Count the devices that can currently open your company’s email and files: office PCs, laptops at home, phones in pockets, the tablet in the meeting room, whatever the new starter brought with them. Now ask the harder question: if one of them was stolen tonight, what exactly could you do about it? For most SMEs the honest answer is “send a worried email”, which is not a device strategy.
Microsoft Intune is Microsoft’s answer to that problem, and there is a decent chance your business already owns it without using it: it is included in Microsoft 365 Business Premium. This page explains what Intune actually does, why owning it and running it are different things, and what having it managed looks like.
What Intune actually does
Intune is Microsoft’s cloud device-management platform: one console that knows every enrolled device (Windows, macOS, iOS, Android) and enforces your rules on all of them. In practice, four capabilities carry the value:
Enrolment and setup. New devices join the company configuration automatically: a new laptop unboxes into a working, secured, policy-compliant machine (Windows Autopilot) rather than an afternoon of manual setup. Leavers’ devices are wiped of company data as cleanly.
Compliance policies. Rules every device must meet to touch company data: encryption on, screen lock set, OS version current, security software running. Non-compliant devices can be blocked automatically until they mend, which converts your security standards from a memo into a mechanism, and pairs with conditional access so the block actually holds.
App and update control. Required apps deployed to every device, forbidden ones blocked, and updates rolled out on your schedule rather than each user’s whim: the mechanism behind the 14-day patching discipline that Cyber Essentials demands and audits.
Remote wipe, done properly. Lost and stolen devices wiped remotely; personally owned devices handled with the finer instrument of *selective* wipe, removing company data and access while leaving the owner’s photos and apps untouched. That distinction is what makes bring-your-own-device workable rather than merely tolerated.
Owning Intune vs running Intune
Here is the pattern we find repeatedly in audits: a business pays for Business Premium (Intune included), and every device in the company remains unenrolled, unmanaged and invisible. The licence is a capability; the value only arrives with the work: designing sensible policies, enrolling the estate, handling the exceptions (the ancient laptop, the director’s personal iPad), and then living with it: reviewing compliance reports, tuning policies as Windows and iOS evolve, wiping the occasional lost phone at 7am.
That ongoing part is why “Intune support” is a service rather than a project. Set-and-forget Intune decays like everything else in IT: policies drift out of date, new device types arrive unhandled, and two years later the console shows forty devices, of which the business owns sixty. Under our management, Intune is part of the standing device-management service: policies maintained, estate reconciled against reality, and the console watched by people who use it daily across many clients.
Intune vs other MDM tools
Dedicated MDM products exist (some excellent, particularly deep in Apple-only estates), and the honest comparison is short: if your business runs Microsoft 365, Intune’s case is usually decisive, because it is already licensed in Business Premium, natively integrated with Entra ID and conditional access (device compliance feeding sign-in decisions is the pairing that makes both stronger), and one console rather than another vendor, invoice and login. Businesses outside the Microsoft ecosystem, or with specialised fleets (rugged Android estates, kiosk deployments), sometimes fit better elsewhere, and we will say so when they do.
What managed Intune looks like with us
- Design: policies matched to your reality: what compliant means for you, which apps are required, how BYOD is handled, what happens to leavers’ access, written down and agreed.
- Rollout: estate enrolled in waves with minimal user friction: company devices first, BYOD by invitation with the selective-wipe assurance made explicitly.
- The pairing: compliance policies wired into conditional access, so “unmanaged device” and “unrestricted access” stop coexisting: the single change that most improves an M365 tenancy’s security posture after MFA.
- The living part: compliance monitoring, policy updates as platforms change, lost-device response as part of support, and the estate report that finally answers “how many devices do we actually have?”
Costwise: if you hold Business Premium licences, the platform is paid for, and management folds into standard support arrangements; on other plans, Intune licensing is a modest per-user add-on that the plan comparison puts in context.
Frequently asked questions
What is Microsoft Intune in simple terms?
A cloud console that manages every company device from one place: automatic setup, enforced security rules, controlled apps and updates, and remote wipe for lost or departed devices, across Windows, Mac, iOS and Android.
Is Intune included in Microsoft 365?
It is included in Business Premium (and enterprise E3/E5 plans); Basic and Standard require an add-on. Many Premium businesses already own it unused, which makes enabling it one of the cheapest security upgrades available to them.
Can Intune manage employees’ personal phones?
Yes, gently: app-protection and selective-wipe modes govern company data on personal devices without touching personal content, and staff see exactly what the company can and cannot do. That transparency is what makes BYOD enrolment stick.
What’s the difference between Intune and MDM?
MDM is the category; Intune is Microsoft’s product in it (technically spanning MDM and application management). For Microsoft 365 businesses it is the default choice on integration and licensing grounds; see our MDM service page for the wider discipline.
Does Cyber Essentials require something like Intune?
Not by name, but the certification’s device, patching and access controls are far easier to implement and evidence with device management in place. Assessors like consoles; memos age badly.
How disruptive is an Intune rollout?
Company devices enrol with little user impact; BYOD is opt-in with clear terms. The friction, such as it is, lives in policy design and the exceptions list, which is exactly the part experience shortens.
Find out what you already own
The first question is whether your licences already include Intune; the second is how many devices would fail your own compliance rules today. Both answers fall out of the free IT health check, along with the rollout plan and what managed device control would cost you monthly. Get in touch before the next lost laptop asks the question for you.