Prepare the Infrastructure
- Bring devices into Microsoft Entra ID: registration or Entra join, device groups with dynamic membership rules
- Enrolment in Intune: settings, automatic enrolment for Windows, personal enrolment for macOS, iOS and iPadOS
- Android enrolment profiles (fully managed, dedicated, work profile), Apple Business Manager, Samsung Knox and Google Zero Touch
- Roles and scope tags for environments with multiple administrators, multi-stage approval
- Compliance policies for all platforms, conditional access with compliance status, Windows Hello for Business, Windows LAPS, manage local groups
Manage Devices
- Windows Autopilot: deployment profiles and device preparation policies, user-driven, pre-provisioned or self-deploying, naming templates, enrolment status page
- Upgrade to Windows 11 via Intune, deploy Windows 365 Cloud PCs, Windows Backup and Restore
- Configuration profiles for Windows (including ADMX import and Group Policy analytics), Android, iOS/iPadOS, macOS, and specialty devices such as Teams Rooms and HoloLens 2
- Intune Suite: Endpoint Privilege Management, Enterprise App Catalog, Remote Help, Microsoft Cloud PKI, Microsoft Tunnel for MAM, Advanced Analytics
- Remote actions: sync, restart, retire, reset, bulk actions, rotate BitLocker keys and local passwords, device diagnostics and queries with KQL
Protect Devices
- Endpoint security: antivirus, disk encryption and firewall policies, attack surface reduction based on zero-trust principles, security baselines
- Integration with Microsoft Defender for Endpoint: EDR policies, onboarding, investigate threats and triage incidents; App Control for Business
- Control updates: update rings, feature and quality updates, Windows Autopatch and hotpatch, updates for iOS, macOS and Android, delivery optimisation, monitoring
Manage and Secure Applications
- Deploy apps: Win32 apps, line-of-business apps, Microsoft Store apps, Microsoft 365 Apps – including as part of an Autopilot deployment
- Apps from platform stores via the Apple Volume Purchase Program and Google Play, monitor deployment status and fix installation failures
- App protection policies for managed and personal devices (BYOD), conditional access for app protection, app configuration policies
Automate and Monitor Operations
- Automate Intune via PowerShell and Microsoft Graph, extend compliance through scripts
- Security Copilot agents in Intune: investigate threats, analyse device performance, evaluate recommendations
- Reports, workbooks and dashboards; Endpoint Analytics with proactive remediations, device health and startup performance
- Monitor tenant status and service messages, alert rules for compliance deviations and enrolment failures