Setting up Microsoft Intune means preparing a cloud tenant to manage your organization’s devices and apps: assigning licenses, setting the mobile device management (MDM) authority to Intune, configuring enrollment for each platform, and creating the policies devices receive when they enroll.
To set up Microsoft Intune, sign in to the Microsoft Intune admin center at intune.microsoft.com, add users and groups, assign Intune licenses, confirm the MDM authority is set to Intune, configure enrollment prerequisites for each device platform, create compliance and configuration policies, add apps, and enroll devices in stages starting with a pilot group.
Key Takeaways
- Intune is administered from the Microsoft Intune admin center at intune.microsoft.com. The Microsoft Endpoint Manager name was retired in 2022, and setup no longer runs through the Office 365 admin center.
- Every managed user needs an Intune license. Intune Plan 1 is included in Microsoft 365 E3, E5, F1, F3, Business Premium, and Enterprise Mobility + Security E3 and E5.
- As of July 1, 2026, Intune Suite capabilities are included in Microsoft 365 E3 and E5. E5 tenants gain Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise App Management at no add-on cost.
- Windows automatic enrollment requires Microsoft Entra ID P1 or P2. Apple devices need an MDM push certificate, and Android Enterprise needs a Managed Google Play connection, before any device can enroll.
- New Intune tenants have the MDM authority set to Intune automatically; older tenants should confirm it in the admin center before enrolling the first device.
What You Need Before You Set Up Intune
An Intune setup needs three things in place before any device enrolls: the right licenses, a Microsoft Entra ID tenant, and devices running a supported operating system.
Licensing: Intune Plan 1 is included in Microsoft 365 E3, E5, F1, F3, Business Premium, Enterprise Mobility + Security E3 and E5, and Government G3 and G5, and is also sold standalone. A free trial includes 25 licenses. Administrators do not need a license themselves: unlicensed admin access is enabled by default for tenants created after July 2021. As of July 1, 2026, Intune Suite capabilities are included in Microsoft 365 E3 and E5. E3 and Enterprise Mobility + Security E3 tenants gain Remote Help, Advanced Analytics, and the Intune Plan 2 features, while Microsoft 365 E5 additionally gains Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise App Management. Microsoft is rolling the change out across tenants over summer 2026 with a 30-day notice in the Message Center, alongside a list-price increase effective the same date. If you currently pay for the Intune Suite add-on, review your agreement so you do not pay twice for the same entitlement.
Microsoft Entra ID: Intune stores no identities of its own; it depends on Microsoft Entra ID (formerly Azure Active Directory) for users, groups, and Conditional Access. Automatic MDM enrollment of Windows devices requires Entra ID P1 or P2, which every Microsoft 365 E3 and E5 bundle includes.
Supported operating systems: Verify your fleet against Microsoft’s supported platforms reference before you begin. As of July 2026 the minimums are:
| Platform | Minimum supported version (July 2026) | Notes |
| Windows | Windows 11 (Home, S, Pro, Pro Education, Education, Enterprise, IoT Enterprise); Windows 10 devices still enroll | Windows 10 reached end of support on October 14, 2025; pair remaining devices with Extended Security Updates |
| iOS/iPadOS | iOS/iPadOS 17 or later | Intune tracks the three most recent Apple releases |
| macOS | macOS 14 or later | The minimum is expected to move to macOS 15 after Apple ships macOS 27 later in 2026 |
| Android | Android 10 or later for user-based management; Android 8 for userless dedicated devices | Android device administrator support ended for devices with Google Mobile Services in December 2024 |
| Linux | Ubuntu Desktop 24.04 and 26.04 LTS; Red Hat Enterprise Linux 9 and 10 | Ubuntu 22.04 support ends in August 2026 |
How to Set Up Microsoft Intune in Seven Steps
Setting up Intune follows Microsoft’s own deployment sequence: prepare the tenant, configure enrollment, build policies, then enroll devices in stages.
- Sign in to the Microsoft Intune admin center: Go to intune.microsoft.com with a Global Administrator or Intune Administrator account. If your organization has no subscription yet, start the free trial from the same page. Add your custom domain name before enrolling devices, or the default onmicrosoft.com domain becomes part of every enrolled identity.
- Add users and groups, then assign licenses: Create users and security groups in Microsoft Entra ID, and assign an Intune license to every user who will enroll a device. Group-based licensing keeps assignments consistent as people join and leave.
- Confirm the MDM authority is set to Intune: New tenants have the MDM authority set to Intune automatically. Tenants that once activated Basic Mobility and Security for Microsoft 365 may show a different authority and must switch it before enrollment works. Co-managed environments with Configuration Manager also keep the MDM authority set to Intune.
- Configure enrollment prerequisites for each platform: For Windows, enable automatic enrollment by setting the MDM user scope under Devices, Enrollment, Automatic Enrollment; this requires Entra ID P1 or P2. For iOS/iPadOS and macOS, upload an Apple MDM push certificate, and add an Apple Business Manager token if you want zero-touch automated device enrollment. For Android, connect your tenant to Managed Google Play to unlock the Android Enterprise enrollment profiles.
- Create compliance policies and Conditional Access: Compliance policies define what a healthy device looks like: minimum OS version, disk encryption, password rules. Conditional Access in Microsoft Entra ID then uses each device’s compliance state to allow or block access to company resources, which is what gives enrollment its teeth.
- Add apps and configuration profiles: Deploy Microsoft 365 Apps, store apps, and line-of-business packages, and build configuration profiles for Wi-Fi, VPN, and email. Profiles that authenticate with certificates need SCEP or PKCS certificate profiles, which in turn need a certificate authority behind them: either Microsoft Cloud PKI or an on-premises CA reached through the Certificate Connector.
- Enroll devices in stages: Assign enrollment policies to a pilot group first, expand as policies prove stable, and use enrollment restrictions to control which platforms and ownership types can enroll. A standard user can enroll up to 15 devices; a device enrollment manager account can enroll up to 1,000 corporate devices for staged handout.
Where Certificates Fit in an Intune Setup
Certificates enter an Intune deployment early, because Wi-Fi, VPN, and email profiles authenticate with certificates rather than passwords.
Intune distributes certificates; it does not replace the PKI that issues them. Distribution happens through SCEP and PKCS certificate profiles, and the issuing side is either Microsoft Cloud PKI, included with Microsoft 365 E5 from July 2026, or an existing on-premises certificate authority connected through the Intune Certificate Connector. The same certificate foundation carries passwordless sign-in: Intune pushes the Windows Hello for Business configuration to enrolled Windows devices, and its key trust and certificate trust models rest on your public key infrastructure. Decide who owns that PKI, and how certificates renew, before the first SCEP profile ships, not after the first Wi-Fi outage.
Troubleshooting Common Setup Issues
Most Intune setup failures trace back to five causes: licensing, the MDM authority, missing platform prerequisites, enrollment restrictions, or an expired Apple certificate.
- Automatic enrollment settings are missing: The MDM user scope only appears for tenants with Microsoft Entra ID P1 or P2. Without it, Windows devices must be enrolled manually from Settings, Accounts, Access work or school.
- A device joins Entra ID but never appears in Intune: Either the MDM user scope excludes the user, or the user has no Intune license assigned. Check both before touching the device.
- Apple enrollment suddenly fails tenant-wide: The Apple MDM push certificate is valid for one year. Renew it before expiry, and always with the same Apple ID that created it; a new Apple ID breaks management of every enrolled Apple device.
- Android enrollment errors: Confirm Managed Google Play is connected, the device runs Android 10 or later, and the device has Google Mobile Services. Device administrator enrollment retired for GMS devices in December 2024 and is not the fallback it used to be.
- Personal devices are blocked or corporate devices misclassified: Review enrollment device platform restrictions and corporate device identifiers; the highest-priority restriction assigned to the user wins.
How Encryption Consulting Helps
PKI Services from Encryption Consulting designs and operates the certificate infrastructure that Intune’s SCEP, PKCS, Wi-Fi, and VPN profiles depend on, from CA architecture and CP/CPS development to day-to-day operations. The Microsoft PKI with Intune integration service connects a certificate authority directly to your Intune-managed device policies so certificates issue and renew automatically as devices enroll, and the Windows Hello for Business implementation service handles the trust model Intune pushes down for passwordless sign-in. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
How long does it take to set up Microsoft Intune?
The tenant itself can be ready in a day: licensing, the MDM authority, and enrollment prerequisites are portal configuration, not infrastructure. A production rollout takes longer because compliance policies, apps, and certificate profiles need testing against a pilot group before broad enrollment. Most organizations plan a phased rollout over several weeks, expanding the pilot ring as policies prove stable.
Do I need Microsoft Entra ID P1 to set up Intune?
You need Microsoft Entra ID P1 or P2 for automatic MDM enrollment of Windows devices and for Conditional Access policies. Intune itself works without P1, but users must then start enrollment manually from each device. Microsoft 365 E3, E5, Business Premium, and Enterprise Mobility + Security E3 and E5 all include Entra ID P1 or higher, so most Intune-licensed tenants already have it.
Which Microsoft licenses include Intune?
Intune Plan 1 is included in Microsoft 365 E3, E5, F1, F3, Business Premium, Enterprise Mobility + Security E3 and E5, and Microsoft 365 Government G3 and G5. It is also sold as a standalone subscription. From July 1, 2026, Microsoft 365 E3 and E5 additionally include Intune Suite capabilities such as Remote Help, with Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise App Management reserved for E5.
Do I need to set the MDM authority manually?
New Intune tenants have the mobile device management authority set to Intune automatically. Older tenants, or tenants that activated Basic Mobility and Security for Microsoft 365, may show a different authority and must switch it to Intune before devices can enroll. Co-managed environments with Configuration Manager also keep the MDM authority set to Intune.
Can I set up Intune alongside Configuration Manager?
Yes. Co-management attaches Configuration Manager to Intune so Windows devices are managed by both at once, with workload sliders deciding which tool owns compliance, updates, and apps. The MDM authority stays set to Intune even in co-management. Tenant attach is a lighter option that surfaces Configuration Manager devices in the Intune admin center for visibility and remote actions without moving workloads.
Set Up Intune on a Solid Certificate Foundation
An Intune tenant is a day’s work; the certificate infrastructure behind it decides whether the deployment holds up. Explore PKI Services, or talk to an Encryption Consulting advisor about your Intune and certificate integration before the first enrollment ring goes live.
