Intune MDM: What It Does, What It Costs, and How to Roll It Out
Intune MDM is Microsoft Intune's mobile device management mode: a cloud service that enrolls Windows PCs, Macs, iPhones, and Android devices, then pushes security settings, apps, and updates, checks compliance, and can lock or wipe a lost device. For most small businesses it's already included in Microsoft 365 Business Premium, so the real cost is setting it up properly.

My first IT job was on the bench at Circuit City. Setting up a computer meant sitting in front of it, installing everything by hand, one machine at a time. Today I can ship a new laptop straight from the manufacturer to someone's house, and it configures itself when they sign in. If that doesn't impress you, you never spent a Saturday imaging 30 desktops with a stack of CDs.
That's what Intune does when it's set up right. When it's set up wrong, it's an expensive way to annoy everyone.
TL;DR: Intune MDM manages and secures company devices from the cloud. It's included in Microsoft 365 Business Premium. Use full MDM for company-owned devices and app-only management for personal phones. Roll it out in phases, start with compliance policies and updates, and connect it to Conditional Access, or it's just a very nice inventory list.

What Is Intune MDM?
Microsoft describes Intune on Microsoft Learn as "a cloud-based endpoint management service that secures and manages your organization's devices and apps." It adds: "The service runs entirely in the cloud, with no on-premises infrastructure required."
Intune works in two modes:
MDM (mobile device management). The device is enrolled and Intune manages the whole thing. In Microsoft's words, "If a device is lost or stolen, you can wipe it."
MAM (mobile application management). Intune manages only the work apps and the data inside them. Microsoft notes that "MAM is typical for personal devices in bring-your-own-device (BYOD) scenarios."
Most small businesses need both: MDM for company laptops and phones, MAM for personal phones. We covered the personal-device side in our BYOD policy guide.
Supported platforms include Windows, macOS, iOS and iPadOS, Android, and Linux.

What Intune Mobile Device Management Can Do
Every guide on this lists the same core features. Here's what each means in plain English.
Enrollment. Get devices into management, either automatically on new hardware or by the user signing in.
Configuration. Push Wi-Fi settings, VPN, BitLocker or FileVault encryption, Windows Hello, and browser settings.
Compliance policies. Define what "healthy" means: encrypted, up to date, screen lock on, antivirus running. Devices that fail get flagged.
App management. Install Microsoft 365, line-of-business apps, and approved tools. Remove what shouldn't be there.
Updates. Control when Windows and app updates install, with deadlines so nobody postpones them forever.
Remote actions. Lock, restart, locate, retire, or wipe a device.
Reporting. See every device, its owner, its OS version, and whether it passes your rules.

Compliance Plus Conditional Access Is the Whole Point
Here's the part a lot of setups miss. Intune checks whether a device is healthy. Microsoft Entra Conditional Access decides whether that device gets in.
Microsoft's explanation: "Intune sends device compliance state to Entra, and Conditional Access combines it with the user, app, location, and Defender risk signals to allow or block access to corporate resources."
Without Conditional Access, Intune can tell you a laptop is unencrypted and three months behind on updates. It just can't stop that laptop from opening your client files. With it, the rule becomes simple: no healthy device, no email. That's the difference between a report and a control.

Which Microsoft 365 Plans Include Intune
Microsoft's licensing page explains that Intune comes in Plan 1 (the base service), Plan 2, and the Intune Suite, and that "Most organizations get Intune as part of a Microsoft 365 bundle" rather than buying it separately.
For small businesses, the one that matters is Microsoft 365 Business Premium, which includes Intune Plan 1. Business Basic and Business Standard don't include Intune.
If you're already paying for Business Premium and not using Intune, you're paying for a security system and leaving it in the box. That's the most common thing I see in a new client's tenant.

Windows Autopilot: New Laptops Without the Imaging
Autopilot is Intune's partner for Windows. Microsoft's Autopilot overview calls it "a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use."
In practice: your vendor registers the laptop's hardware ID with your tenant, ships it to the employee, they sign in with their work account, and Intune installs apps, settings, and security policies. No technician has to touch it. It also works for resetting a laptop when someone leaves, so the next person gets a clean machine.
This is where the Circuit City version of me would have cried happy tears.

How to Roll Out Intune MDM Without Breaking Everything
The biggest mistake is turning everything on at once. Do it in phases.
Clean up identities. Make sure every user is in Microsoft Entra ID, with MFA on.
Set the MDM authority and enrollment. Configure automatic enrollment for Windows and Apple Business Manager for company iPhones and Macs.
Start with a pilot group. IT plus two friendly users.
Apply compliance policies in report-only mode first, so you see who would fail without locking anyone out.
Push the basics. Encryption, updates, antivirus, screen lock.
Add app protection for personal phones.
Turn on Conditional Access once most devices pass.
Enroll everyone else and handle the stragglers.
Budget a few weeks, not an afternoon. A managed help desk is useful here, because rollout week generates exactly the kind of "my laptop says it isn't compliant" calls nobody enjoys.

The Unglamorous Fix: Restart It
Here's my one strong opinion. Reboot it first.
A huge share of "Intune isn't working" problems clear up with a restart. Policies don't apply until the device checks in. Updates install but don't finish until a reboot. A laptop that hasn't restarted in 47 days will show as non-compliant, and then Conditional Access will (correctly) block it, and then someone will call me very upset at 8:55am.
So set Windows update deadlines with automatic restarts outside work hours, and teach staff that a restart is the first step, not the last resort. It sounds too simple to say out loud. It's still right nine times out of ten.

Intune's Limits, Honestly
Intune is very good, not magic. Things to know:
Third-party app patching is limited in Plan 1. Many businesses add a separate patching tool or use an RMM alongside Intune.
Mac management works, but Apple-focused tools like Jamf still go deeper for Mac-heavy shops.
It doesn't manage servers. Servers need separate tools and server administration.
It isn't antivirus on its own. Pair it with Microsoft Defender or another EDR tool and someone who reads the alerts.
Setup is easy to get wrong. Conflicting policies are the number one source of Intune headaches.

Intune vs Other MDM Tools
Intune isn't the only option. It's just the one most small businesses already own.
Intune. Best fit if you're on Microsoft 365, mostly Windows, and want device health tied to Conditional Access. Included in Business Premium.
Jamf. The go-to for Mac-heavy shops. Deeper Apple management, separate license.
Google endpoint management. Built into Google Workspace. A good fit if you live in Google, lighter on Windows.
RMM platforms. The remote monitoring and management tools most MSPs use. Strong at patching, scripting, and alerting, weaker at identity-based access control. Many businesses run an RMM alongside Intune.
All-in-one UEM tools like ManageEngine, Kandji, or NinjaOne. Useful for mixed fleets, at extra cost.
Rule of thumb: if you already pay for Business Premium, start with Intune. Add a second tool only when you hit a specific gap, like third-party patching or advanced Mac management, not because a sales demo looked shiny.

When You Don't Need Us for This
You're under 10 people, all on Business Premium, and comfortable in admin centers. Microsoft's setup guides are good. Follow them in the order above.
You're a Mac-only shop. Look at Apple Business Manager with an Apple-focused MDM first.
Where help pays off: 15 or more devices, a mix of Windows, Mac, and phones, compliance requirements, or remote staff who need laptops shipped ready to work. That's part of our managed IT services.

Straight Answers About Intune
What is Intune MDM?
Intune MDM is Microsoft Intune's mobile device management mode. It enrolls devices and manages their settings, apps, security, and updates from the cloud, and can lock or wipe them remotely.
Can Intune wipe a personal device?
If a personal device is fully enrolled in MDM, it can be wiped. With app-only management (MAM), which is typical for personal devices, Intune can selectively remove company data without touching personal content.
Is Intune included in Microsoft 365 Business Premium?
Yes. Microsoft 365 Business Premium includes Intune Plan 1. Business Basic and Business Standard do not.
Can Intune manage Macs?
Yes. Intune supports macOS enrollment, configuration, apps, and compliance policies, though Mac-focused tools can offer deeper Apple-specific features.
Can Intune be used for patch management?
Intune manages Windows and Microsoft app updates well. Patching for many third-party apps needs Intune add-ons or a separate patching tool.
Can Intune manage servers?
No. Intune is built for endpoints like laptops, desktops, and mobile devices, not servers.

Still Stuck? Give Us a Call
If you're paying for Business Premium and Intune is still in the box, give us a call at 410-703-3857 or send us a note. We set up Intune for businesses across the DMV, including Fairfax, on one flat monthly rate.
We'll get your devices managed, compliant, and quiet. We'll also remind you to restart. Sorry in advance.



Comments