personal browsing history, they can still look at the internet history of your work devices.

Can Intune track your location? ›

Corporate-owned work profile devices running Android 12 or above require the end user to grant Intune app location permission by going to Settings > Apps > Intune (in the Work tab) > Permissions > Location > Allow all the time.

What are the disadvantages of using Microsoft Intune? ›

Originally built for Microsoft-exclusive IT infrastructure, While Intune provides robust endpoint management within the Microsoft ecosystem, its support for non-Microsoft endpoint devices and networks is limited. This can be problematic for organizations using a diverse range of operating systems and devices.

What does Intune do to your phone? ›

It involves connecting and configuring each device with a management platform or system, allowing administrators to access them remotely. Having managed devices enrolled in Intune can be monitored continuously and kept secure through company policies while providing control for application delivery.

What is Intune vs Azure? ›

Azure Active Directory (Azure AD) is a universal identity management platform that incorporates user credentials and strong authentication policies to safeguard your company's data, while Microsoft Intune provides cloud-based mobile device management (MDM) and mobile application management (MAM).

What is the difference between SCCM and Intune? ›

Both Intune and SCCM can do the following tasks, but they accomplish these tasks in different ways since Intune is cloud-based and SCCM is agent-based: Manage applications: Intune and SCCM can update, install, or uninstall applications on end user devices.

Top Articles
How to know it's time for a new PC
15 Countertop Trends 2024 | Find The Best Countertop Options On The Market | Marble Systems, Marble Supplier, Marble Travertine Granite Tile
Golden Abyss - Chapter 5 - Lunar_Angel
Tmf Saul's Investing Discussions
It may surround a charged particle Crossword Clue
El Paso Pet Craigslist
Tabc On The Fly Final Exam Answers
Occupational therapist
Ixl Elmoreco.com
Toyota gebraucht kaufen in tacoma_ - AutoScout24
According To The Wall Street Journal Weegy
83600 Block Of 11Th Street East Palmdale Ca
Gas Station Drive Thru Car Wash Near Me
Valentina Gonzalez Leak
Morgan And Nay Funeral Home Obituaries
Procore Championship 2024 - PGA TOUR Golf Leaderboard | ESPN
Amc Flight Schedule
Transfer and Pay with Wells Fargo Online®
Parent Resources - Padua Franciscan High School
Grandview Outlet Westwood Ky
Craigslist Pinellas County Rentals
St. Petersburg, FL - Bombay. Meet Malia a Pet for Adoption - AdoptaPet.com
ABCproxy | World-Leading Provider of Residential IP Proxies
Is A Daytona Faster Than A Scat Pack
Https Paperlesspay Talx Com Boydgaming
Georgia Cash 3 Midday-Lottery Results & Winning Numbers
MyCase Pricing | Start Your 10-Day Free Trial Today
Low Tide In Twilight Ch 52
Www.craigslist.com Austin Tx
Synergy Grand Rapids Public Schools
Wood Chipper Rental Menards
2011 Hyundai Sonata 2 4 Serpentine Belt Diagram
Miles City Montana Craigslist
Mami No 1 Ott
Restored Republic
A Grade Ahead Reviews the Book vs. The Movie: Cloudy with a Chance of Meatballs - A Grade Ahead Blog
First Light Tomorrow Morning
Steven Batash Md Pc Photos
Kips Sunshine Kwik Lube
Www Craigslist Com Brooklyn
Callie Gullickson Eye Patches
QVC hosts Carolyn Gracie, Dan Hughes among 400 laid off by network's parent company
Booknet.com Contract Marriage 2
Marcal Paper Products - Nassau Paper Company Ltd. -
Yourcuteelena
Skyward Cahokia
Random Animal Hybrid Generator Wheel
How the Color Pink Influences Mood and Emotions: A Psychological Perspective
Sinai Sdn 2023
Black Adam Showtimes Near Kerasotes Showplace 14
Sdn Dds
Ark Silica Pearls Gfi
Latest Posts
Article information

Author: Duncan Muller

Last Updated:

Views: 5576

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.