What is our primary use case?
It is good data protection - protecting your endpoints, information on those endpoints, and information stored centrally in Office 365. It focuses on endpoint protection, configuration, and visibility.
You need to know what you have and where it is before you can consider protection. As an MDM umbrella covering all mobile devices, we can instantly see across all of them and centrally manage policies.
How has it helped my organization?
The most obvious example of improvement is full hard drive encryption. You want all your endpoints encrypted, and if a device is lost or stolen, you want to be able to wipe it remotely or disable it remotely. MDM allows all of these features.
We can ensure all devices are encrypted, check instantly and get reports, reset them, wipe them, or block them remotely at any time from anywhere in the world. These are powerful and crucial tools for incident management and data and information governance. You need to be able to protect what you need to protect.
It's very powerful for onboarding employees. It's also powerful for integrating other software applications or pushing out solutions. For example, we use Intune, or sometimes MDM, to ensure all our computers have CrowdStrike installed. MDM automates the installation process, and we get reports confirming its success.
We can also use it to push out other important security software and see any unauthorized software present on the machines. Although we primarily use CrowdStrike for that purpose. CrowdStrike can scan every computer, identify potential threats, and prevent the installation of unauthorized software in the first place.
So, MDM is great for integration in terms of onboarding new staff remotely and securely. It confirms the computer matches all our policies and flags any non-compliance issues. Based on compliance, we can even stop non-compliant devices from connecting to our network through conditional access policies. It's all very automated within Office 365. It integrates everything together, by design.
What is most valuable?
It's excellent. Top-class product.
Fundamentally, MDM is the ability to centrally manage all of our endpoints in terms of the policies applied to them, along with all the actions we can perform on the devices themselves.
We need to harmonize policies across all machines, update them in real time, and get reports. So, all endpoints constantly communicate with Intune, allowing us to view, disable, restart, and push new policies at any moment. It's this centralized control over a distributed network of endpoints that's crucial.
Because our endpoints were remote-first, not centrally located, how else would you manage a large network of computers scattered across individual homes? An MDM solution is the only way. That's why it's so valuable.
We can manage and standardize security across your environment, identify problems, receive alerts, and so on. That's its purpose, and that's also why it's so good.
The reporting is excellent. You can draw what information you want in the reports. So, that's also excellent. I would rate the rating capabilities a ten out of ten as well.
What needs improvement?
It's hard to point to an area of improvement because, like most Microsoft cloud services, they're constantly evolving and adapting. Keeping up with the changes can be more challenging than finding features that are missing.
The only thing to consider is complexity. Think about Excel. It can do everything imaginable, but it's not necessarily the easiest software to use. You need to know how to use it.
Similarly, while Intune might have all the functions you need, finding or configuring them can be difficult, especially for new users. The key is user experience, making essential features easier to find. It's easy to get lost in the complexity.
However, I've never found a crucial function missing in Intune. It just can be challenging to navigate sometimes. They're always working on making it more user-friendly, but it's a difficult task for something so complex. So, improving user experience would be my suggestion for improvement.
In future releases, I would like to see better integration with Apple products. While they integrate reasonably well already, it's never quite as seamless or up-to-date as it is with Windows. That would be helpful because many companies have a mix of devices. So, better integration with macOS.
For how long have I used the solution?
I have been working with this product since the beginning, forever.
When I joined the company, everything was already in Office 365. No physical network, and no domain controller. All devices are connected by the internet, not a physical office network.
What do I think about the stability of the solution?
I've never had any issues with stability. I'd rate it a nine out of ten because I rarely give anything a perfect ten. But it's very stable. I haven't experienced any stability issues.
What do I think about the scalability of the solution?
It's perfectly scalable. I'd rate the scalability a ten out of ten.
There are around 200 end users using it in my company.
How are customer service and support?
The customer service and support are excellent.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We use a family of products. We don't want to put all our eggs in one basket. For example, we use software from other providers for security awareness training, phishing protection, and so on.
However, as a Microsoft Gold Partner, we're heavily integrated with Office 365, Microsoft Defender for Security Center, and everything that goes along with Azure and Office. We essentially have a suite of different tools depending on the specific need.
For our Endpoint Detection and Response (EDR) or physical endpoint security on laptops, we also use CrowdStrike. Our approach involves leveraging different options depending on their strengths.
Some vendors like CrowdStrike claim they can do everything, but we prefer specialization. We want different providers to handle different aspects of our security.
We have Microsoft Defender, which provides access to threat intelligence and also offers endpoint protection. While Defender is a competitor to CrowdStrike, we avoid using its endpoint protection functionality to maintain our distributed security approach. However, we utilize Microsoft Intune for Mobile Device Management (MDM).
And through Intune, we can push out policies that enforce specific security standards on all our computers, such as encryption.
We leverage it for managing device security policies. Additionally, all our devices access Office 365.
We use Microsoft security features within Office 365, SharePoint, and OneDrive.
How was the initial setup?
As with everything in IT, once you reach a certain level of complexity, which Intune does, the rule is: everything is easy when you know how, and everything is difficult when you don't.
Especially with something as complex as MDM, if you don't know everything, it can be very difficult. But if you do, it can be easy. So, it depends. There are very few people who know absolutely everything.
So, there is a difficulty there, but once you know how to do it, it's easy. Like user experience is not necessarily intuitive.
What's my experience with pricing, setup cost, and licensing?
The pricing is not cheap, especially with inflation. They've had to increase their prices. It's not excessive, but alright. So, it's reasonable, but it would be better if it were lower.
Which other solutions did I evaluate?
In my experience, it would be difficult to find a competitor. It's kind of the gold standard because it's Microsoft dealing with Windows. They have an inherent advantage.
If a third-party vendor tries to offer a competing MDM solution, they're always a bit behind the curve. They don't have first access to all updates or the roadmap for future developments. There's always an element of catching up.
On the other hand, Microsoft can bake these changes into the product as they make them. So, on that basis, it's quite simply the best.
What other advice do I have?
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner