SYSTEM ADMIN BOOK
  • Hardware/Physical Machines
    • Physical Networking
      • Patch Panel
    • Hardware Devices
    • PC Build
    • RAID Configs
  • System Configuration
    • Windows
      • OneDrive for Business, Map as Network Drive in Windows
      • PDF Printer
      • Reset Windows Password
    • Linux
    • Mac
      • Factory Reset Mac Mini
      • Install FortiClient VPN
      • Remove FortiClient VPN for Macs
      • Setting Microsoft Teams Notifications in MacOS
      • Download and Install Whatsapp
  • Windows Server
    • Troubleshooting
      • 100% Disk Usage Issue
      • Maximum Path Length Limitation
    • Basic Configurations
      • Change Hostname
      • Change Default RDP Port
      • Create a User
      • Add user to Administrator group
      • Add user to Remote Desktop Users group
      • Allow log on locally - security policy setting
      • Allow Multiple Remote Desktop Connections
      • Enable Insure Guest Authentication
      • Shrink Partition
      • Extend Partition
    • FTP Server
      • Install FTP Server (IIS)
      • Create User Group
      • Add FTP Site (IIS)
      • User Isolation
      • Allow Firewall
      • FTP Client (FileZilla)
      • FTP Server (FileZilla)
      • Configure Passive Mode in FileZilla Server
      • Configuring Windows Firewall for FileZilla Server
      • FileZilla: Password reset
      • Generate a New Self-Signed Certificate
    • Group Policy
      • Block Access to the Control Panel for All Users
      • Create a Logon Banner (Legal Notice)
      • Enable / Disable Copy-Paste Policy
      • Disable Shutdown, Restart Options
      • Disable Multiple Session for Single User
      • Disable Automatic Lock Screen in Windows Server
    • Services
      • NSSM - the Non-Sucking Service Manager
      • Node-windows Library
    • Task Scheduler
      • Automate Program Execution
      • Restart Windows Server Daily
    • Auditing and Diagnostincs
      • Enabling the System Event Audit Log
      • Audit RDP Port Change Event
      • Check the read/write speed of your hard drive
      • Clear temp file and .trc file
    • Event Viewer
      • Restart / Shutdown Event
  • Control Panels
    • Plesk
      • Set Hard Quota on disk space for subscription(s)
      • Changing MX, A, and CNAME Records
      • Host Node.js Application
      • Add FTP account
      • Remove FTP account
      • Download a folder using Plesk File Manager
      • Install WordPress on domain using WP Toolkit
      • Change the name of a Subscription system user
      • Exporting and Importing Database Dumps
    • OVI Panel
      • DNS Zone Editor
    • SolidCP
      • Add a MS SQL database in SolidCP
    • cPanel
  • Virtualization
    • Proxmox VE
      • Introduction
      • Download Proxmox ISO
      • Prepare Installation Media
      • Launch Proxmox Installer
      • Create a VM
  • Web Servers
    • IIS
      • Install IIS
      • Configure Default Site
      • Application Pool
      • Installing PHP
      • Deploy a PHP Application
      • Deploying a Laravel app on Windows using IIS
      • Update PHP Version in IIS
      • Host a Node.js /w Next.js Application
    • JBoss
  • VPNs and Proxy Servers
    • Reverse Proxy
      • IIS - Node.js Application
  • Database Servers
    • MS SQL
      • Download and Install
      • Install SSMS
      • Uninstall an Instance of SQL Server
      • Enable SA Account
      • Change SA Account Password
      • Enable Network Access to SQL Express
      • Create and configure a user in MSSQL
      • Clear SQL Server Cache
      • Setting Infinite Timeout in SQL Server Contexts
      • Take SQL Server Database Offline
      • Memory configuration
  • Web Dev Stacks
    • MERN (w/ Next)
      • Build and Run Node.js Project with Next.js
  • IT Ticketing Systems
    • Jira Ticketing System
  • Linux Servers
  • AWS Environment
  • Azure Environment
  • Backup and Security
    • SSL Certificates
      • Types of SSL Certificates
      • IIS 10: Create CSR and Install SSL Certificate
      • IIS 7: Generate CSR for Wildcard SSL
      • IIS: Generate CSR for Multi-Domain SSL
      • OpenSSL: Generate CSR
      • IIS 10: How to Install and Configure Your SSL Certificate on Windows Server
      • IIS: Export Pfx using MMC
      • IIS: Import Pfx using MMC
      • IIS: Export Pfx using IIS Manager
      • IIS: Import Pfx using IIS Manager
      • cPanel: Export PFX
      • Godaddy-CPanel: Generate a CSR
      • Godaddy-CPanel: Install SSL Certificate
      • cPanel: Generate CSR
      • cPanel: Install SSL Certificate
      • cPanel: Install Let's Encrypt SSL
      • Plesk: Generate CSR
      • Plesk: Let's Encrypt SSL Installation
      • Plesk: Installing the SSL certificate
      • Plesk: Export Public & Private Key
      • Win-ACME Let's Encrypt SSL
      • Certbot - Install SSL
      • Export Leaf, Root, and Intermediate Files
      • XAMPP - Let's Encrypt SSL Installation
      • JBoss Web Server: CSR Generation
      • JBoss: Install SSL Certificate
    • Backup
      • Database
        • MS SQL DB Backup
        • MS SQL Restore Backup
    • Microsoft Defender for Endpoint
      • Introduction & Licenses
    • Microsoft Intune - Endpoint Management
      • Product Introduction
      • Intune Policies for MacOS
      • Enroll your macOS device using the Company Portal app
    • Vulnerability Scanning
      • OpenVAS Quick Guide
      • Nessus Quick Guide
    • Acronis
      • Download and Install the Acronis Cyber Protection Agent
      • Performing a file-level backup
      • Creating a disk-level backup
      • Performing a file-level recovery
      • Enabling Active Protection and Vulnerability Assessment
  • Email and Office 365
    • Troubleshooting
      • Run a message trace in the Exchange admin center
      • Not receiving email
      • Office 365 Apps Activation Error
      • Gmail Issue: Clearing Cache and Cookies
      • Excel worksheet, right click insert not functioning
      • Microsoft 365 Apps activation error: “Your organization has disabled this device”
    • Hybrid Mail Setup
      • Set Up Connectors Between Microsoft 365 and SmarterMail
    • Email Authentication
      • Protocols
    • Mail Clients
      • Outlook
        • Maximum number of Exchange accounts in an Outlook profile
        • Enable automatic forwarding in new Outlook
        • Add Email Signature
        • Create Email Singature
        • Gmail Account Login in Outlook
        • Enable desktop notifications for Outlook on the Web (OWA) in Windows
        • Move Mails to Specific Folders
      • Apple Mail
        • Add email accounts in Mail on Mac
        • Add Mail Signatures
      • Gmail
        • Mail Forwarding to Another Account
        • Set Up an Auto-Reply (Vacation Responder) in Gmail
    • Office 365
      • Intro & Subscriptions
      • How to Create a Trial Account
      • How to Access the Office 365 Admin Center
      • Creating a Tenant
      • Create Users
      • Add several users at the same time to Microsoft 365
      • Creating & Managing Roles
      • Add a Domain
      • Manage MFA
      • Let users reset their own passwords
      • Assign Global Admin Roles
      • Create APP Password
      • Change a user name and email address
      • Reset MFA for Microsoft 365 User
      • Configure email forwarding
      • Add email aliases to a user
      • Change Username or Email Address
      • Export Mailbox to PST From Office 365
      • Import PST to Exchange Online (Microsoft O365)
      • Enable archive mailboxes for Microsoft 365
      • Grant Export Permission in M365 Compliance Center
      • Generate Transfer Token
    • Google Workspace
      • Intro & Plans
      • Create your Google Workspace trial account
      • Review your DNS records
      • Adding Users
      • Create organizational units
      • Restrict access to a Google Workspace service
      • Edit user attributes
      • Manage user accounts
      • Suspend a User
      • Generate a Transfer Token
      • Reduce Licenses in Google Workspace
      • Auto-forward From Google Workspace Using Routing
      • Recovering administrator access to your account
    • MailEnable
    • SmarterMail
      • SmarterMail Installation
      • SmarterMail Server Setup
      • Installation and Configuration (Practical)
      • Enable / Disable Domain in SmarterMail
      • Enable / Disable MFA for User Accounts
      • Create an Administrator User in SmarterMail
    • Microsoft Teams
      • Guest Access vs. External Access
      • Adding Guests To Microsoft Teams Team
      • Teams Chat DIfferent Domain: Enable External Access
      • Setup Teams Time Zone and Work Hours
      • Add Contact Numbers in Profile Page
    • Microsoft Defender for Office 365
      • Remove blocked users from the Restricted entities page
    • Microsoft Purview
      • Create a Retention Policy for Archiving in M365
  • DevOps
  • Firewalls and Access Points
    • Windows Firewall
      • Allow Ports on Windows Firewall
    • Sophos Firewall
      • Set up a new firewall with Sophos Central
      • Enable Sophos Central management of Sophos Firewall
  • Networking
    • Troubleshooting
    • Cisco Router Config
    • Cisco Switch Config
      • Basic Data and Voice VLAN Setup Homelab
  • Migration
    • Drive Migration
      • Google Drive to One Drive
      • One Drive to One Drive [SharePoint Migration Tool]
      • Migrate Google files to Microsoft 365 for business
    • Mail Migration
      • Google Workspace to Office 365 (Manual Method)
      • Google Workspace to Office 365 (Automatic Method)
      • IMAP to Office 365
      • Migration Using PST File Method
      • Office 365 to Google Workspace Migration
      • G-Suite to G-Suite Migration
    • VM Migration
    • Website Migration
      • Migrating IIS Sites Using Web Deploy
      • Plesk to Plesk Migration
    • Database Migration
  • Monitoring
    • Prometheus
      • Monitoring Windows Servers Using Prometheus
    • Grafana
      • Visualize Data in Grafana
    • Loki
  • Data Center
    • HPE ProLiant ILO Configuration
  • Other Technologies
    • Some R&Ds
      • Active vs. Passive Mode in FTP
      • IIS Recycling and Virtual Memory Limit
      • IIS Application Pool
Powered by GitBook
On this page
  • What is Microsoft Intune?
  • Microsoft Intune features and capabilities
  • How it works
  • Benefits of Microsoft Intune
  • Challenges of Microsoft Intune
  • History and development
  • Microsoft Intune pricing
  • REFERENCES

Was this helpful?

  1. Backup and Security
  2. Microsoft Intune - Endpoint Management

Product Introduction

PreviousMicrosoft Intune - Endpoint ManagementNextIntune Policies for MacOS

Last updated 13 days ago

Was this helpful?

What is Microsoft Intune?

Microsoft Intune is a cloud-based unified endpoint management (UEM) tool that aims to help organizations manage the mobile devices employees use to access corporate data and applications, such as email.

It is a component of Microsoft's Enterprise Mobility + Security (EMS) offering, a mobile device management and mobile application management (MAM) platform. Intune is designed to integrate with other parts of the EMS offering, including Azure Active Directory (Azure AD) and Microsoft Azure Information Protection. Intune's app protection policy component uses the Azure AD identity to separate corporate and personal data.

Microsoft Intune features and capabilities

Over the years, Microsoft Intune has evolved into a cross-platform tool for managing devices and apps. The most important features and capabilities include the following:

  • Manage personally owned and company-owned devices of the most common platforms and provide secure access to company data on those devices. Microsoft Intune currently supports management for Android, iOS and iPadOS, Linux, macOS, Windows and ChromeOS devices.

  • Manage the lifecycle of apps on managed devices, including the deployment, update and removal of apps.

  • Manage apps on mobile devices and securely provide access to company data via those apps.

  • Enable self-service functionalities, such as resetting PIN or password, installing apps and removing devices, via the Company Portal app.

  • Integrate with mobile threat defense services for a real focus on endpoint security.

  • Provide report capabilities that provide insights into your environment. This includes reports with insights about policies, profiles, updates, apps and more.

Microsoft Intune is the company's unified endpoint management tool.

How it works

In Microsoft's approach to managing mobile devices, Intune mainly uses protocols or APIs available in mobile OSes to execute tasks, such as enrolling devices. Enrollment lets IT personnel maintain an inventory of devices that can access enterprise services. Other tasks include mobile device configuration, certificates, Wi-Fi and VPN profiles, and compliance reporting concerning corporate standards. Intune integrates with Azure AD to provide access control capabilities. That provides the required tool set for working toward a zero-trust environment.

Meanwhile, Microsoft's Intune app management approach covers areas such as assigning mobile apps to the workforce, configuring those apps with standard settings and removing enterprise data from mobile apps. When used with other EMS suite services, Intune lets an organization provide apps that can access additional mobile app and data security features, such as single sign-on (SSO) and multifactor authentication.

Benefits of Microsoft Intune

Intune provides organizations with the features and capabilities to manage their devices and apps and protect company data. With the integrations of Intune with Azure AD, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft 365 and Windows Autopatch, it's an important part of the zero-trust strategy in a Microsoft cloud environment.

Intune can provide an IT department with the required features for managing enrollments, configurations, security, compliance, apps and updates on any supported device. That enables IT admins to securely provide access to company data on nearly any device.

With direct integration with Conditional Access via Azure AD, Intune can enable IT administrators to check if a device complies with company policies and only allow access to company data and apps when that device is compliant.

Challenges of Microsoft Intune

Intune excels within a Microsoft environment because it integrates well with other Microsoft products. While Intune can manage non-Windows platforms, it won't be at the same level as specialized products. For example, a product like Jamf provides more options for managing devices in the Apple ecosystem.

Additionally, organizations that use Linux devices may want to look at alternative UEM platforms. Except for verifying compliance and securely providing access to company data, no other management capabilities are currently available for Linux distributions.

History and development

Microsoft Intune launched in 2011 as Windows Intune, with the name change to Microsoft Intune announced in 2014. A key development since then was the migration of Microsoft Intune to the Microsoft Azure public cloud. In December 2016, Microsoft unveiled a preview where administrators could access and manage Microsoft Intune using the Azure portal. In June 2017, Microsoft announced the general availability of Intune management through the Azure portal.

Microsoft's Conditional Access feature became available via the Azure portal in 2017. Conditional Access works across the EMS suite, letting organizations control access to enterprise data based on considerations such as location and the sensitivity of a given application.

In 2018, Microsoft announced that the Intune Managed Browser application on iOS and Android could utilize SSO to access all web applications, both SaaS and on premises, provided those applications connect to Azure AD.

Another name change came in 2019 when Microsoft rebranded the suite that contains endpoint management. The new suite, which includes products like Configuration Manager, Intune and Windows Autopilot, was named Microsoft Endpoint Manager.

In 2022, Microsoft rebranded Microsoft Endpoint Manager back to Microsoft Intune with several new product announcements, including Remote Help, Endpoint Privilege Management, advanced endpoint analytics and Microsoft Tunnel for MAM. The first batch of expanded tools launched on March 1, 2023, and more features are planned for release later in 2023.

Microsoft Intune pricing

Intune is priced per user, per month, and organizations can purchase it as a standalone plan or a component of another subscription. The following are the three individual plans:

  1. Microsoft Intune Plan 1. Plan 1 includes basic UEM functionality and is included with subscriptions to Microsoft 365 E3, E5, F1, F3, EMS E3 and E5, and Business Premium plans. Notably, the expanded tools in Microsoft Intune Suite are purchasable as add-ons for Plan 1. The price for Plan 1 is $8 per user, per month.

  2. Microsoft Intune Plan 2. Plan 2 is an add-on to Plan 1 and features additional tools, such as Microsoft Intune Tunnel for MAM and endpoint management for specialty devices. The price for Plan 2 is $4 -- in addition to the $8 for Plan 1 -- per user, per month.

  3. Microsoft Intune Suite. Intune Suite is the highest-tier plan for Intune as a standalone service. It's an add-on to Plan 1, includes the add-ons from Plan 2 and features even more tools. The additional tools found in Intune Suite include Remote Help, Endpoint Privilege Management, advanced endpoint analytics and more tools set for release later in 2023. The price for Intune Suite is $10 -- in addition to the $8 for Plan 1 -- per user, per month.


REFERENCES

  • https://www.techtarget.com/searchitchannel/definition/Microsoft-Intune

  • https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune

  • https://www.microsoft.com/en-us/security/business/microsoft-intune-pricing

  • https://www.stanfieldit.com/microsoft-intune-features/

Chart with key details of Microsoft Intune, including history, business uses and management approach