- Key Takeaways
- Mobile Device Management (MDM)
- Mobile Application Management (MAM)
- Conditional Access
- Endpoint Security
- Microsoft 365 Integration
- Monitoring and Compliance Reporting
- Windows Autopilot
- How Encryption Consulting Helps
- Frequently Asked Questions
- Secure the Identities Behind Your Intune Deployment
Microsoft Intune is Microsoft’s cloud-based endpoint management platform, combining mobile device management (MDM) and mobile application management (MAM) to secure phones, tablets, and PCs from a single admin console.
Microsoft Intune’s core features are device management for enrolling and configuring hardware, app protection policies for securing corporate data without full device enrollment, Conditional Access tied to Microsoft Entra ID, Microsoft Defender-based endpoint security, deep Microsoft 365 integration, compliance reporting, and Windows Autopilot for zero-touch provisioning. Together, these features let IT teams manage a mixed fleet of company-owned and personal devices from one place.
Key Takeaways
- Intune combines MDM (managing the whole device) and MAM (protecting data inside specific apps), so IT can secure both corporate and personal devices.
- Conditional Access policies use Microsoft Entra ID sign-in data to block or allow access based on device compliance, location, and risk.
- Intune integrates natively with Microsoft Defender for Endpoint for real-time threat detection and response.
- Windows Autopilot device preparation, generally available since June 2024, replaces manual imaging with a policy-driven, zero-touch setup flow for Windows 11 devices.
- Every Intune feature depends on the certificates and identities issued by the organization’s PKI; weak certificate practices undermine even a well-configured Intune deployment.
Mobile Device Management (MDM)
Mobile device management lets Intune enroll, configure, and monitor smartphones, tablets, and PCs running iOS, iPadOS, Android, Windows, and macOS. Organizations can enroll both company-owned hardware and personal devices used for work under a Bring Your Own Device (BYOD) policy.
Once a device is enrolled, administrators can:
- Create and enforce configuration profiles that control device settings, encryption, and password requirements.
- Deploy, update, and remove apps on managed devices, keeping app versions consistent across the fleet.
- Apply compliance policies that flag devices as noncompliant if they fall out of policy, such as a missing PIN or a disabled encryption setting.
- Perform remote actions, including full wipe, selective wipe of corporate data only, and remote lock, when a device is lost or an employee leaves.
- Push OS updates and security patches on a managed schedule instead of relying on users to install them manually.
Mobile Application Management (MAM)
Mobile application management protects corporate data inside specific apps without requiring full device enrollment, which matters for contractors and BYOD users who will not enroll a personal phone. App protection policies can require a separate PIN to open a managed app, encrypt app data at rest, and block copy-paste or “save as” actions that would move corporate data into an unmanaged app. If an employee leaves the organization, IT can wipe the corporate data inside the managed app and leave personal photos, messages, and apps untouched.
For a full comparison of when to use MDM versus MAM and how Intune licensing maps to each, see EC’s introduction to Microsoft Intune.
| MDM (device management) | MAM (app protection) | |
|---|---|---|
| What it controls | The whole device: OS settings, encryption, updates | Corporate data inside managed apps only |
| Enrollment required | Yes, the device enrolls in Intune | No device enrollment needed |
| Typical use | Company-owned hardware | BYOD phones, contractors |
| Wipe behavior | Full wipe or selective wipe of the device | Wipes corporate app data, leaves personal data untouched |
Conditional Access
Conditional Access ties resource access to real-time signals about the user and device, evaluated through Microsoft Entra ID (formerly Azure Active Directory). Administrators build policies in the Microsoft Intune admin center or the Microsoft Entra admin center that grant, block, or restrict access based on conditions rather than a one-time login check.
Common Conditional Access controls include:
- Requiring multi-factor authentication (MFA) before granting access to sensitive apps.
- Allowing access only from devices marked compliant by Intune, such as devices with disk encryption and an up-to-date OS build enabled.
- Blocking access entirely from unmanaged devices or specific geographic regions.
- Requiring an Intune app protection policy, so data can only be opened through apps governed by an active app protection policy. This grant replaced the older “Require approved client app” control, which Microsoft retired on June 30, 2026.
Because these policies check device compliance at every sign-in, Conditional Access is one of the sub-questions covered in EC’s Windows Hello for Business article, since WHfB’s certificate-based sign-in feeds directly into how Entra ID evaluates device trust.
Endpoint Security
Intune extends beyond mobile devices to manage and secure Windows PCs and Macs as full endpoints. It integrates with Microsoft Defender Antivirus for real-time malware protection and lets administrators configure and monitor antivirus settings centrally from the Intune admin center.
Security baselines let organizations apply pre-configured, Microsoft-recommended settings for Windows Defender Firewall, antivirus, and other security controls in a few clicks instead of building policies from scratch. Intune also integrates with Microsoft Defender for Endpoint, part of the Microsoft 365 security stack, to bring endpoint detection and response (EDR) signals into the same console used for device management, so a compliance failure and a security alert can be investigated side by side.
Microsoft 365 Integration
Intune is built to work with Microsoft 365 rather than sit beside it. Devices enrolled in Intune get single sign-on across Microsoft 365 services once a user authenticates through Microsoft Entra ID, so employees are not repeatedly prompted for credentials across Outlook, Teams, and SharePoint.
Intune and Microsoft 365 also power Windows Autopilot together (covered below) and share the same Microsoft Entra ID directory for identity and group management, which keeps user and device identity consistent across the two services instead of maintaining separate directories.
Monitoring and Compliance Reporting
Intune generates compliance reports showing which devices meet the organization’s policies and which do not, giving administrators a direct list of devices that need attention rather than a general risk score. Device configuration reports track which settings have actually applied to each device, which is useful for confirming a policy rollout worked as intended rather than assuming it did. These reports run continuously in the background, so a device that falls out of compliance after an update or a disabled setting shows up on the next reporting cycle, not weeks later during an audit.
Windows Autopilot
Windows Autopilot simplifies the Windows device lifecycle from initial deployment to retirement by replacing manual imaging with policy-driven, self-service setup. A user can unbox a new device, connect it to the internet, and have Intune apply the organization’s apps, settings, and security policies automatically during the out-of-box experience (OOBE).
Windows Autopilot device preparation, Microsoft’s newer provisioning flow, reached general availability in June 2024 and is available only on Windows 11 (version 22H2 or 23H2 with the April 2024 update KB5035942, or version 24H2 and later), per Microsoft’s device preparation documentation. It only supports Microsoft Entra join (not hybrid join), adds each device to a pre-created device security group at enrollment time so configuration is delivered immediately, and gives administrators near real-time deployment status instead of finding out about a failed provision after the fact. The original Windows
Autopilot profile flow, which supports hybrid Entra join and self-deploying mode, continues to run alongside device preparation; Microsoft has not announced a migration deadline between the two.
How Encryption Consulting Helps
Intune enforces the policy, but the certificate proves the device. Every Conditional Access decision, Wi-Fi profile, and Windows Hello sign-in behind an Intune deployment traces back to certificates issued by the organization’s PKI.
PKI Services from Encryption Consulting help organizations design and operate the certificate infrastructure that Intune’s Wi-Fi, VPN, and S/MIME email profiles depend on, including CP/CPS development and day-to-day certificate authority operations. For organizations extending Intune-managed devices into certificate-based sign-in, EC’s Windows Hello for Business implementation service handles the certificate trust or cloud Kerberos trust model that Intune pushes down as a device configuration profile.
Encryption Consulting also offers Microsoft PKI with Intune integration, connecting a certificate authority directly to Intune-managed device policies so certificates renew automatically as devices enroll, and PKI-as-a-Service for organizations that want managed, cloud-hosted PKI without operating their own CA infrastructure. All engagements are backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
What is the difference between MDM and MAM in Microsoft Intune?
MDM manages the entire device, including OS settings, enrollment, and remote wipe, and is typically used for company-owned hardware. MAM protects corporate data inside specific apps without enrolling the whole device, which fits BYOD and contractor scenarios where the organization does not own the hardware.
Does Microsoft Intune require Microsoft Entra ID?
Yes. Intune relies on Microsoft Entra ID (formerly Azure Active Directory) for user authentication, group membership, and identity data. Conditional Access policies, single sign-on across Microsoft 365, and Windows Autopilot’s Entra join step all depend on the same Entra ID directory.
What is Windows Autopilot device preparation?
Windows Autopilot device preparation is a policy-driven provisioning flow that reached general availability in June 2024. It applies apps, scripts, and configurations automatically during a Windows 11 device’s out-of-box experience, using Microsoft Entra join and a pre-created device security group that the device joins at enrollment time.
Can Intune manage personal devices as well as company-owned ones?
Yes. Intune supports Bring Your Own Device (BYOD) enrollment for full MDM, and app protection policies (MAM) for organizations that want to protect corporate data on a personal device without enrolling the device itself.
Does Intune replace antivirus software?
Intune does not replace antivirus software; it manages and monitors it. Intune integrates with Microsoft Defender Antivirus and Microsoft Defender for Endpoint so administrators can configure protection settings and view threat detection alerts from the same console used for device management.
Secure the Identities Behind Your Intune Deployment
Intune’s device and app policies are only as strong as the certificates and identities behind them. Explore PKI Services to see how Encryption Consulting designs and operates the certificate infrastructure your Intune policies depend on, or talk to a PKI expert about your specific Intune and certificate integration questions.
