The purpose of using Microsoft Intune is to provide security for all company devices and company data.
As an Intune Consultant, the role involves suggesting ideas for implementation.
The purpose of using Microsoft Intune is to provide security for all company devices and company data.
As an Intune Consultant, the role involves suggesting ideas for implementation.
I use Microsoft's Copilot in Microsoft Intune. It helps tremendously. I work as an architect and consultant in Microsoft Intune, and it assists majorly in developing new scripts and customizations which do not have built-in templates in Microsoft Intune. We can customize our requirements using Copilot, which helps significantly in that aspect.
The Enterprise Application Management feature in Microsoft Intune helps tremendously with deployment because one of the strongest points is pushing out customized applications as Win32. Even without a package, deployment can be done as a PowerShell script. Customization in deploying applications can be managed using application protection policies, which provide control of company data even on personal machines, such as iOS or Android, without interrupting privacy.
I particularly appreciate the features for Windows machines because it's a Microsoft product that specializes in developing Windows machines and can manage them effectively. Any data on machines or devices can be monitored professionally and completely while securing the data. The security implementation has been developed brilliantly over the past few years, and its cost is very efficient compared to other MDM tools.
Microsoft Intune is very easy to understand for anyone.
Certificate management within Microsoft Intune's Suite is still under development. It's not very reliable compared to other certificate tools, though it has made good progress within a couple of years. Microsoft Intune could provide more features in certificate management, delivery optimization, patching, and technical support. These areas have scope for significant improvement.
It has been around four years.
Nothing is perfect. Microsoft Intune deserves a rating of nine out of ten. It performs very well with no downtime at all.
Microsoft Intune is scalable but still has scope for improvement.
Our clients are large enterprise businesses. In my organization, there are many users specializing in Microsoft Intune, but in my project, I'm the main one. Overall, the company supports nearly 1,000 clients, but I'm not exactly sure how many Intune administrators we have. However, I can say there are quite a few.
The technical support of Microsoft Intune rates at seven out of ten. Having worked for Microsoft support previously, providing answers to organizational tickets, the experience was good. Many employees had great knowledge from their experience working at Microsoft. However, due to workload, organizations sometimes find it difficult to get timely answers when they reach out to Microsoft support.
We have a hybrid deployment method for Microsoft Intune. One client was using SCCM previously, and we migrated all policies and related configurations to Microsoft Intune. We have already had machines set up, so all the previous machines are in a co-managed or hybrid state, you could say. But right now, we are enrolling all our machines with Autopilot, meaning they are all cloud machines.
It doesn't require much maintenance. If you have a subscription, your license takes care of everything. You don’t need to worry about updates or anything else; it updates automatically without user intervention or admin approval
It saves time, money, and resources. When there was a local liaison, managing everything was a significant challenge. Without utilizing any MDM tools, handling all the organizational units (OUs) was quite difficult. It has become much easier. I would estimate it to be around 60% to 70% easier. It is very beneficial. In terms of reliability and ease of use, it excels.
Microsoft Intune is very cost-efficient, which is a major reason for its rapid growth compared to other tools in the industry. Additionally, its ability to integrate configurations and collaborate with services like Copilot and recent offerings from Microsoft makes it stand out, allowing it to grow at a faster pace compared to other MDM tools.
Microsoft Intune is recommended for Windows management specifically. However, it's not recommended for managing iOS devices or Mac devices, as Apple products don't have many configurations within Microsoft Intune. Other MDM tools such as Jamf are superior for Apple products, though not as good for Windows, which is why organizations often use both tools together.
I would rate Microsoft Intune an eight out of ten.
Microsoft Intune was used by the organization that hired me. Microsoft Intune allows organizations to manage all devices. It is a cloud-based service that helps organizations manage and secure their devices such as laptops, smartphones, and iOS devices. We primarily used it for managing applications through mobile application management (MAM) and mobile device management (MDM). Device enrollment is another purpose of Microsoft Intune which automatically configures devices within the organization with their work accounts.
In the Microsoft Intune company portal, there is an option to develop and deploy applications that are trusted by the company.
Additional use cases include compliance, conditional access, and endpoint security. To summarize, the main purposes are MDM for laptops, mobiles, and iOS devices; MAM; device enrollment; app deployment; compliance and conditional access; and endpoint security. I had access to compliance and conditional access, endpoint security, device enrollment, MDM, and MAM. App deployment was not part of my responsibilities.
Microsoft Intune provides valuable functionality for locating lost devices. Through the Endpoint Management Admin Center within Microsoft Intune, we can find the last seen location of enrolled devices that may have been stolen or misplaced. This requires device numbers, serial numbers, usernames, or IMEI for mobile phones.
Another excellent feature is the ability to enroll devices and set compliance status. Notifications can be pushed from the Microsoft Intune Admin Center to users' portals, informing them when devices are not compliant and providing steps to follow company policies.
Microsoft Intune saves approximately 20% of time and resources through automated features that enable quick resolution and guided SOPs. It reduces troubleshooting and support time by 30-40%. The security compliance capabilities make it widely adopted across organizations. The user experience is robust, and the pricing model is budget-friendly. Its integration with Azure AD and Microsoft 365 applications adds significant value.
Microsoft Intune could be improved in several key areas. Policy and app deployment should be faster, as it currently takes between minutes to hours to apply, with an average of one hour. This could be enhanced by adding real-time sync or faster push intervals for critical changes. When users transition between devices, the process takes 45 minutes to one hour, which could be optimized.
The error reporting system needs improvement, particularly for automatic retry of failed installations. In the Microsoft Intune company portal, when application downloads fail, users must manually reinitiate the installation process. An automatic retry mechanism for failed installations would enhance the user experience.
I have been using Microsoft Intune since 2019.
Microsoft Intune demonstrates excellent stability with a rating of nine out of ten, providing a very stable experience.
In my role as an IT administrator, I have overseen Microsoft Intune implementation for approximately 10,000 users across multiple organizations. My previous organization had 7,000 plus users, and my current organization has between 3,000 to 4,000 users.
When comparing Microsoft Intune to alternatives such as Unified Endpoint Management solutions, VMware Workspace One, and Google Endpoint Management, each has distinct strengths. For Microsoft environments, Microsoft Intune rates five out of five, while Ivanti (formerly MobileIron) rates three out of five, and Google Endpoint Management rates two out of five.
For iOS environments, Microsoft Intune rates three out of five due to compatibility issues, MobileIron Ivanti rates four out of five, and Google Endpoint Management rates 3.5 out of five. Regarding user interface and ease of use, Microsoft Intune scores five out of five, Ivanti three out of five, and Google Endpoint Management four out of five.
In security and compliance, Microsoft Intune achieves five out of five, Ivanti four out of five, and Google Endpoint Management three out of five. For budget-friendliness, both Microsoft Intune and Google Endpoint Management rate five out of five, while Ivanti rates four out of five.
Microsoft Intune provides an excellent experience for both employees and IT administrators. While the user interface requires some initial guidance for new users, it is straightforward for IT administrators to navigate. The platform ensures device compliance effectively, earning a five out of five rating for user-friendliness.
Maintenance requirements for Microsoft Intune are minimal compared to on-premises applications such as SCCM or Active Directory Certificate Services. Required maintenance includes policy and app management, monitoring and troubleshooting, OS and app updates, and license and user management.
I recommend Microsoft Intune to other users and companies due to its password policies, seamless Microsoft system integration, multi-platform support (Windows, iOS, Android, macOS), simplified device enrollment management, cost-effectiveness, and smooth user experience. It represents a future-proof investment for companies.
Regarding Mobile Application Management, I have worked with MAM policies including conditional launch, PIN encryption, data encryption within apps, and copy-paste restrictions.
Overall rating: nine out of ten.
Our main use case for Microsoft Intune is for laptops in remote situations where the client is remote and not where we are locally, as well as when the end user is not at the home office. When they get a new computer, they open it up out of the box and then it connects to the internet and it will automatically set up their username to the brand new computer. It'll download apps, it'll set up security policies, it'll connect, program in the company Wi-Fi, the network settings, mapping drives. This enables automated remote setup and management of the computer.
We provide IT support through a managed service provider (MSP) model, offering both hourly work and contracted managed services.
Once the initial setup is complete, which involves running PowerShell commands, programming, and testing, the product becomes very user-friendly for end users, particularly for Level 1 tech support staff. After Level 3 network engineers have configured everything, it becomes easy for frontline support personnel to manage the computers effectively. This system allows a Level 1 technician to address various needs without having to remote into the end user's computer. For instance, if a user requires a new printer, the technician can simply deploy the printer driver remotely. If access to certain resources is needed, that can also be pushed out without direct interaction. Additionally, the capability to remotely apply or remove settings is crucial. If a machine is lost or confiscated, technicians can lock it down or even wipe the data remotely. In the event of an operating system failure, they can instruct the computer to reinstall the system from a distance.
In this way, once properly set up, Microsoft Intune significantly alleviates the headaches and hassles faced by Level 1 tech support staff when addressing end user issues. The system is not only designed for setting up computers but also for maintaining them and assisting in troubleshooting. Without Microsoft Intune, it would be extremely challenging, if not impossible, for a large company to send out computers to users and have them set up and ready to use right out of the box in a remote location. If a vendor needs to ship a brand new computer to a user whose previous computer has broken, the process becomes much simpler. The user doesn’t need to be on the phone for setup; the computer connects to Microsoft servers remotely and sets itself up automatically.
Our client has around 300 machines, and initially, their goal was to complete the setup of one or two machines each week. However, after implementing Intune for them, they have been able to set up and install approximately 30 machines per week. This has significantly exceeded their expectations, allowing them to accomplish far more than they initially planned.
The best feature of Microsoft Intune is that since it's working with Microsoft servers and the Microsoft operating system, it's tightly integrated. There's a lot of documentation and resources for training. It's the first step to remote managing a Windows-based laptop or machine that you want to use out of the box. Even if you use a third party, they're still built on Microsoft services.
There are some cases where features of Microsoft Intune have changed, and sometimes it's tricky to find the answer. It's such a mass amount of information that searching for the solution to why something isn't working as expected is sometimes tricky or daunting. That's where the AI searches with ChatGPT and CoPilots come in because those AIs are helping us search a vast amount of data all at once. We can type in our question and formulate it to get the steps to the problem, the answer, and then verify it or write a script. We're leveraging AI to search the vast amount of old solutions, new solutions, and potential solutions all at once.
We've been learning Microsoft Intune for a year and a half and have just started to use it.
We haven't used their support. The documentation has been pretty good so far. It has allowed us to meet our clients' needs and deadlines and remotely manage, install their software, remove software, and ensure compliance.
When it comes to the IT department, regardless of individual skill levels, setting up and using these systems requires dedication. It's not something one can merely "hack" their way through; you need to start from the basics and understand the complexities involved. This isn't necessarily Microsoft's fault; rather, it's a reflection of the intricate problems and challenges that Intune addresses.
Intune is designed to handle complex issues, and Microsoft has made it as user-friendly as possible given the many options and components involved. It interacts with various parts of the computer, including group policies, on-premises servers, hybrid systems, and cloud-based solutions like Azure. With such a wide range of capabilities, it's not something you can simply learn by watching a single YouTube video. To effectively use Intune, you need to read and study the material. In summary, it requires a highly skilled individual to properly implement and manage this technology.
The deployment model is what's called a hybrid join with Microsoft Intune. The client has an on-premise server and an off-premise Azure cloud server. Because some of their software is still local and the way they have their network set up, we have to do it as a hybrid, which is one of the more complicated ways to do it, but we've been able to get it done. That's considered a temporary solution by Microsoft. Once you get it all working, there are some changes that you make where it's no longer hybrid.
We've just started taking a look at CoPilot in Microsoft Intune. We use a combination of ChatGPT and CoPilot to get answers and help write scripts quicker or to search for problems quicker.
I would recommend Microsoft Intune to others because it's the industry standard for doing what it does. There's not really another option.
I would rate Microsoft Intune an eight out of ten.
We use Microsoft Intune for managing devices. We deploy our devices to users using Microsoft Intune Autopilot, which enables us to set up the device for the user and then ship it to them. When they log in, everything is there for them, including all the applications they need. We push applications through Microsoft Intune; for example, we install Zoom through it.
We do not allow users to install their own apps. We use AppLocker, which prevents users from installing their apps. We can use remediation scripts. One script uninstalls Google Chrome if someone installs it because it hasn't been set up in AppLocker yet. If it were, AppLocker would prevent the user from installing Google Chrome. We use Microsoft Edge because it's easier to manage using Microsoft Intune and Microsoft Endpoint Manager. We can prevent users from installing extensions, which is beneficial because password and session token theft often occurs through malicious extensions. We can have a whitelist of extensions that users can install or push an extension to be installed using Microsoft Endpoint Manager. I'm using Microsoft Endpoint Manager and Microsoft Intune interchangeably here because they're practically the same product.
The best feature in Microsoft Intune is the ability to wipe a device if it gets lost or stolen. Even if the device goes offline, if you send the command to wipe the device and it appears online, you can still wipe it. If the device breaks or ruins the storage, it doesn't matter because the goal is to ensure they don't have the data. You can also keep the device locked to your tenant if desired. If someone steals the device and tries to install Windows again, it will display 'Welcome to X company' and they cannot proceed past that point.
Another notable feature of Microsoft Intune is application supersedence. For example, if we were using Microsoft Paint and we don't want it on the device but want another paint program, we can specify that Microsoft Paint will be superseded by this new application. It finds the application on the device, uninstalls it, and then installs the new application, providing two actions for the price of one.
Regarding the Enterprise Application Management feature for app discovery, deployment, and automatic updating, we utilize that functionality. We use advanced endpoint analytics with Microsoft Intune. Only one of the global admins needs the license, and the rest of the admins can manage without individual licenses.
I’m not sure if Microsoft can do anything to improve this situation. The most frustrating part for me is when we make changes to a device, particularly with our virtual machine setups and test users. These test users need an intern license, so we usually provide them with what the other users have, which is a business premium license—it's the best value for our needs. When we push an application, it’s usually manageable. However, when it comes to configuration changes, the waiting game can be tedious. Sometimes the change takes effect in just two minutes, but other times it can take up to two hours. It’s difficult to be patient while waiting to see if the change works. We could try restarting the Intune management service to prompt it to check for updates, but that’s hit or miss too. I really don’t know how the changes are pushed to devices—whether our changes go into a larger queue with others or not. What frustrates me the most is just waiting and tapping my fingers, uncertain about whether my changes will take effect. I honestly don’t know how they could improve this process, as I’m not familiar with the inner workings. But this delay is the most annoying part for me.
Sometimes, the menu system isn't very user-friendly. You'll find yourself digging through various sections, and the changes to the menu can be frustrating. For example, when you ask Copilot, "Where is this?" it might respond with a sequence of steps to follow, saying you need to go here, here, and then there. However, either Copilot is misunderstanding the situation, or the option has been moved, as it might no longer be where it used to be or it could have a different name. This is something that seems to change frequently. Microsoft tends to update things consistently; they do it with Windows and other products as well.
The most important thing is to stay patient while waiting for these changes to take effect. Additionally, not only do we need to wait for the changes, but we also need access to logs that detail what has changed. It's frustrating when you see the changes happening on the device, and maybe they fail, but then it takes twenty minutes to an hour for that information to be reflected in Intune. This delay hinders your ability to troubleshoot effectively. From Intune's perspective, while I can check the event logs to see why an application might not have installed, I'm more concerned about understanding why Intune itself failed. So, the two main issues are the time it takes for changes to be implemented and the time it takes to report on the effectiveness of those changes.
I have been using Microsoft Intune for approximately five years now.
There has only ever been one issue with Microsoft Intune, which they fixed quickly in less than a day. That issue concerned displaying incorrect access rights to users. It did not disrupt operations significantly; we simply couldn't test anything for a while.
It's a very scalable solution. You can have thousands of devices connected if you want. It allows you to manage numerous aspects effectively. This system has greatly benefited my company, as we were previously reliant on an inadequate VPN for connecting to our network infrastructure. Now, we have the flexibility to hire employees from places like Arizona and Washington, which wasn’t possible before due to the need for onsite presence. Using Intune has enabled our workforce to operate remotely. Since implementing this solution, our company has grown substantially, and our talent pool has significantly expanded. Although we only hire within the United States, we now have the ability to recruit from virtually anywhere in the country.
Our company has approximately 100 users working with Microsoft Intune, with a more complex setup due to our structure of five separate companies.
We contact our cloud service provider first, who escalates us to level two tech support if needed. Microsoft support can be very inconsistent, warranting a rating of seven out of ten.
Neutral
My last use of SCCM was about eight years ago. Microsoft Intune's interface is superior; SCCM appeared outdated at that time. While I cannot extensively comment on SCCM due to dated experience, Microsoft Intune remains a strong product despite its regularly changing interface.
Our deployment is entirely in the cloud. We used to operate on-premises, but I migrated everyone to use Entra ID instead of Active Directory on-site. I had to accomplish this while everyone was working remotely, which made the process more challenging since using Entra Connect or AD Connect was not feasible for many users. Currently, everyone is fully in the cloud. We do have an office, but people are rarely there. They only come in for meetings and such; most of the time, they are working remotely.
The deployment of Microsoft Intune is relatively straightforward to set up. It's more straightforward than SCCM, though SCCM lacks certain features that Microsoft Intune has, and vice versa. For beginners, completing Microsoft SC-900 provides a foundation, which is more oriented towards Entra. However, MS-900 might be more suitable as it focuses on the admin center.
For new companies implementing Microsoft Intune, setup can be quick with experienced personnel. Transitioning from on-premises to a hybrid solution depends on the number of users. It's crucial to ensure proper ID transfer and appropriate Entra licenses, particularly for write-back functionality. Without write-back enabled, users changing passwords outside the office might end up with two different passwords.
One essential step is onboarding computers to Microsoft Autopilot. A script pushed through Microsoft Intune can accomplish this, though it becomes more complex without automatic enrollment settings. Autopilot facilitates device building and shipping, ensuring everything is set up when users log in. For organizations with small footprints using Microsoft Office and minimal apps such as Zoom and SharePoint, the process is streamlined. When moving to the cloud, consideration must be given to migrating SharePoint from on-premises, for which Microsoft provides migration tools.
Maintenance involves running reports and managing stale devices. Setting up automatic removal of inactive devices helps maintain a healthy Microsoft Defender secure score. When reassigning devices, running an offboarding script ensures proper device management in Microsoft Defender.
Regarding return on investment, Microsoft Intune's value becomes apparent when comparing it to licensing costs of other management tools. Since it comes bundled with Microsoft Business Premium, it serves as a powerful tool that proved more valuable than initially anticipated. The overall ROI is positive, and the solution effectively meets our needs. Additionally, we can now deploy Global Secure Access, a VPN solution that protects remote workers and filters internet traffic, adding further value.
The pricing of Microsoft Intune rates around four or five out of ten. The cost structure varies based on requirements. We utilize licensing bundles such as Microsoft 365 Business Premium, which includes the Microsoft Intune license and provides good value. Microsoft Intune alone costs approximately $6 monthly, but considering its device management capabilities, application installation features, and Microsoft Autopilot deployment functionality, the price is reasonable.
The user experience has been good. There is some crossover with Microsoft Entra ID. You can access groups and users from Microsoft Endpoint Manager when onboarding a device. This can be set up using Microsoft Endpoint Manager. If someone receives a new device, they can sign in for work purposes, and if you are familiar with Microsoft Windows, they will have the option to choose whether the device is for home or work use. Once we see the device in Microsoft Endpoint Manager, we can begin assigning profiles and encrypting the drive, making it easier for us to remain compliant. We utilize the CIS framework for compliance, which provides guidelines on tasks such as drive encryption and ensuring all settings are appropriately configured.
Additionally, we implement conditional access policies. For instance, if someone is outside the United States, we can require them to re-authenticate using Microsoft Authenticator for security verification. This measure ensures that if an unauthorized person managed to steal someone’s MFA token and attempted to sign in from outside the country, they would be prompted to complete another MFA session, which adds an extra layer of protection. Furthermore, we can restrict actions on mobile devices. For example, we can prevent users from copying and pasting content from Word documents into applications like Apple Notes. This feature is particularly useful for maintaining security.
If you are a Microsoft shop, these processes streamline operations significantly. However, for larger enterprises, costs may escalate. In such cases, it would be necessary to contact Microsoft to establish a suitable arrangement, similar to agreements made with Microsoft Azure for their resources. For small to medium-sized businesses, getting set up with these systems is straightforward and can assist in achieving compliance. It's important to note that this information pertains to Microsoft Purview and is distinct from Intune, which I will not discuss further.
We do use Copilot, but we have it turned off for email due to a current exploit. There are hidden Copilot commands that can pull data from sources a user might have access to and then email it to someone else, which is why it's disabled for mail. We only have a handful of licenses, and they are primarily for people who have limited time during the day and receive a lot of emails. It's a time-saving feature for them. Sometimes, they use it to write scripts quickly, like in PowerShell, which I then review to understand what it does. You can trust it, but you should always verify its output. Copilot is also helpful for creating a basic outline for documents, such as policies, where you can simply fill in the blanks. However, the pricing is not great. Additionally, you are locked into a one-year subscription with no month-to-month option. The cost is around $360 a year per person, which adds up quickly, so you have to be sure the person really wants it. Consider purchasing one license first to let someone try it out. If they find it beneficial, they can keep it, and we can buy additional licenses for others who express interest. Currently, we have very limited licenses due to the high cost. If they were half the price, I believe everyone would have access to it.
For those implementing Microsoft Intune, if you plan to have remote workers, consider whether you want to provide them with actual physical devices or if you can offer cloud PCs instead. Cloud PCs can be managed through Intune, and anyone with access to a Chrome-based web browser can use a desktop from anywhere with an internet connection. This approach also helps you avoid issues with retrieving physical devices from users, as they are not legally obligated to return them, potentially leading to a loss of significant investment.
Additionally, there are compliance issues to consider when providing devices. For instance, if you give a physical device to a contractor, they may be legally considered your employee under laws in certain states, such as California. Therefore, think carefully about your deployment strategy. Decide whether you'll be using physical devices, which may require more effort to manage, or cloud PCs, which might save you headaches in the long run. You also need to be proficient in PowerShell, as you may have to write remediation scripts. If you're not comfortable with PowerShell and prefer a simpler solution, be aware that there may not be many alternatives. This also aligns well with Microsoft Windows.
If you prefer to use Apple products, keep in mind that you can't just purchase a MacBook from a store. You'll need an Apple business account to obtain a certificate required for managing the device through Microsoft Intune. This rule applies to iPhones and iPads as well. In contrast, with Android devices, you don’t have these management restrictions. So, before making any decisions, consider your deployment strategy and the existing device ecosystem you have in place. I'm not familiar with using SCCM or other management tools, but be sure that with Microsoft Intune, simply buying a MacBook will not allow you to manage it without following the necessary procedures.
I would rate Microsoft Intune overall as an eight out of ten.
I use the solution across my full enterprise. That means for me roughly 4,000 devices, with 2,000 being desktops, 2,000 being laptops, and then maybe another 2,000 mobile devices.
The most valuable feature I have found is the access control. It integrates with Endpoint Manager. The reason for that is that it has allowed me to customize my organization's policies.
The security posture is very good. It's very customizable.
Overall, my user experience with Microsoft Intune has been great. It's offered a very smooth transition and I'm very positive on the product.
I am just starting with Microsoft Security Copilot. My experience with Copilot, and Microsoft Intune Copilot in general, has been incredibly positive as it's a skill multiplier for daily operations.
It's an absolutely critical application that I use every day.
Intune helps with app discovery. It's a game changer as it provides so much overall visibility.
I have analytics available. It's a wonderful tool, and I love the amount of data it's able to extract.
Intune is reducing our attack surface and improving our security posture.
Microsoft Intune has potential for improvement; I would like to see a lot more customization in the reporting tools.
I have been using the solution for four years.
My assessment of stability and reliability is that the uptime is fantastic, and I haven't had any issues.
Compared to my previous solution, it's incredibly easy, and it's scaled to the entire organization. Within a month, I had gone from zero to full deployment.
My experience with customer support or technical support is that they have been nothing but excellent.
Positive
Previously, I was using IBM to address the same issues. I made the switch since it was both more cost-efficient and Microsoft is best in breed.
The deployment was incredibly easy, and it's scaled to the entire organization; within a month, I had gone from zero to full deployment.
Intune has been helping us reduce the cost of devices per user and offers trusted effectiveness for maintaining the accuracy of those devices.
I don't have specific ROI data points.
The licensing has been fantastic and the support we've received from Microsoft has been impressive.
I wasn't involved in the RFP process.
I do not use PKI yet; it is on our task list, and it's on the list to get done, but it hasn't been completed. The reason it's on the list to get done is that I want everything in the same platform, just so everything integrates and supports each other.
My assessment of endpoint analytics is that it's a wonderful tool, and I love the amount of data it's able to extract; I can provide examples of how these features work.
On a scale of one to ten, I rate Microsoft Intune a ten.
As an administrator and user of Microsoft Intune, we have implemented several key features. Currently, we are using it for Windows updates across the whole company, pushing updates through Microsoft Intune. We also use it for the mass deployment of new applications.
Additionally, for security and access, we implement conditional access controls through Microsoft Intune. We have completed corporate device configuration and starting new journey on bring your own device (BYOD) management.
We use enterprise application management features in Microsoft Intune, with most applications integrated without multi-factor authentication previously. We need to control the number of devices accessing our environment to prevent data breaches or PII issues.
The most useful features in Microsoft Intune are the policy enforcement and conditional access. These features make our operations easier from a company perspective. Each company has its own policies, which are often only written in documents. By using Microsoft Intune, we can enforce these policies throughout the organization, binding everyone together instead of just having documented policies.
Microsoft needs to strategize its licensing structure. When using Microsoft Intune, we bought a small scale of controls, only controlling part of the devices, though Microsoft Intune can do much more. The Intune Suite offers more features, allowing extensive integration with either internal or cloud environments without requiring third-party licensing. However, each feature has a separate license, making logistics and cost management difficult if not strategically bundled together.
I have been working with Microsoft Intune for at least 2 years.
I would rate technical support from Microsoft a nine out of ten.
Positive
We previously used System Center Configuration Management (SCCM). With SCCM, out of 10,000 staff members, only 2,000 to 3,000 received updates and deployments. The updates were slower, and using SCCM caused more network congestion as updates were pushed through the internal network. With Microsoft Intune's cloud-based deployment, users can receive updates and application deployment almost everywhere, and they get updates almost daily. This keeps machines up to date and helps reduce vulnerabilities.
It's easy. In terms of cloud, I am mainly focusing on Azure. There are other divisions that handle AWS and also Huawei Cloud.
While managing Microsoft Intune, we experience some glitches in our hybrid environment with on-premises Active Directory. If the on-premises system has an issue, it can synchronize to the cloud with additional problems. This requires resolution on both sides, which is difficult. It's not Microsoft Intune's fault; it's due to our environment. For companies wanting to use Microsoft Intune, it's better to avoid a hybrid deployment and join everything to the cloud.
In terms of automatic updating with Microsoft Intune, users sometimes complain about needing to restart for weekly updates. Updates are automatically pushed to devices for security purposes. Microsoft Intune helps us manage these updates automatically, unlike SCCM, which requires manual work.
We conducted workshops with Microsoft to ensure we hosted management internally instead of paying third parties. We mobilized our internal team, which has allowed us to avoid additional costs related to external services.
All security solutions worldwide are expensive. Microsoft has allowed a small scale of features within Microsoft Intune for cost-efficient solutions. If you want the full suite, you need to invest more to gain better security features. It's not necessarily more expensive. You need to choose which features to buy. For basic features, Enterprise Mobility + Security E3 (EMS E3) is the lowest pricing Microsoft can offer.
We plan to explore Microsoft Intune Cloud PKI more, as it's not just a replacement for the CA server on-premises. It's a game changer for SSL certificates, eliminating reliance on third-party solutions such as GlobalSign and DigiCert. We plan to implement Wi-Fi with certificate integration, though this is currently just a vision, as we need to purchase it.
Microsoft Intune focuses on device management, including MDM (mobile device management) and MAM (mobile application management). Microsoft Intune can control various devices, but we currently focus on four operating systems: Android (with Google Play Store) and iOS for mobile devices, and Windows and macOS for computers. Our recommendation for Microsoft Intune would be to use it for managing device resources and ensuring policy enforcement according to company guidelines. Each device must maintain current security to prevent attacks or vulnerabilities.
I would rate Microsoft Intune an eight out of ten. I recommend Microsoft Intune and suggest purchasing it along with Microsoft 365 Suite or Azure, as the Intune Suite is essential for managing everything from antivirus to policies and accessing the environment.
Microsoft Intune policies, remote wipe, and using corporate and private profiles are valuable features, but MFA is the most valuable feature as it ensures that the end user is authentic. After authentication, logs can help us diagnose further. Previously, we didn't know who was using the devices, with every person having 3, 4, or 5 mobile devices registered to their email. We didn't know which device was live or not. With MFA, it is very helpful to identify which one is the last authenticated device. We can also restrict the number of devices using Microsoft Intune.
From an end-user perspective of Microsoft Intune, I haven't experienced any challenges since installation. However, some customers have reported experiencing slowness when using lower versions of the Android system. This observation has been reported to the distributor team, and they are working on it. Hopefully, this issue will be resolved in the next release.
As we have only been using it for six months, it might be too early to identify other areas for improvement.
We recently started using Microsoft Intune. We just completed about six months of usage.
It is very stable.
We have plans for expanding our business at least 5 to 10% in the next financial year with Microsoft Intune. With most people opting for hybrid work and not coming to the office five days a week, working from home or branch offices, the requirement will definitely grow.
It is too early to provide comprehensive feedback regarding the technical support for Microsoft Intune. We have basic support included in the plan. We have not opted for the advanced support ticket facility. We haven't utilized support services as we haven't faced any issues in the last six months. Without any support scenarios, we cannot comment on response times or resolution quality.
Neutral
We were not using any other solution. The requirement for such a solution came from the data breach incident. After that incident, it was brought to our notice that we needed an MDM solution to protect our data.
It's very smooth. It's done with two to three clicks. It's very easy.
After installation, Microsoft gave us a vulnerability assessment. Our IT administrators handled the necessary tasks based on the recommendations. The patch management, pushing of patches, and manually updating applications are helpful. They inform us when auto update is off, alerting us to turn on application updates when vulnerabilities are found.
We have not evaluated the measurable benefits since the deployment of Microsoft Intune. With only six months having passed, we need more time to observe and evaluate the returns.
It comes with the E5 plan. We bought the E5 plan from Microsoft.
From a price perspective, the E5 plan we opted for includes features we aren't fully utilizing. Our basic needs were offline Office for end users and cloud-based emails. When we inquired about MDM specifically, they offered separate plans, such as MDM Basic and others. We compared all options and migrated because paying separate license fees for Office and Microsoft 365 mailbox would be more complex. While it is somewhat costly, the major benefit is that we can select licenses only for those using personally owned devices rather than the entire organization.
We had an incident in our organization where we found a data breach in a mobile device, specifically on a personally owned device that employees were bringing in. To protect against this, we evaluated multiple products, including IBM, Microsoft, and ManageEngine. We chose Microsoft Intune as we were already existing Office 365 users. It was easier for us to upgrade the plan from our existing one to E5. It came with a bundle where we received all the services we wanted: private profile, secure download, prevention of sharing corporate data, and access to corporate data. It is easier for us to manage everything from a single console.
ManageEngine's MDM solution was less expensive and of good quality based on our evaluation. However, we couldn't proceed with it because their management console was different, and we were already using Office 365 with a 100 GB mailbox. Migrating all emails would have taken considerable time and risked potential email loss.
Microsoft Copilot is integrated with E5, and some users are utilizing it for writing emails and creating presentations. Copilot is an effective AI engine that helps predict known vulnerabilities and facilitates notification management and task scheduling.
For endpoint protection, we use Acronis through a separate console, which we've been using for 3-4 years with satisfaction. We are not using Microsoft Defender Advanced Security as it cannot currently integrate with third-party solutions.
I would rate Microsoft Intune a nine out of ten. It is very stable. The GUI is very good and efficient. Everything is fine. The only issue is with the Android devices.
We use Microsoft Intune as an MDM solution for all of our Windows laptops and some of our company mobile phones. This serves as an endpoint solution we use so we can control the users' laptops or phones and have access to things on their devices.
Without Microsoft Intune, there would be a lot of cybersecurity attacks happening. We need to use Microsoft Intune so we know which devices can access all of our company resources. If they don't have Microsoft Intune, we automatically deny them from accessing company-sensitive information, so it serves as a layer to protect all of our assets.
I appreciate how easy it is to deploy certificates to end users to get control over their device with Microsoft Intune; that's what Microsoft Intune is known for, and that's what we use them for.
The user experience of Microsoft Intune is pretty easy. Initially, the user has to download a certificate, so when we first give them a certificate to download, they download it on their side, and once they verify themselves, we have access to their phone or laptop, which works pretty effectively.
We are using Microsoft Copilot with Microsoft Intune. Microsoft Copilot helps us with the deployment of Microsoft Intune. Previously, things were more difficult to manage, especially when certificates expire, as they need to be pushed out every year. Sometimes we forgot that, and then people's laptops stop working, so Microsoft Copilot helps us stay on track.
Microsoft Copilot is equally as important as Intune. The go hand in hand as it works in conjunction with Microsoft Intune to affect the deployment process.
Microsoft Intune can be improved by making it even more seamless for users to download their certificates. Currently, we have to push it out to their laptop and they have to do some work on their end, but if we could integrate it so it's seamlessly done and the end user doesn't even know that Microsoft Intune is on their laptop and it's just naturally there, that would be even better. This is especially true for Apple devices, such as Apple phones, where you have to push it out and the user has to accept or deny whether Microsoft Intune can have access to these applications. If it were easier for us to do it automatically without getting permission, that would be beneficial, but in today's environment, we have to get permission to access data.
To make it a perfect ten, it would be helpful if there was a better way to troubleshoot user issues, as I've had a few users with corrupt files before and had to redeploy it without knowing the root cause.
We have been using Microsoft Intune for eight years.
I would rate Microsoft Intune a nine out of ten for stability and reliability. We've never really had any issues with it in the past, and if we have, it's maybe one or two random people where their certificate is corrupt or something's wrong, so we just need to go back and redeploy it, which is not really a significant issue.
Microsoft Intune scales very effectively with our growing needs. The only requirement is more licenses, so once we get more licenses, we're able to deploy them more quickly.
I haven't needed to contact customer service or technical support, which is a good sign. Since I haven't had to use them, I have no experience with their quality of service.
Positive
We did not use a different solution. We started with Intune.
My experience with the deployment of Microsoft Intune was good. Initially, I didn't know much about it, so I had to review all the documentation, complete training, and watch videos to get familiar. Once I got a grasp of things, I tested it on my phone and laptop, and when it worked, I felt comfortable deploying it to more people. I eventually deployed it to about 7,000 machines as it scaled up.
The biggest return on investment for using Microsoft Intune comes down to protecting security. We are protecting all of our assets and using it as an endpoint MDM solution, which fulfills our needs.
Microsoft Intune costs about $7 per user per month, which is somewhat on the pricier end. That said, it's a reliable product, so it's fair. If it were less expensive, we would be able to roll it out to more people, so it's definitely something we're considering.
We use Microsoft Intune for Windows products and Jamf for Apple Mac products. I'm not sure if Microsoft Intune works for Macs. If they do, that's something we'd be interested in exploring.
I prefer Microsoft Intune because Jamf is not the most reliable solution based on my personal experience.
We do not use Microsoft Intune Suite's cloud PKI.
We also do not use the Enterprise Application Management features of Microsoft Intune Suite.
I haven't examined the Advanced Endpoint Analytics in the Microsoft Intune Suite yet. That said, we do have it; I just haven't had the opportunity to review it.
I rate Microsoft Intune a nine out of ten.
Microsoft Intune is primarily used for mobile device management (MDM) and mobile application management (MAM) to secure and manage corporate devices, applications, and data.
Microsoft Intune has proven to be highly effective in managing Windows, macOS, iOS, and Android devices. From inventory control and application management to security and compliance, Intune streamlines IT operations, significantly reducing management time. This efficiency allows IT staff to focus more on providing care and support to end users.
Microsoft Intune has significantly enhanced our organization's IT operations by streamlining device management, strengthening security, and improving overall efficiency. Key improvements include:
• Simplified Device Management: Centralized control over Windows, macOS, iOS, and Android devices, reducing manual configurations and deployment time.
• Enhanced Security & Compliance: Automated enforcement of security policies, including encryption, access controls, and compliance monitoring, ensuring data protection and regulatory adherence.
• Improved Application Management: Seamless deployment and management of business-critical applications, reducing downtime and improving user experience.
• Efficient Remote Work Support: Secure access to corporate resources for remote and hybrid employees, enabling productivity while maintaining security.
• Reduced IT Workload: Automation of routine tasks, such as software updates and policy enforcement, allowing IT staff to focus on higher-value initiatives and user support.
From my expertise with Microsoft Intune, the most valuable features likely include:
1. Zero-Touch Deployment with Autopilot
2. Endpoint Security & Compliance Policies
3. Conditional Access & Integration with Microsoft 365
4. Mobile Application Management (MAM)
5. Remote Actions (Wipe, Lock, Reset, and Remote Assistance)
6. Software & Patch Management
Microsoft often updates and modifies the user interface without providing timely documentation for administrators. Changes such as relocating options, renaming settings, or removing features altogether can create confusion. As a result, administrators must search through Microsoft documentation— which may not yet reflect these updates— to identify and adapt to the changes.
I have been utilizing Microsoft Intune across various deployments of the M365 GCC, GCCH, and commercial platforms for approximately 8 to 9 years.
The system itself is great. It is on an enhanced platform that I do not have anything to worry about. The only part I need to worry about is my own redundancy on my side since if my circuit goes down, I will lose connectivity to the platform.
Intune scales effectively as your organization grows. As the user base increases, the cost per user decreases, making it a sustainable solution. Additionally, features like Windows Autopilot simplify zero-touch deployment and device provisioning, saving valuable IT time as you scale.
The need for Microsoft support was minimal due to our ability to rely on available documentation, even though some of it was somewhat outdated. We were able to effectively use this documentation to understand the functionality and features of Intune within our organization's operations. While there were occasional gaps in the documentation, our internal expertise and familiarity with Microsoft 365 allowed us to navigate and implement the necessary configurations without significant external support. This proactive approach helped streamline the deployment and ongoing management of the platform.
Neutral
No, switching is unnecessary. Microsoft allows for the integration of third-party solutions or the development of custom alternatives within Power Platform.
The initial setup of Microsoft Intune can be considered relatively straightforward, but with some complexity that requires an engineering mindset for full optimization.
At a high level, the process involves configuring the service, setting up device policies, integrating with Azure Active Directory, and applying security settings. For organizations that already use Microsoft 365 services, the setup is generally more streamlined due to the integration with Azure AD, which simplifies user and device management.
However, for an engineer, the complexity arises in designing the policies, determining which configurations and security measures are required based on organizational needs, and ensuring that devices across multiple platforms (Windows, macOS, iOS, Android) are properly managed. The setup process also requires thoughtful planning to align with compliance requirements, such as data protection, encryption, and remote wipe capabilities. Configuring these settings with precision is crucial to avoid security vulnerabilities.
Moreover, the engineering mindset is essential when working with advanced configurations, such as conditional access policies, application deployment strategies, or setting up integration with other Microsoft services like Endpoint Manager or Defender for Endpoint. Testing and fine-tuning these configurations to ensure they work as intended across various devices and user profiles can add complexity but is necessary for long-term success and security.
Overall, while the setup can be streamlined, a thorough understanding of your organization’s IT architecture and security requirements is essential to leverage Intune effectively.
I collaborated with our in-house team to deploy Microsoft Intune as part of the broader Microsoft 365 suite. Together, we leveraged our internal resources and expertise to integrate Intune seamlessly into our existing environment, ensuring smooth deployment and configuration. By utilizing our team’s knowledge of our organization’s infrastructure and security requirements, we were able to customize Intune settings to meet our specific needs, providing a secure and efficient device management solution across the organization.
The resources required to house and manage numerous physical servers, maintain various third-party software license bundles, and handle the upkeep of the infrastructure—including costs for cooling, electricity, and regular maintenance—would incur a significant financial burden. When compared to an all-in-one, secure Microsoft cloud-based solution, the contrast becomes clear. The cloud eliminates the need for extensive physical maintenance, providing built-in security and scalability. It offers the flexibility to seamlessly integrate additional products, reducing the reliance on physical devices. This not only simplifies IT management but also reduces overall operational costs, making the Microsoft cloud-based solution the most cost-effective and efficient choice for businesses.
For businesses, especially those in regulated industries, the cost of security features like encryption, data loss prevention, and multi-factor authentication can add up quickly if purchased individually. However, with Microsoft 365, particularly in environments like GCC High, these essential features are bundled together, providing strong protection without the need for additional third-party solutions. For example, $1,000 per year for an end-user on GCC High is a competitive price when considering the built-in compliance certifications and government-grade encryption.
Although the pricing may seem high at first glance, Microsoft’s licensing model is structured to scale with the growth of an organization. As the business expands, the cost per user decreases, making it a long-term investment that supports growth and adaptability. Features like Windows Autopilot for zero-touch deployment, MDM (Mobile Device Management), and MAM (Mobile Application Management) simplify the management of an expanding device fleet, reducing administrative overhead.
A key advantage of Microsoft 365, including Intune, is its seamless integration with the wider Microsoft ecosystem. From SharePoint and OneDrive to Azure AD and Microsoft Teams, these components work together as a unified solution. The pricing reflects this comprehensive value, streamlining the management of various enterprise functions from a single platform and saving time and resources in the process.
We did evaluate other options, which were developed within Power Platform. These alternatives offer the same level of security, as they are built within the same platform as Microsoft Intune.
Overall, Microsoft Intune is a powerful tool for managing devices, securing corporate data, and integrating with the broader Microsoft ecosystem. A 9/10 rating reflects its strengths and the few areas where it could further enhance its capabilities.
We are using various security solutions and implementing a Zero Trust framework for our organization. Intune is part of this framework.
We are transforming our flat network by adopting different cloud solutions, and our own applications are hosted in the cloud. Intune ensures our security throughout our entire cloud-based system, improving our security posture.
Intune is valuable for managing various endpoints and integrating with the Azure cloud, which is essential for our organization. The user experience is good because we only use Microsoft solutions, which are user-friendly.
We have Intune's enterprise application management in our pipeline, and our infrastructure and hybrid cloud team are working together to deploy applications using Intune. It has security analytics, and more exciting features are on the way.
Cloud PKI helps us manage the complexity of certificate infrastructure. Previously, we hosted all the VMs in our own data center, but now we're on the cloud, helping our user base and VMs grow.
Copilot helps our engineers work better by making suggestions and offering resolution metrics. We can understand and push those patches or fixes from that side.
Intune could be improved by organizing different solutions, like Defender and Sentinel, into a single package. This would allow us to focus on security while Microsoft manages other areas. Having a unified solution would drive better management of various sectors. Although the Intune user experience is good, we should continue enhancing it.
I have used Intune for one and a half years.
Since we started last year, it's relatively new, and I would need more time to fully assess it. However, I have positive thoughts about Microsoft Intune's stability and anticipate it will be beneficial for us.
Intune is scalable, and Microsoft is always focused on scalability, especially for business conglomerates like ours. Scalability has been ensured, and it's working correctly.
I rate Microsoft support seven out of 10. Technical support can be challenging when resources shift, requiring repeated explanations. Support from India sometimes provides information without the right solution. Given our premium support, expert-level service from Microsoft could be enhanced.
Neutral
Before Microsoft Intune, we used regular security solutions. We chose Microsoft Zero Trust for full security.
The initial setup was aided by our partner, who guided us well. Although there was much to learn initially, current processes have simplified the experience.
We worked with a local reseller, Elevate Solutions, who is implementing the Zero Trust framework for us. They have been committed and focused on implementing the right solutions, which has been helpful.
Earlier incidents caused data loss and required reentry. Microsoft Intune has improved our processes.
We have a limited budget for security investments, so Microsoft should consider reducing pricing in our region. This would make investment more viable, especially since larger businesses in other countries can afford it easily.
We evaluated Google Cloud Platform (GCP) before choosing Microsoft Intune, but since our team is experienced with Microsoft, and Microsoft's clear vision for the future aligns with ours, we chose Microsoft Intune.
I rate Microsoft Intune eight out of 10.
