No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2669466 - PeerSpot reviewer
IT Administrator at a financial services firm with 5,001-10,000 employees
Real User
Top 20
Jan 9, 2026
Device policies have improved compliance while software inventory now supports better control
Pros and Cons
  • "We handle the distribution software, collect metrics for app usage, and create policies to make the device compliant for Microsoft Intune."
  • "The interface is easy, but it is not user-friendly when evaluating the overall user experience of Microsoft Intune."

What is our primary use case?

We do use Microsoft Intune internally in our company. We handle the distribution software, collect metrics for app usage, and create policies to make the device compliant for Microsoft Intune.

The features that we use very frequently include collecting information about the software installed and determining which software is allowed from our company or not. This is our main feature for now.

We have different departments in our company, and the configuration and distribution of Copilot is another team's responsibility. We use it, but we do not have any part of that process.

What is most valuable?

We handle the distribution software, collect metrics for app usage, and create policies to make the device compliant for Microsoft Intune.

The features that we use very frequently include collecting information about the software installed and determining which software is allowed from our company or not. This is our main feature for now.

What needs improvement?

The interface is easy, but it is not user-friendly when evaluating the overall user experience of Microsoft Intune.

The settings are confusing, and it is not always clear where I apply the configuration because we have to open various pages to see where we are applying the settings that we have configured.

For how long have I used the solution?

We are using Microsoft Intune for about two years.

Buyer's Guide
Microsoft Intune
July 2026
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
907,664 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Microsoft Intune is acceptable and adapts well. I give it an eight regarding scalability.

How are customer service and support?

The technical support of Microsoft Intune rates as an eight when rated from one to ten, where ten would be the best support.

We have addressed other questions and other possible customization, and it is satisfactory because our company also has support from Microsoft directly in our company. This makes it easy for us to ask questions and request features that can be useful in our company.

Which solution did I use previously and why did I switch?

Before choosing Microsoft Intune, we did not evaluate other options other than BigFix.

How was the initial setup?

The initial setup and deployment of Microsoft Intune is easy to participate in.

What about the implementation team?

We actually used service technicians from Microsoft to deploy Microsoft Intune. We hired Microsoft technicians to do that.

The technical team from Microsoft are good technicians, and we can see that they are comfortable with the process.

Which other solutions did I evaluate?

Before choosing Microsoft Intune, we did not evaluate other options other than BigFix.

What other advice do I have?

I am involved in solutions, and we have Microsoft Intune and BigFix in our company.

We are administrators and end users of this solution. However, it is not the priority application because our priority is BigFix.

We are separated into different areas in Microsoft Intune. We have many solutions in Microsoft Intune, but for now, we are only creating policies, managing devices, and installing software because other teams handle other configurations.

We are using Microsoft Copilot in Microsoft Intune. I cannot make any comments about whether Copilot in Microsoft Intune helped protect our environment because Copilot is another department's responsibility.

We had the BigFix platform before Microsoft Intune. We chose Microsoft Intune in the first place because most of our components and services are moving to Microsoft. Microsoft Intune is adding to all the services that we now have from Microsoft.

My overall review rating for Microsoft Intune is eight.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jan 9, 2026
Flag as inappropriate
PeerSpot user
CISO at a tech services company with 10,001+ employees
Real User
Top 5
Aug 31, 2025
Efficient endpoint management and improved visibility streamline operations
Pros and Cons
  • "When a user receives the machine, sets it up, and turns it on, it connects to the domain and begins installing software, becoming ready within approximately half an hour, which represents a significant time savings for IT departments."
  • "Installing software in Microsoft Intune can be challenging if it is not already prepackaged."

What is our primary use case?

Our use case for Microsoft Intune is managing end-user endpoints, specifically Windows desktops. It is not limited to Windows desktops as it can also manage Mac OS desktops, laptops, and mobile devices for both Android and Apple iOS. 

In terms of needing Microsoft Intune to manage devices, first, there is a requirement that devices must be joined to an Azure domain, either hybrid joined or purely joined. 

From my perspective, purely joined is really the only viable way of setting up an environment. Once devices are joined to Azure, access to Microsoft group policy is no longer available. Because group policy is not accessible in Azure, another way to manage and control devices is necessary. This alternative method uses Microsoft Intune Windows profiles. 

When setting up devices using Microsoft Intune, Windows profiles can be established which perform most of the same functions that Microsoft Group Policy did in a local Windows Active Directory environment. Microsoft Intune can manage and control machines and install software. It allows for Windows provisioning on machines and enables autopilot deployment with pre-packaged installations. When a user receives the machine, sets it up, and turns it on, it connects to the domain and begins installing software, becoming ready within approximately half an hour, which represents a significant time savings for IT departments.

How has it helped my organization?

Companies using Microsoft Intune are much better at managing their endpoints with far more visibility. The endpoint inventory is far more accurate and up to date. The Windows versioning for the endpoints is much better, and Windows stays current. Companies not using Microsoft Intune still rely on manual or prior methods of updating and inventorying, which are subject to gaps and inaccurate information.

What is most valuable?

The Microsoft Intune management console provides visibility into the current status of machines and deployed software. It can automatically update components within its capability, primarily Microsoft products. Third-party software updates, such as VLC media player, are not within Microsoft Intune's update capabilities. Some companies, such as Adobe, have packaged their software to be updatable in Microsoft Intune, though this is more the exception than the rule. Installing software in Microsoft Intune can be challenging if it is not already prepackaged.

What do I think about the stability of the solution?

The stability and reliability of Microsoft Intune is good. Microsoft takes everything in, and if users stay with Microsoft, everything works together effectively.

How are customer service and support?

Microsoft support for Microsoft Intune is good. In my own use of Microsoft Intune, I did not spend significant time with support because the Microsoft documentation was adequate for our needs.

How would you rate customer service and support?

What about the implementation team?

In a prior environment, when setting up Microsoft Intune, we utilized a third party for assistance. They contacted Microsoft on several occasions, and their needs were answered sufficiently.

Which other solutions did I evaluate?

We have a couple of companies using other options besides Microsoft Intune. One company is using Avanti Neurons.

What other advice do I have?

I rate the documentation for Microsoft Intune very highly, approximately nine or ten out of ten. One of our companies is beginning to provision and establish a Cloud PK to replace their legacy on-prem ADCS server. 

I used Microsoft Intune extensively in setting up, running, and managing it for several years. In my current role, I don't have hands-on management responsibility for Microsoft Intune as much as responsibility for ensuring it secures the environment from a cybersecurity perspective. 

From an IT infrastructure team perspective, the experience with Microsoft Intune is good, although somewhat complex to navigate initially. From an end-user perspective, the experience is good as long as the infrastructure team has done their due diligence in setting it up to remove any obstacles from the user's setup of their own machine. 

I rate Microsoft Intune a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Intune
July 2026
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
907,664 professionals have used our research since 2012.
Desktop Support Engineer at COMnet Solutions (Global)
Real User
Top 20
Jul 22, 2025
Provides centralized management and positive user experience
Pros and Cons
  • "The best features in Microsoft Intune that I appreciate most are its centralized features."
  • "For macOS devices, we use the Jamf portal. I understand that the Jamf portal and server are more secure than Microsoft Intune for macOS."

What is our primary use case?

In our organization, we use Microsoft Intune for enrolling our end user devices. We handle enrollment and de-enrollment and BitLocker recovery. We manage conditional access policies, configuration profiles, MDM, MAM, and managed endpoint devices such as Android phones, iOS devices, and tablet devices. 

We use Copilot in Microsoft Intune as it is premium-based with licensing. In our organization, we have over 1000 licenses for our end users. If there is any requirement from our end users, we check their approval from their manager and provide Microsoft Copilot licenses. 

We also manage and protect our apps through Microsoft Intune and have protection tools such as DLP, Netscope, and Zscaler. We utilize monitoring features in Microsoft Intune through conditional access policy.

What is most valuable?

The best features in Microsoft Intune that I appreciate most are its centralized features. There is no concern about managing end user devices. We enroll the user devices through Microsoft Intune and can manage them from anywhere. For instance, if I am in India, I can manage a user device that is available in the USA, Dubai, or any other country. 

I assess the user experience of Microsoft Intune as a very positive experience from our user end because it is user-friendly and manageable, resulting in great reviews from our users.

We use advanced endpoint analytics, which is very useful and protective. That is the benefit of advanced analytics. We use Microsoft Enterprise features. The Enterprise Application Management feature is very useful because we simply configure through policy and do not need to worry about any disturbance or further monitoring. We check the monitor or report sheet, and everything works perfectly and smoothly.

What needs improvement?

We could benefit from some AI features in Microsoft Intune, and it would be helpful to have some automation features available.

For macOS devices, we use the Jamf portal. I understand that the Jamf portal and server are more secure than Microsoft Intune for macOS. It would be beneficial if there were ways to improve and make it more user-friendly for managing macOS devices.

For how long have I used the solution?

I have approximately 1.5 years of experience managing and supporting Microsoft Intune.

What do I think about the stability of the solution?

I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

For scalability, I would rate it a nine out of ten.

We are using it at multiple locations. In India, we have about seven offices, and we have multiple offices in UAE and the USA.

Approximately, we have 10,000 users, but at my location, I manage and support about 1,000 users.

How are customer service and support?

Their technical support deserves a rating of ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

It's not complex. It's very user-friendly. It generally takes 24 to 48 hours.

It's a hybrid environment. We use the cloud and on-prem environments.

It doesn't require any maintenance from our side.

What's my experience with pricing, setup cost, and licensing?

It's cheap. It's not expensive. 

What other advice do I have?

As compared to other products, Microsoft Intune is more secure, reliable, and user-friendly. 

I would rate Microsoft Intune a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Jeff Wickham - PeerSpot reviewer
Engineer at a healthcare company with 5,001-10,000 employees
Real User
Top 20
Nov 27, 2024
It streamlines application deployment and management, but the reporting could be more intuitive
Pros and Cons
  • "Previously, we used on-prem SCCM to deploy applications we built manually. After migrating to Intune, we automated and streamlined the process of deploying applications with autopilot. I can do more with my day. I can manage more applications and ensure that they're updated without monitoring and manually starting that process all over again."
  • "EAM is a godsend."
  • "There are challenges with Intune, specifically in reporting. Many third-party companies offer single-pane-of-glass reporting that shows you what your update environment looks like, how your patch is doing, application status, etc., but Intune's reporting is not intuitive. You can connect to Azure, monitoring, and the workbooks, but it's not streamlined."

What is our primary use case?

Currently, we use Intune for endpoint security and deployments. We're migrating from SCCM to Intune cloud-first technology. We use it to deploy applications, CSPs, and conditional access.

How has it helped my organization?

Previously, we used on-prem SCCM to deploy applications we built manually. After migrating to Intune, we automated and streamlined the process of deploying applications with Autopilot. I can do more with my day. I can manage more applications and ensure that they're updated without monitoring and manually starting that process all over again.

My director used to say that we need to have cattle, not pets. You need to care for and manage pets, but you only need to feed cattle and put them out to pasture. Once you deploy it, you just let them out to pasture, and they update themselves. It's streamlined and so easy.

What is most valuable?

I've been exploring the Intune Suite, which includes Security Copilot and enterprise application management. EAM is a godsend. I can manage my third-party applications without having to worry about it. I

I set up a proof of concept for the advanced analytics. It was very streamlined. I like the information I got from it. For example, when we were troubleshooting an application, it told me possible scenarios and commonalities between group one and group two and what could be the issue. It is great in that aspect, but we decided ultimately we didn't want to go with it.

We're still learning how Copilot fits into our environment and setting up a POC for Security Copilot. We're trialing Copilot for a subset of users to get a baseline of how we're gonna be using it. I use it to manage my day, meetings, teams, and chats. It keeps me organized.

What needs improvement?

There are challenges with Intune, specifically in reporting. Many third-party companies offer single-pane-of-glass reporting that shows you what your update environment looks like, how your patch is doing, application status, etc., but Intune's reporting is not intuitive. You can connect to Azure, monitoring, and the workbooks, but it's not streamlined. 

The user experience is still a little difficult. In the first version of Intune, everything is all over the place. It wasn't organized, and things weren't categorized. They changed the name in six months, and we had to relearn everything. 

For how long have I used the solution?

I have used Microsoft solutions for about 15 years.

What do I think about the stability of the solution?

I am very impressed with the stability of Microsoft Intune. There hasn't been an instance where things just weren't working. While there may be service alerts or outages, it doesn't significantly impact our operations.

What do I think about the scalability of the solution?


How are customer service and support?

I rate Microsoft support five out of 10. Customer service is inconsistent. Sometimes, the support provided is excellent, and the representative is knowledgeable, while other times, the service needs improvement.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We looked at Tanium and Recast for servers and management but ultimately chose to stay with Intune.

How was the initial setup?

The initial setup was made easier with online resources. After setting up some basic components and connections, everything was interconnected seamlessly.

What about the implementation team?

We used a consultant for further development after it was configured. CDW was used to help refine the setup.

What was our ROI?

There is a return on investment, particularly with the Enterprise Application Management and the efficient deployment features of Intune. It has given me more time in my workday.

What's my experience with pricing, setup cost, and licensing?

Experience with pricing and licensing was challenging. Understanding Microsoft's licensing costs can require certification, making it difficult to know exactly what is needed versus what is available.

What other advice do I have?

I would rate Intune seven out of 10. As much as I sing Intune's praises, I would like more improvements, especially in the reporting. We need to standardize how we use the solution. For example, just in October, we had the update rings completely fleshed out. Then, I went on vacation, and when I came back in October, it had completely changed with new names and new scenes. There are lots of strategic hoops to jump through, but it's a solid solution.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Joseph Merusi - PeerSpot reviewer
Collaborations engineer at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Nov 24, 2024
Everything has worked better since we started using it
Pros and Cons
  • "Our configuration profiles used to be all over the place. For example, there's a lot of legacy stuff in Active Directory. Going through Intune has helped us enforce settings, which has improved device security and functionality. When you apply something through Intune, you know it works. You don't have to worry about a legacy setting from Active Directory that was uploaded by somebody seven years ago. With Intune, you can see that a device has a setting, and you can be confident that the device is configured how you want."
  • "Everything has worked better since we started using Intune."
  • "Sometimes the syncing is inconsistent. I'm confident that the devices are checking in every eight hours, but sometimes the devices aren't picking up the settings as quickly as I would expect. Some features haven't been updated in a while, and Microsoft doesn't seem interested in developing them. Unless you talk to an engineer, you don't know whether there will be an update."

What is our primary use case?

Our primary use case of Microsoft Intune was initially to provide a more cohesive update platform. Our organization was trying to move away from SCCM as far as updating our device platforms across Windows devices. We chose Intune because it had a simplified way to configure Windows Update, view reports, and manage devices for updates. We expanded its use for configurations, moving from a hybrid join scenario to CloudJoin, which offers advantages for hybrid work and on-premise settings.

How has it helped my organization?

Everything has worked better since we started using Intune. Our devices use Intune for their authentication SSO process, which is also something that Intune integrates with, so we get fewer SSO prompts for our devices. There's more consistency in the configuration. 

Our configuration profiles used to be all over the place. For example, there's a lot of legacy in Active Directory. Going through Intune has helped us enforce settings, which has improved device security and functionality. When you apply something through Intune, you know it works. You don't have to worry about a legacy setting from Active Directory that was uploaded by somebody seven years ago. With Intune, you can see that a device has a setting, and you can be confident that the device is configured how you want.

What is most valuable?

The most valuable feature of Microsoft Intune is the extensive reporting that is available. The platform's transparency allows us to see when a device has been configured correctly and what it is receiving. 

We haven't implemented it yet, but Intune provides a cohesive platform for passwordless authentication. The single pane of glass is also huge. We were using SCCM with a third-party management platform. We took down five servers and consolidated everything into Intune. The ability to migrate everything into one platform greatly reduced our server footprint. It was effortless. We onboarded all 12,000 of our devices to Intune in a week.

Our users don't notice it, which is probably a good thing. If you don't notice something interacting with your computer, that's good from a user perspective. When we deploy stuff through Intune, it's silent. We recently deployed a bunch of potentially impactful settings to our users and tried to align devices with Microsoft's best practices. Nobody noticed.

What needs improvement?

Sometimes the syncing is inconsistent. I'm confident that the devices are checking in every eight hours, but sometimes the devices aren't picking up the settings as quickly as I would expect. Some features haven't been updated in a while, and Microsoft doesn't seem interested in developing them. Unless you talk to an engineer, you don't know whether there will be an update.

There are communication issues, so you might start working with a feature without knowing if it will be deprecated six months from now. Some reporting areas still need development. For example, I noticed that the reporting for driver updates is still confusing. 

For how long have I used the solution?

We have been using Microsoft Teams since the middle of 2022 when we started rolling it out to our Windows devices.

What do I think about the stability of the solution?

Microsoft Intune has been very stable. There has been only one incident with an outage on the Microsoft side, but it is rare to have significant outages.

What do I think about the scalability of the solution?

Microsoft Intune is a scalable platform with room for growth. Over the past year, it has significantly developed, with onboarding Mac OS devices now an option. Microsoft has put effort into making Intune manage macOS effectively, surpassing some other providers.

How are customer service and support?

I rate Microsoft support eight out of 10. Microsoft Intune's customer service is generally efficient. When a support ticket is submitted, it directly reaches someone with Intune support expertise, unlike other Microsoft products where assistance may be delayed. Elevation to the right person is swift, though I haven't needed to submit many tickets because Intune functions well.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used SCCM and a device management platform called Remedy in tandem. We switched to unify our mobile device management under one platform and eliminate internal servers. Intune functioned as that single pane of glass for us. Additionally, Intune is more functional and user-friendly than SCCM or Remedy, making it an obvious choice.

How was the initial setup?

The ease of setup depends on your scenario because there are many ways to deploy Intune. Our setup was straightforward because our devices were already in Active Directory, so we could add them using a GPO. After that, we had to do some fine-tuning. We first onboarded our mobile devices and moved our Windows devices to it once the Windows management side matured a little. It took about a week to deploy the solution.

What about the implementation team?

We did not engage a reseller or consultant for our migration. The migration was handled internally without external help.

What was our ROI?

I can't speak to specific ROI numbers, but there is a noticeable reduction in man-hours spent on support and troubleshooting. Applications are deployed through Intune, and we see fewer tickets for common issues because we can resolve them through the solution.

What's my experience with pricing, setup cost, and licensing?

We did not incur additional setup costs for Intune, as it was already included in our E5 license.

Which other solutions did I evaluate?

We didn't evaluate other solutions; choosing Intune was obvious as the next step.

What other advice do I have?

I rate Microsoft Intune eight out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Satyam Gupta - PeerSpot reviewer
Technical Support Executive at DigitalTrack Solutions Pvt Ltd
Real User
Top 5
May 30, 2026
Centralized endpoint policies have streamlined security management and reduce manual workloads
Pros and Cons
  • "We are getting good compliance and we are able to save time, with workload reduction between 40 to 60 percent, and we are also getting very good security, which represent significant time-saving and money-saving aspects for the organization."

    What is our primary use case?

    My main use case for Microsoft Intune is to enforce endpoint security policies, manage device compliances, and deploy applications across Windows, Android, or iOS devices.

    We use Microsoft Intune to automatically onboard corporate laptops through Autopilot, enforce BitLocker encryptions, and deploy security baselines while controlling access to corporate resources using compliance policies.

    How has it helped my organization?

    Microsoft Intune positively impacts our organization processes by providing standardized device management, improving endpoint security, and reducing manual workloads. This provides centralized visibility into device health, compliance status, and security postures, making it very easy to manage and secure endpoints.

    We are getting good compliance and we are able to save time, with workload reduction between 40 to 60 percent. We are also getting very good security. These represent significant time-saving and money-saving aspects for the organization.

    What is most valuable?

    The best features Microsoft Intune offers include its ability to combine endpoint management, compliance enforcement, and security control within a single cloud-native platform.

    Combining endpoint management, compliance enforcement, and security controls in one platform has helped me day-to-day by simplifying daily operations because having everything managed from a centralized platform makes it easier. For example, if a device becomes non-compliant due to disabled encryption or missing critical updates, Microsoft Intune can immediately detect it and apply the appropriate policy, restricting access to corporate resources through conditional access. This is very useful.

    What needs improvement?

    Apart from the initial setup that requires expertise to implement and fine-tune it, which could be simplified, everything is very seamless and has stable features.

    For how long have I used the solution?

    I have been working in my current field for almost two years.

    What other advice do I have?

    Microsoft Intune's AI capabilities support governance and security by helping to identify non-compliant devices and security gaps. The recommendations are very useful and also improve security postures.

    It is a very reliable solution and provides very accurate outcomes.

    My advice would be for anyone considering Microsoft Intune to go for this solution. Additionally, my advice would be to start with clear endpoint management and security planning before deployments and take advantage of each feature. I would rate this product overall as a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: May 30, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer1572123 - PeerSpot reviewer
    Programmer at a insurance company with 1,001-5,000 employees
    Real User
    Top 5
    Aug 3, 2025
    Enables efficient remote laptop setup and management
    Pros and Cons
    • "Without Microsoft Intune, it would be extremely challenging, if not impossible, for a large company to send out computers to users and have them set up and ready to use right out of the box in a remote location."
    • "There are some cases where features of Microsoft Intune have changed, and sometimes it's tricky to find the answer."

    What is our primary use case?

    Our main use case for Microsoft Intune is for laptops in remote situations where the client is remote and not where we are locally, as well as when the end user is not at the home office. When they get a new computer, they open it up out of the box and then it connects to the internet and it will automatically set up their username to the brand new computer. It'll download apps, it'll set up security policies, it'll connect, program in the company Wi-Fi, the network settings, mapping drives. This enables automated remote setup and management of the computer.

    We provide IT support through a managed service provider (MSP) model, offering both hourly work and contracted managed services. 

    How has it helped my organization?

    Once the initial setup is complete, which involves running PowerShell commands, programming, and testing, the product becomes very user-friendly for end users, particularly for Level 1 tech support staff. After Level 3 network engineers have configured everything, it becomes easy for frontline support personnel to manage the computers effectively. This system allows a Level 1 technician to address various needs without having to remote into the end user's computer. For instance, if a user requires a new printer, the technician can simply deploy the printer driver remotely. If access to certain resources is needed, that can also be pushed out without direct interaction. Additionally, the capability to remotely apply or remove settings is crucial. If a machine is lost or confiscated, technicians can lock it down or even wipe the data remotely. In the event of an operating system failure, they can instruct the computer to reinstall the system from a distance.

    In this way, once properly set up, Microsoft Intune significantly alleviates the headaches and hassles faced by Level 1 tech support staff when addressing end user issues. The system is not only designed for setting up computers but also for maintaining them and assisting in troubleshooting. Without Microsoft Intune, it would be extremely challenging, if not impossible, for a large company to send out computers to users and have them set up and ready to use right out of the box in a remote location. If a vendor needs to ship a brand new computer to a user whose previous computer has broken, the process becomes much simpler. The user doesn’t need to be on the phone for setup; the computer connects to Microsoft servers remotely and sets itself up automatically.

    Our client has around 300 machines, and initially, their goal was to complete the setup of one or two machines each week. However, after implementing Intune for them, they have been able to set up and install approximately 30 machines per week. This has significantly exceeded their expectations, allowing them to accomplish far more than they initially planned.

    What is most valuable?

    The best feature of Microsoft Intune is that since it's working with Microsoft servers and the Microsoft operating system, it's tightly integrated. There's a lot of documentation and resources for training. It's the first step to remote managing a Windows-based laptop or machine that you want to use out of the box. Even if you use a third party, they're still built on Microsoft services.

    What needs improvement?

    There are some cases where features of Microsoft Intune have changed, and sometimes it's tricky to find the answer. It's such a mass amount of information that searching for the solution to why something isn't working as expected is sometimes tricky or daunting. That's where the AI searches with ChatGPT and CoPilots come in because those AIs are helping us search a vast amount of data all at once. We can type in our question and formulate it to get the steps to the problem, the answer, and then verify it or write a script. We're leveraging AI to search the vast amount of old solutions, new solutions, and potential solutions all at once.

    For how long have I used the solution?

    We've been learning Microsoft Intune for a year and a half and have just started to use it.

    How are customer service and support?

    We haven't used their support. The documentation has been pretty good so far. It has allowed us to meet our clients' needs and deadlines and remotely manage, install their software, remove software, and ensure compliance.

    How would you rate customer service and support?

    How was the initial setup?

    When it comes to the IT department, regardless of individual skill levels, setting up and using these systems requires dedication. It's not something one can merely "hack" their way through; you need to start from the basics and understand the complexities involved. This isn't necessarily Microsoft's fault; rather, it's a reflection of the intricate problems and challenges that Intune addresses.

    Intune is designed to handle complex issues, and Microsoft has made it as user-friendly as possible given the many options and components involved. It interacts with various parts of the computer, including group policies, on-premises servers, hybrid systems, and cloud-based solutions like Azure. With such a wide range of capabilities, it's not something you can simply learn by watching a single YouTube video. To effectively use Intune, you need to read and study the material. In summary, it requires a highly skilled individual to properly implement and manage this technology.

    The deployment model is what's called a hybrid join with Microsoft Intune. The client has an on-premise server and an off-premise Azure cloud server. Because some of their software is still local and the way they have their network set up, we have to do it as a hybrid, which is one of the more complicated ways to do it, but we've been able to get it done. That's considered a temporary solution by Microsoft. Once you get it all working, there are some changes that you make where it's no longer hybrid.

    What other advice do I have?

    We've just started taking a look at CoPilot in Microsoft Intune. We use a combination of ChatGPT and CoPilot to get answers and help write scripts quicker or to search for problems quicker. 

    I would recommend Microsoft Intune to others because it's the industry standard for doing what it does. There's not really another option.

    I would rate Microsoft Intune an eight out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Security and Infrastructure - IT Specialist at a tech vendor with 201-500 employees
    Real User
    Top 20
    Jul 26, 2025
    Makes device management easy with remote wipe and app supersedence features
    Pros and Cons
    • "Since implementing this solution, our company has grown substantially, and our talent pool has significantly expanded."
    • "What frustrates me the most is just waiting and tapping my fingers, uncertain about whether my changes will take effect."

    What is our primary use case?

    We use Microsoft Intune for managing devices. We deploy our devices to users using Microsoft Intune Autopilot, which enables us to set up the device for the user and then ship it to them. When they log in, everything is there for them, including all the applications they need. We push applications through Microsoft Intune; for example, we install Zoom through it. 

    We do not allow users to install their own apps. We use AppLocker, which prevents users from installing their apps. We can use remediation scripts. One script uninstalls Google Chrome if someone installs it because it hasn't been set up in AppLocker yet. If it were, AppLocker would prevent the user from installing Google Chrome. We use Microsoft Edge because it's easier to manage using Microsoft Intune and Microsoft Endpoint Manager. We can prevent users from installing extensions, which is beneficial because password and session token theft often occurs through malicious extensions. We can have a whitelist of extensions that users can install or push an extension to be installed using Microsoft Endpoint Manager. I'm using Microsoft Endpoint Manager and Microsoft Intune interchangeably here because they're practically the same product.

    What is most valuable?

    The best feature in Microsoft Intune is the ability to wipe a device if it gets lost or stolen. Even if the device goes offline, if you send the command to wipe the device and it appears online, you can still wipe it. If the device breaks or ruins the storage, it doesn't matter because the goal is to ensure they don't have the data. You can also keep the device locked to your tenant if desired. If someone steals the device and tries to install Windows again, it will display 'Welcome to X company' and they cannot proceed past that point.

    Another notable feature of Microsoft Intune is application supersedence. For example, if we were using Microsoft Paint and we don't want it on the device but want another paint program, we can specify that Microsoft Paint will be superseded by this new application. It finds the application on the device, uninstalls it, and then installs the new application, providing two actions for the price of one.

    Regarding the Enterprise Application Management feature for app discovery, deployment, and automatic updating, we utilize that functionality. We use advanced endpoint analytics with Microsoft Intune. Only one of the global admins needs the license, and the rest of the admins can manage without individual licenses.

    What needs improvement?

    I’m not sure if Microsoft can do anything to improve this situation. The most frustrating part for me is when we make changes to a device, particularly with our virtual machine setups and test users. These test users need an intern license, so we usually provide them with what the other users have, which is a business premium license—it's the best value for our needs. When we push an application, it’s usually manageable. However, when it comes to configuration changes, the waiting game can be tedious. Sometimes the change takes effect in just two minutes, but other times it can take up to two hours. It’s difficult to be patient while waiting to see if the change works. We could try restarting the Intune management service to prompt it to check for updates, but that’s hit or miss too. I really don’t know how the changes are pushed to devices—whether our changes go into a larger queue with others or not. What frustrates me the most is just waiting and tapping my fingers, uncertain about whether my changes will take effect. I honestly don’t know how they could improve this process, as I’m not familiar with the inner workings. But this delay is the most annoying part for me.

    Sometimes, the menu system isn't very user-friendly. You'll find yourself digging through various sections, and the changes to the menu can be frustrating. For example, when you ask Copilot, "Where is this?" it might respond with a sequence of steps to follow, saying you need to go here, here, and then there. However, either Copilot is misunderstanding the situation, or the option has been moved, as it might no longer be where it used to be or it could have a different name. This is something that seems to change frequently. Microsoft tends to update things consistently; they do it with Windows and other products as well.

    The most important thing is to stay patient while waiting for these changes to take effect. Additionally, not only do we need to wait for the changes, but we also need access to logs that detail what has changed. It's frustrating when you see the changes happening on the device, and maybe they fail, but then it takes twenty minutes to an hour for that information to be reflected in Intune. This delay hinders your ability to troubleshoot effectively. From Intune's perspective, while I can check the event logs to see why an application might not have installed, I'm more concerned about understanding why Intune itself failed. So, the two main issues are the time it takes for changes to be implemented and the time it takes to report on the effectiveness of those changes.

    For how long have I used the solution?

    I have been using Microsoft Intune for approximately five years now.

    What do I think about the stability of the solution?

    There has only ever been one issue with Microsoft Intune, which they fixed quickly in less than a day. That issue concerned displaying incorrect access rights to users. It did not disrupt operations significantly; we simply couldn't test anything for a while.

    What do I think about the scalability of the solution?

    It's a very scalable solution. You can have thousands of devices connected if you want. It allows you to manage numerous aspects effectively. This system has greatly benefited my company, as we were previously reliant on an inadequate VPN for connecting to our network infrastructure. Now, we have the flexibility to hire employees from places like Arizona and Washington, which wasn’t possible before due to the need for onsite presence. Using Intune has enabled our workforce to operate remotely. Since implementing this solution, our company has grown substantially, and our talent pool has significantly expanded. Although we only hire within the United States, we now have the ability to recruit from virtually anywhere in the country.

    Our company has approximately 100 users working with Microsoft Intune, with a more complex setup due to our structure of five separate companies.

    How are customer service and support?

    We contact our cloud service provider first, who escalates us to level two tech support if needed. Microsoft support can be very inconsistent, warranting a rating of seven out of ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    My last use of SCCM was about eight years ago. Microsoft Intune's interface is superior; SCCM appeared outdated at that time. While I cannot extensively comment on SCCM due to dated experience, Microsoft Intune remains a strong product despite its regularly changing interface.

    How was the initial setup?

    Our deployment is entirely in the cloud. We used to operate on-premises, but I migrated everyone to use Entra ID instead of Active Directory on-site. I had to accomplish this while everyone was working remotely, which made the process more challenging since using Entra Connect or AD Connect was not feasible for many users. Currently, everyone is fully in the cloud. We do have an office, but people are rarely there. They only come in for meetings and such; most of the time, they are working remotely.

    The deployment of Microsoft Intune is relatively straightforward to set up. It's more straightforward than SCCM, though SCCM lacks certain features that Microsoft Intune has, and vice versa. For beginners, completing Microsoft SC-900 provides a foundation, which is more oriented towards Entra. However, MS-900 might be more suitable as it focuses on the admin center.

    For new companies implementing Microsoft Intune, setup can be quick with experienced personnel. Transitioning from on-premises to a hybrid solution depends on the number of users. It's crucial to ensure proper ID transfer and appropriate Entra licenses, particularly for write-back functionality. Without write-back enabled, users changing passwords outside the office might end up with two different passwords.

    One essential step is onboarding computers to Microsoft Autopilot. A script pushed through Microsoft Intune can accomplish this, though it becomes more complex without automatic enrollment settings. Autopilot facilitates device building and shipping, ensuring everything is set up when users log in. For organizations with small footprints using Microsoft Office and minimal apps such as Zoom and SharePoint, the process is streamlined. When moving to the cloud, consideration must be given to migrating SharePoint from on-premises, for which Microsoft provides migration tools.

    Maintenance involves running reports and managing stale devices. Setting up automatic removal of inactive devices helps maintain a healthy Microsoft Defender secure score. When reassigning devices, running an offboarding script ensures proper device management in Microsoft Defender.

    What was our ROI?

    Regarding return on investment, Microsoft Intune's value becomes apparent when comparing it to licensing costs of other management tools. Since it comes bundled with Microsoft Business Premium, it serves as a powerful tool that proved more valuable than initially anticipated. The overall ROI is positive, and the solution effectively meets our needs. Additionally, we can now deploy Global Secure Access, a VPN solution that protects remote workers and filters internet traffic, adding further value.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of Microsoft Intune rates around four or five out of ten. The cost structure varies based on requirements. We utilize licensing bundles such as Microsoft 365 Business Premium, which includes the Microsoft Intune license and provides good value. Microsoft Intune alone costs approximately $6 monthly, but considering its device management capabilities, application installation features, and Microsoft Autopilot deployment functionality, the price is reasonable.

    What other advice do I have?

    The user experience has been good. There is some crossover with Microsoft Entra ID. You can access groups and users from Microsoft Endpoint Manager when onboarding a device. This can be set up using Microsoft Endpoint Manager. If someone receives a new device, they can sign in for work purposes, and if you are familiar with Microsoft Windows, they will have the option to choose whether the device is for home or work use. Once we see the device in Microsoft Endpoint Manager, we can begin assigning profiles and encrypting the drive, making it easier for us to remain compliant. We utilize the CIS framework for compliance, which provides guidelines on tasks such as drive encryption and ensuring all settings are appropriately configured.

    Additionally, we implement conditional access policies. For instance, if someone is outside the United States, we can require them to re-authenticate using Microsoft Authenticator for security verification. This measure ensures that if an unauthorized person managed to steal someone’s MFA token and attempted to sign in from outside the country, they would be prompted to complete another MFA session, which adds an extra layer of protection. Furthermore, we can restrict actions on mobile devices. For example, we can prevent users from copying and pasting content from Word documents into applications like Apple Notes. This feature is particularly useful for maintaining security.

    If you are a Microsoft shop, these processes streamline operations significantly. However, for larger enterprises, costs may escalate. In such cases, it would be necessary to contact Microsoft to establish a suitable arrangement, similar to agreements made with Microsoft Azure for their resources. For small to medium-sized businesses, getting set up with these systems is straightforward and can assist in achieving compliance. It's important to note that this information pertains to Microsoft Purview and is distinct from Intune, which I will not discuss further.

    We do use Copilot, but we have it turned off for email due to a current exploit. There are hidden Copilot commands that can pull data from sources a user might have access to and then email it to someone else, which is why it's disabled for mail. We only have a handful of licenses, and they are primarily for people who have limited time during the day and receive a lot of emails. It's a time-saving feature for them. Sometimes, they use it to write scripts quickly, like in PowerShell, which I then review to understand what it does. You can trust it, but you should always verify its output. Copilot is also helpful for creating a basic outline for documents, such as policies, where you can simply fill in the blanks. However, the pricing is not great. Additionally, you are locked into a one-year subscription with no month-to-month option. The cost is around $360 a year per person, which adds up quickly, so you have to be sure the person really wants it. Consider purchasing one license first to let someone try it out. If they find it beneficial, they can keep it, and we can buy additional licenses for others who express interest. Currently, we have very limited licenses due to the high cost. If they were half the price, I believe everyone would have access to it.

    For those implementing Microsoft Intune, if you plan to have remote workers, consider whether you want to provide them with actual physical devices or if you can offer cloud PCs instead. Cloud PCs can be managed through Intune, and anyone with access to a Chrome-based web browser can use a desktop from anywhere with an internet connection. This approach also helps you avoid issues with retrieving physical devices from users, as they are not legally obligated to return them, potentially leading to a loss of significant investment.

    Additionally, there are compliance issues to consider when providing devices. For instance, if you give a physical device to a contractor, they may be legally considered your employee under laws in certain states, such as California. Therefore, think carefully about your deployment strategy. Decide whether you'll be using physical devices, which may require more effort to manage, or cloud PCs, which might save you headaches in the long run. You also need to be proficient in PowerShell, as you may have to write remediation scripts. If you're not comfortable with PowerShell and prefer a simpler solution, be aware that there may not be many alternatives. This also aligns well with Microsoft Windows.

    If you prefer to use Apple products, keep in mind that you can't just purchase a MacBook from a store. You'll need an Apple business account to obtain a certificate required for managing the device through Microsoft Intune. This rule applies to iPhones and iPads as well. In contrast, with Android devices, you don’t have these management restrictions. So, before making any decisions, consider your deployment strategy and the existing device ecosystem you have in place. I'm not familiar with using SCCM or other management tools, but be sure that with Microsoft Intune, simply buying a MacBook will not allow you to manage it without following the necessary procedures.

    I would rate Microsoft Intune overall as an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Systems Administratorcyber Security Administrator at a healthcare company with 1,001-5,000 employees
    Real User
    Top 20
    May 5, 2025
    Access control integration boosts policy customization and improves enterprise management
    Pros and Cons
    • "The security posture is very good. It's very customizable."
    • "Overall, my user experience with Microsoft Intune has been great."
    • "Microsoft Intune has potential for improvement; I would like to see a lot more customization in the reporting tools."

    What is our primary use case?

    I use the solution across my full enterprise. That means for me roughly 4,000 devices, with 2,000 being desktops, 2,000 being laptops, and then maybe another 2,000 mobile devices.

    What is most valuable?

    The most valuable feature I have found is the access control. It integrates with Endpoint Manager. The reason for that is that it has allowed me to customize my organization's policies.

    The security posture is very good. It's very customizable. 

    Overall, my user experience with Microsoft Intune has been great. It's offered a very smooth transition and I'm very positive on the product.

    I am just starting with Microsoft Security Copilot. My experience with Copilot, and Microsoft Intune Copilot in general, has been incredibly positive as it's a skill multiplier for daily operations.

    It's an absolutely critical application that I use every day. 

    Intune helps with app discovery. It's a game changer as it provides so much overall visibility.

    I have analytics available. It's a wonderful tool, and I love the amount of data it's able to extract. 

    Intune is reducing our attack surface and improving our security posture.

    What needs improvement?

    Microsoft Intune has potential for improvement; I would like to see a lot more customization in the reporting tools.

    For how long have I used the solution?

    I have been using the solution for four years.

    What do I think about the stability of the solution?

    My assessment of stability and reliability is that the uptime is fantastic, and I haven't had any issues.

    What do I think about the scalability of the solution?

    Compared to my previous solution, it's incredibly easy, and it's scaled to the entire organization. Within a month, I had gone from zero to full deployment.

    How are customer service and support?

    My experience with customer support or technical support is that they have been nothing but excellent.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Previously, I was using IBM to address the same issues. I made the switch since it was both more cost-efficient and Microsoft is best in breed.

    How was the initial setup?

    The deployment was incredibly easy, and it's scaled to the entire organization; within a month, I had gone from zero to full deployment.

    What was our ROI?

    Intune has been helping us reduce the cost of devices per user and offers trusted effectiveness for maintaining the accuracy of those devices.

    I don't have specific ROI data points. 

    What's my experience with pricing, setup cost, and licensing?

    The licensing has been fantastic and the support we've received from Microsoft has been impressive.

    Which other solutions did I evaluate?

    I wasn't involved in the RFP process. 

    What other advice do I have?

    I do not use PKI yet; it is on our task list, and it's on the list to get done, but it hasn't been completed. The reason it's on the list to get done is that I want everything in the same platform, just so everything integrates and supports each other.

    My assessment of endpoint analytics is that it's a wonderful tool, and I love the amount of data it's able to extract; I can provide examples of how these features work.

    On a scale of one to ten, I rate Microsoft Intune a ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Farasat Hassan - PeerSpot reviewer
    IT Admin at a financial services firm with 10,001+ employees
    Real User
    Top 20
    Aug 15, 2024
    It helps consolidate our endpoints, provide flexibility for users, and save costs
    Pros and Cons
    • "Microsoft integrated BitLocker and Active Directory into Intune, simplifying management."
    • "There's a significant discrepancy in Intune pricing between tenants."

    What is our primary use case?

    Previously, when dealing with COVID-related issues, we had to bring laptops to the office network to resolve problems physically. However, with the introduction of Intune and autopilot, we can now build and manage machines remotely. Intune allows us to upload our operating system and create a tenant, enabling users to enroll and build machines anywhere with an internet connection. This eliminates the need for physical device management and reduces downtime. Additionally, Intune simplifies application management by providing a centralized platform for accessing and deploying applications without requiring multiple servers. Overall, Intune offers significant improvements in device management, flexibility, and efficiency compared to traditional methods.

    Currently, we operate Intuneas as a hybrid model. While devices are enrolled in cloud-based Intune, updates are still being deployed from our on-premises SCCM. A complete migration to the cloud will take time, especially for larger organizations with tens or even hundreds of thousands of machines. This transition is hindered by legacy applications that are incompatible with Intune. To facilitate a smooth migration, Microsoft must either enable the use of these legacy applications within Intune or provide equivalent cloud-based alternatives.

    How has it helped my organization?

    Historically, application management involved installing software on users' machines. However, many organizations now utilize software-as-a-service models that are accessible through web portals like Intune. We also employ App-V to virtualize legacy applications, allowing access to any physical or virtual machine. Our current methods include direct endpoint installation, SCCM deployment, and App-V server hosting applications. We introduced App-V as a virtual application platform to address challenges like developer environment inconsistencies and license costs. By centralizing applications and implementing a first-come, first-served licensing model, App-V reduces costs, improves accessibility, and simplifies management.

    Intune consolidates our endpoint and security management tools into a single, user-friendly platform. It seamlessly integrates existing on-premises policies, allowing for easy creation or upload. Organizations migrating to Intune or replacing on-premises Active Directory can effortlessly establish new policies. Unlike the complexities of on-premises management, Intune simplifies policy creation and implementation through a click-based interface, eliminating registry changes. Additionally, Intune's cloud-based architecture ensures consistent policy application across devices, avoiding the delays and potential bandwidth issues associated with on-premises servers. Microsoft's robust infrastructure provides reliable performance, making Intune an efficient and effective solution for managing endpoints and security.

    Intune users appreciate its flexibility compared to traditional on-premises Active Directory systems. For instance, with on-premises AD, policy implementation requires the user to be physically present in the office. In contrast, Intune enables remote policy management, as demonstrated by the scenario where a user's account is locked on an Intune-managed laptop. Even if the user cannot log in to the device, unlocking the account in Azure AD automatically unlocks it on the laptop, regardless of location. This significantly improved over previous methods involving complex workarounds like sharing local profile passwords. Intune's integration with Azure AD simplifies account management and provides seamless access for remote users.

    We manage multiple users who use Azure AD and Azure VDI machines but often prefer using the VDI machines over their laptops. To address this, we proactively contact users whose laptops haven't reported to Intune in 20-30 days, informing them of potential removal and providing additional notifications through tools like Nexting or SysTrack. We also send emails to users whose assigned machines are inactive, warning of removal if usage doesn't resume within 30 days. Additionally, we monitor machine downtime, login times, and compliance status while pushing necessary policies and updates. Our organization utilizes a hybrid model combining Intune for machine management and BitLocker encryption with SCCM for software updates due to the ongoing migration from on-premises to cloud-based solutions. While Intune enrollment and management are in place, we anticipate a full transition to Intune in the future.

    We are using Intune Suites Cloud PKI to assign certificates to users. Previously, we managed Microsoft certificates on a hosted server. This process was manual. However, Intune now automates certificate management. Once a machine connects to Intune and authenticates, the necessary certificates are pushed without manual intervention. VPN login requires both a user and device certificate for compliance. Intune offers certificate management from both Microsoft and third-party vendors. Due to cost considerations, we are transitioning to a different certificate provider within our organization.

    We have implemented Copilot in Microsoft Teams and Zoom to improve meeting efficiency significantly. Copilot automatically generates meeting minutes, including attendee lists, saving valuable time compared to manual creation. Additionally, it provides real-time meeting summaries, allowing latecomers to grasp discussed topics quickly. By automating these tasks, Copilot frees up approximately half an hour per meeting, enabling us to focus on more productive activities.

    For IT and security operations, our company has implemented Copilot by hosting all ChatGPT features on-premises. As a financial company, we cannot access external AI tools directly. Therefore, our system interacts with our server rather than the Internet, allowing us to utilize ChatGPT capabilities based on our specific business needs.

    Intune has significantly improved our device management process. Previously, we had to physically build machines on-site, requiring users to come to the office. Now, we can remotely push updates and assist users from anywhere, saving them time and eliminating the need for travel. Additionally, Intune's dashboard provides comprehensive insights into our device fleet, including compliance status, update failures, and application installations. This centralized view has increased our efficiency and proactivity in addressing issues compared to our previous reliance on SCCM reports.

    When enrolling personally owned devices, Intune applies organizational-level settings. This prevents downloads to local machines when using Office 365 applications or Teams. We can restrict downloads to specific containers that cannot be copied to other folders. Alternatively, we can limit application usage to on-premises or organizational machines. While our current setup allows Office 365 access on handheld devices, downloads and uploads are blocked. Intune offers this level of control, preventing data transfer to or from the device, regardless of whether it's personally owned or a company-issued app.

    We are upgrading our privilege management policies to mirror those already existing in our on-premises Active Directory. While we are not making substantive changes, Intune's endpoint privilege management offers significant improvements over our previous approach. By consolidating multiple policies into a few comprehensive ones, we can more effectively restrict user actions based on organizational hierarchy. This streamlined process eliminates the need for extensive group management in Active Directory and saves time overall.

    Once implemented, our policies will reduce the attack surface by restricting service access only to users possessing an infrastructure organization certificate, which we have obtained. Additionally, we will enforce IP-level restrictions, preventing access from personal devices or those outside our specified IP ranges. We can implement these restrictions at the IP, device, or certificate level.

    Intune has significantly reduced our costs. Previously, we managed multiple servers, but now we rely solely on a CCM server, which will be decommissioned soon. This eliminates the need for on-site server infrastructure, backup systems, dedicated staff, and extensive network support. With Intune, we can host the CCM server in a central location and avoid latency issues associated with multiple servers across different regions. Additionally, expanding to new offices no longer requires building additional data centers. Intune's cloud-based platform allows remote access from any location without needing on-premises infrastructure. As a result, many organizations, especially smaller ones, are adopting cloud-based solutions and eliminating the need for physical servers and laptops. Employees can leverage their own devices to access applications through Intune, further reducing costs and increasing flexibility.

    We can primarily manage security posture through Intune. However, due to pricing, we will likely use a third-party solution for device certificates. Interestingly, Microsoft seems to be introducing third-party vendor options within their portal. Ultimately, the security team will evaluate all options, including Intune, considering factors like policies, pros, cons, and pricing before deciding.

    Intune Suite's integration with Microsoft 365 and Microsoft Security provides robust capabilities for centrally managing both cloud and co-managed devices. Previously, managing Exchange, Active Directory, and applications required separate teams, but Intune has streamlined this process, enabling efficient management of all mailboxes across devices from a single platform. It's incredibly easy to manage, allowing for remote administration and policy creation. Unlike the previous process of manually creating and testing Group Policy updates, Intune simplifies policy creation and testing with just a few clicks. Additionally, Intune eliminates the challenges of server-based upgrades by providing centralized management and control.

    We are currently utilizing multiple security solutions, leading to a complex environment. Due to cost considerations, we are transitioning from Microsoft's device certificate to a solution from a different vendor. Additionally, we are integrating this new solution with Intune and have replaced Jamf to manage our MacBook fleet. This change eliminates Jamf license costs while allowing us to manage Mac devices through Intune centrally. Similar to our previous use of Jamf, we incurred costs in a previous company but have successfully eliminated them by consolidating management within Intune. Furthermore, we are exploring Microsoft's evolving Office 365 licensing options. The latest E5 license offers integrated phone capabilities, replacing the need for separate devices like Cisco or Avaya phones. This consolidation allows users to make domestic and international calls through Microsoft Teams directly.

    What is most valuable?

    Previously, we relied on third-party applications like PointSec for mobile device security before Microsoft introduced BitLocker. PointSec required complex management, including console login, authentication, and handshake processes. BitLocker offered a cost-effective solution, initially used independently of Intune. However, Microsoft integrated BitLocker and Active Directory into Intune, simplifying management. While our previous company used an outdated AD environment that was difficult to migrate, Intune's integration with AD FS eliminated these concerns. Intune now allows us to easily manage BitLocker, including remote device wiping, providing enhanced security and control over mobile devices.

    What needs improvement?

    We currently aren't building any data centers. Previously, we did, but now we're facing a tenant-related issue. When accessing a US-hosted Azure machine from India, latency is a problem regardless of whether we're using a data center, our own, or Intune. I believe Microsoft could offer a feature to create a nearby tenant, allowing users in India to create one there rather than dealing with multiple tenants, policies, and groups for different regions. For example, if a company with a US-based data center expands to India, they currently need to create a separate Indian tenant to provide machines for Indian employees. Instead, Microsoft could potentially offer a peer-to-peer connectivity solution or similar approach, enabling access to US-based machines from India without requiring additional tenants or administrative overhead. This would simplify management, as administrators wouldn't need to handle separate tenants for each region.

    There's a significant discrepancy in Intune pricing between tenants. Previously, my company assigned Canadian machines to Indian users due to a lack of Indian tenant options. This resulted in exorbitant costs compared to the drastically lower pricing for identical configurations in India. Given that Microsoft can determine the user's location based on IP address, they could potentially adjust pricing accordingly. For instance, a Canadian machine accessed from India could be charged a reduced rate similar to locally provisioned machines. This would align pricing with the actual location of use rather than solely relying on the tenant or data center.

    Intune's lack of support for legacy applications is hindering rapid migration to Intune or Microsoft platforms. Organizations are reluctant to switch due to Intune's limitations and potential cost implications compared to alternatives like AWS or Google Cloud. While many organizations are using Intune and registering applications, they often rely on other cloud providers for specific services like storage or SQL. Given the extensive use and reliability of platforms like AWS over the past decade, Microsoft should consider offering competitive pricing and comparable services to encourage wider adoption of Intune.

    For how long have I used the solution?

    I have been using Microsoft Intune for two and a half years.

    What do I think about the stability of the solution?

    I have never experienced any stability issues with Intune. If something occurs, it is resolved in a fraction of a second. I would rate the stability ten out of ten.

    What do I think about the scalability of the solution?

    I would rate the scalability of Intune nine out of ten. The scalability is dependent on the configuration. To increase usage, we have to pay more.

    How are customer service and support?

    The technical support is good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Previously, we relied on SCCM and on-premises Active Directory, which was challenging due to manual account management and group assignments. Intune has significantly improved this by allowing us to implement policies upon user creation and automatic replication. Active Directory management was often problematic, with group removals due to scripts and inconsistent replication across different locations. Intune's cloud-based nature ensures faster updates and accessibility regardless of location or VPN status. This flexibility benefits both IT staff and end users. Intune's integration with Windows and potential for future enhancements, such as system health monitoring, make it the leading choice over third-party solutions.

    How was the initial setup?

    Intune deployment is straightforward. Even end users can perform it. All organizational laptops have a built-in operating system. Resetting a laptop returns it to factory settings, automatically installing the enterprise OS, ready for Intune enrollment. The only requirement is internet connectivity. Enrollment is simple: log in to the laptop, press Shift, restart, and the device enters enrollment mode.

    Deployment time varies based on the operating system's complexity. At my previous company, we deployed twelve applications within the OS. Currently, I manage the deployment of over forty applications through autopilot. The exact duration depends on the specific OS configuration, including the number of applications and other bundled components. Generally, it can take anywhere from two to three and a half hours to complete the process.

    What's my experience with pricing, setup cost, and licensing?

    Microsoft's pay-as-you-go pricing model for Intune could benefit from a Google-like approach. While Microsoft charges for actual usage, it lacks discount options. In contrast, Google offers discounts based on usage duration, rewarding customers for extended service utilization. AWS also provides organizational-level discounts, demonstrating alternative pricing strategies. Intune's current focus on cost savings through service adoption is effective, but incorporating usage-based discounts could enhance its competitiveness and attract more customers. While the current pricing is market-competitive, additional discounts could position Intune as a more compelling option.

    What other advice do I have?

    I would rate Microsoft Intune ten out of ten. Previously, we had to physically go to the office to build machines. Now, we no longer need to build them on-site, as Intune allows us to manage many aspects of devices remotely and easily without a VPN connection. It's truly a SaaS solution.

    If someone is interested in using Intune, I would need to assess their enterprise's size, work location, and specific needs to determine if it's suitable. Intune is particularly beneficial for remote workforces and larger organizations due to its ease of management and scalability. I would evaluate their department structure, policies, applications, and existing infrastructure to provide tailored recommendations. Intune's cloud-based nature eliminates the need for on-premises infrastructure, reducing complexity and administrative overhead. Additionally, it consolidates management responsibilities, allowing for efficient oversight of various IT functions. Compared to traditional IT setups, Intune simplifies email management with cloud-based solutions like Office 365, offering increased storage, accessibility, and device compatibility.

    Approximately 60 of our 100 employees utilize Intune, and the platform manages 100 percent of their devices.

    Intune generally requires minimal maintenance, but this depends entirely on the complexity of our created policies, including allowed and restricted settings. While Microsoft offers guidance to minimize management efforts, adhering strictly to their recommendations is essential for full automation. Customizations may necessitate ongoing maintenance. Ultimately, closely following Microsoft's guidelines will optimize Intune management and minimize our workload.

    We also use Bing Copilot, but I find Bing AI less effective than ChatGPT. Bing frequently requires multiple prompts before providing a response, whereas ChatGPT typically delivers accurate answers more directly. For instance, when asking for a Microsoft Outlook KB article, Bing requested clarification on the term "KB," while ChatGPT promptly provided relevant KB articles. It seems Microsoft's AI could benefit from further development to match ChatGPT's capabilities.

    I recommend Microsoft Intune for larger organizations. Legacy applications may not be compatible with Intune, preventing their use. Smaller companies might consider Software as a Service solution like Office 365 instead, offering email, PowerPoint, and other tools without requiring Intune. Enrolling devices in Intune for small businesses might not be justified due to the costs and IT management overhead. However, for organizations with 1,000 or more employees, Intune can provide enhanced security and device management. If Intune pricing is scalable based on the number of enrolled devices, smaller companies could evaluate it. Ultimately, the decision depends on the organization's size, IT resources, and security needs.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.