Microsoft Intune
Microsoft’s cloud-based endpoint management platform. From Windows through macOS to iOS and Android — Intune is the central control point for every device in a modern Microsoft environment.
What is Microsoft Intune?
Microsoft Intune is a cloud-based unified endpoint management (UEM) platform. It allows central management and protection of:
- Windows 10/11 — desktops, laptops, tablets
- macOS — Apple machines with or without MDM
- iOS / iPadOS — iPhones, iPads
- Android — personal and company-owned devices
- Linux — Ubuntu, Red Hat (policies, not full MDM)
- Cloud-PCs & AVD — Windows 365, AVD Session Hosts
A history of renaming: Intune began as “Windows Intune” (2011), then became part of “Enterprise Mobility + Security (EMS)”, then “Microsoft Endpoint Manager” (together with SCCM/ConfigMgr), and since 2022 it is simply “Microsoft Intune” again — now with the Intune Suite as a premium add-on.
What Intune can do
| Feature area | Examples |
|---|---|
| Device Enrollment | Autopilot, BYOD, Company-owned |
| Compliance Policies | BitLocker required, password complexity, operating system version |
| Configuration Profiles | Wi-Fi, VPN, certificates, mail configuration |
| App Management | Win32-Apps, MSIX, Store-Apps, LOB-Apps |
| Mobile App Management (MAM) | App protection without full MDM |
| Updates Management | Windows Autopatch, Feature Updates, Quality Updates |
| Remote Actions | Sync, Wipe, Restart, Lost Mode |
| Endpoint Analytics | Start-up time, crash rate, user experience score |
Intune vs SCCM/ConfigMgr
Microsoft has developed both products in parallel. The trend clearly favours Intune — but SCCM/Configuration Manager is still relevant for large on-premises estates.
SCCM / Config Manager
- DeploymentOn-premises server
- DevicesWindows only, plus macOS and Linux (limited)
- BandwidthOptimised for LAN and peer cache
- ApplicationsVery large task sequences are possible
- UseLarge AD-based estates
Microsoft Intune
- DeploymentCloud SaaS
- DevicesEvery common operating system
- BandwidthRequires internet access for every device
- ApplicationsWin32 support through Intune Win32 app packaging
- UseModern, hybrid environments
Co-Management
Many organisations run Co-Management: devices are registered in both SCCM and Intune at the same time. Workloads (compliance, updates, application deployment) are moved from SCCM to Intune step by step, as the estate matures.
Intune for AVD and Windows 365
Windows 365 & Intune
Windows 365 Enterprise is fully integrated into Intune. Cloud PCs are managed there like ordinary Windows devices — compliance, applications and Conditional Access, all centrally.
AVD & Intune
Since mid-2023 AVD session hosts have been officially manageable through Intune — but with limitations:
- Supported: personal desktops, multi-session (with limitations)
- Prerequisite: Entra ID join (not on-premises AD)
- Policies: Configuration Profiles, Compliance, Apps
- Not every feature: Autopilot is not relevant, and multi-session comes with some policy limitations
For production enterprise AVD, Intune is strongly recommended as a replacement for classic group policies.
Intune integration in DaaS Maps
DaaS Maps shows Intune integration patterns for AVD and Windows 365. For discussion of endpoint management strategy and Intune rollouts, you will find me on LinkedIn.