Our use case for Microsoft Intune is managing end-user endpoints, specifically Windows desktops. It is not limited to Windows desktops as it can also manage Mac OS desktops, laptops, and mobile devices for both Android and Apple iOS.
In terms of needing Microsoft Intune to manage devices, first, there is a requirement that devices must be joined to an Azure domain, either hybrid joined or purely joined.
From my perspective, purely joined is really the only viable way of setting up an environment. Once devices are joined to Azure, access to Microsoft group policy is no longer available. Because group policy is not accessible in Azure, another way to manage and control devices is necessary. This alternative method uses Microsoft Intune Windows profiles.
When setting up devices using Microsoft Intune, Windows profiles can be established which perform most of the same functions that Microsoft Group Policy did in a local Windows Active Directory environment. Microsoft Intune can manage and control machines and install software. It allows for Windows provisioning on machines and enables autopilot deployment with pre-packaged installations. When a user receives the machine, sets it up, and turns it on, it connects to the domain and begins installing software, becoming ready within approximately half an hour, which represents a significant time savings for IT departments.
Companies using Microsoft Intune are much better at managing their endpoints with far more visibility. The endpoint inventory is far more accurate and up to date. The Windows versioning for the endpoints is much better, and Windows stays current. Companies not using Microsoft Intune still rely on manual or prior methods of updating and inventorying, which are subject to gaps and inaccurate information.
The Microsoft Intune management console provides visibility into the current status of machines and deployed software. It can automatically update components within its capability, primarily Microsoft products. Third-party software updates, such as VLC media player, are not within Microsoft Intune's update capabilities. Some companies, such as Adobe, have packaged their software to be updatable in Microsoft Intune, though this is more the exception than the rule. Installing software in Microsoft Intune can be challenging if it is not already prepackaged.
The stability and reliability of Microsoft Intune is good. Microsoft takes everything in, and if users stay with Microsoft, everything works together effectively.
Microsoft support for Microsoft Intune is good. In my own use of Microsoft Intune, I did not spend significant time with support because the Microsoft documentation was adequate for our needs.
In a prior environment, when setting up Microsoft Intune, we utilized a third party for assistance. They contacted Microsoft on several occasions, and their needs were answered sufficiently.
We have a couple of companies using other options besides Microsoft Intune. One company is using Avanti Neurons.
I rate the documentation for Microsoft Intune very highly, approximately nine or ten out of ten. One of our companies is beginning to provision and establish a Cloud PK to replace their legacy on-prem ADCS server.
I used Microsoft Intune extensively in setting up, running, and managing it for several years. In my current role, I don't have hands-on management responsibility for Microsoft Intune as much as responsibility for ensuring it secures the environment from a cybersecurity perspective.
From an IT infrastructure team perspective, the experience with Microsoft Intune is good, although somewhat complex to navigate initially. From an end-user perspective, the experience is good as long as the infrastructure team has done their due diligence in setting it up to remove any obstacles from the user's setup of their own machine.
I rate Microsoft Intune a ten out of ten.