- Key Takeaways
- The Intune Journey: From Windows Intune to Cloud-Native Management
- What Are the Different Design Models in Microsoft Intune?
- Comparison Between Intune Design Models
- How to Choose the Right Intune Design Model
- How Encryption Consulting Helps
- Frequently Asked Questions
- Design Your Intune and PKI Integration
Microsoft Intune design models are the architectural patterns for deploying Intune: cloud-native, where devices join Microsoft Entra ID and Intune is the sole management authority, and hybrid, where Intune shares management workloads with Microsoft Configuration Manager through co-management.
Microsoft Intune supports two primary design models. In the cloud-native model, devices join Microsoft Entra ID and Intune handles all management workloads. In the hybrid model, known as co-management, Intune and Microsoft Configuration Manager manage the same Windows devices, and each workload is assigned to one of the two tools.
Key Takeaways
- Microsoft Intune offers two primary design models: cloud-native, where Intune is the only management authority, and hybrid, where Intune co-manages Windows devices with Microsoft Configuration Manager.
- Legacy hybrid MDM, which connected an Intune subscription to Configuration Manager, was retired on September 1, 2019, and is not the same thing as co-management.
- Co-management arrived with Configuration Manager version 1710 in November 2017 and moves workloads such as compliance policies, Windows Update, and client apps to Intune one at a time.
- Tenant attach, added in Configuration Manager version 2002 in April 2020, uploads Configuration Manager devices to the Intune admin center without moving any workloads.
- Microsoft recommends the cloud-native model for new deployments; Windows Autopilot provisions new devices directly into Intune without imaging.
The Intune Journey: From Windows Intune to Cloud-Native Management
Microsoft Intune began as Windows Intune, released in beta in April 2010 and made generally available in March 2011 as a cloud service for managing Windows PCs. Microsoft renamed it Microsoft Intune in 2014 as Android and iOS management grew, folded it into the Microsoft Endpoint Manager brand alongside Configuration Manager in November 2019, then returned to the Microsoft Intune name at Ignite in October 2022. Today Intune manages Windows, macOS, iOS/iPadOS, Android, and Linux devices from a single web-based admin center.
Whichever design model an organization picks, an Intune rollout moves through four phases:
- Planning: Define goals, scope, and desired functionality: which platforms to manage, which identity model to use, and which workloads Intune will own.
- Deployment: Choose the design model (cloud-native or co-management), then configure enrollment, compliance baselines, and certificate profiles.
- Management: Apply policies, distribute apps, and monitor compliance from the Intune admin center.
- Optimization: Refine the configuration over time: retire redundant policies, tighten compliance rules, and, in hybrid deployments, move more workloads to Intune.
What Are the Different Design Models in Microsoft Intune?
Microsoft Intune offers two design models for managing devices: a cloud-native architecture and a hybrid architecture built on co-management. The older hybrid MDM model, which set Configuration Manager as the MDM authority for an Intune subscription, was deprecated on August 14, 2018 and retired on September 1, 2019, according to Microsoft Learn. Any hybrid design built today should use co-management, not the retired hybrid MDM connector.
Cloud-Native Architecture Model: Pros and Cons
In the cloud-native model, devices join Microsoft Entra ID, enroll directly in Intune, and receive every policy, app, and update from the Intune service. No on-premises management infrastructure is required, and Windows Autopilot can ship a new device straight from the vendor to the user, who signs in and receives the full corporate configuration without imaging.
Pros:
- Simplified Management: There are no site servers to build, patch, or back up; Microsoft operates the service and delivers updates continuously.
- Scalability: Capacity is handled by the service. Growing the estate means adding licenses and enrolling devices, not adding servers.
- Modern Provisioning: Windows Autopilot replaces imaging, so devices can be provisioned anywhere with an internet connection.
Cons:
- Limited On-Premises Control: Organizations lose Configuration Manager capabilities such as operating system deployment task sequences, and applications that depend on on-premises Active Directory may need rework.
- Feature Gaps for Complex Estates: Microsoft’s own migration guidance notes that custom task sequences, on-premises server management, and third-party software update management remain Configuration Manager strengths.
Hybrid Architecture Model (Co-Management): Pros and Cons
In the hybrid model, Windows devices carry the Configuration Manager client and are enrolled in Intune at the same time, a configuration Microsoft calls co-management. Introduced with Configuration Manager version 1710 in November 2017, co-management requires devices to have a cloud identity, either hybrid Microsoft Entra joined or Microsoft Entra joined only, and lets administrators assign each workload, such as compliance policies, Windows Update policies, or client apps, to either tool through workload sliders. Existing Configuration Manager clients joined to on-premises Active Directory must be hybrid joined before co-management is enabled; new devices provisioned through Windows Autopilot reach co-management as Microsoft Entra joined devices once Intune installs the Configuration Manager client.
Pros:
- Greater Control: Task sequences, on-premises distribution points, and granular configuration stay available for workloads with specific regulatory or operational requirements.
- Gradual Transition: Workloads move to Intune one slider at a time, so existing Configuration Manager investment keeps working while the organization shifts to the cloud at its own pace.
Cons:
- Increased Complexity: Two consoles and two policy engines manage the same devices, so workload assignments need careful planning to avoid conflicting policies.
- Resource Requirements: Site servers, distribution points, and SQL infrastructure still need hardware, licensing, and staff to run.
A third option, tenant attach, sits between the two models. Added in Configuration Manager version 2002 in April 2020, tenant attach uploads Configuration Manager devices to the Intune admin center so administrators can view them and run actions from the cloud console, without enrolling the devices in Intune or moving any workloads.
Comparison Between Intune Design Models
The right Intune design model depends on how much on-premises control an organization needs and how quickly it wants to reach the cloud.
| Attribute | Cloud-Native Model | Hybrid Model (Co-Management) |
| Management Authority | Intune only | Intune and Configuration Manager, assigned per workload |
| Identity model | Microsoft Entra joined | Hybrid Microsoft Entra joined for existing clients; Microsoft Entra joined supported through the Autopilot path |
| Organizational Control | Suits organizations that run most operations on cloud services | Retains granular control over on-premises resources and task sequences |
| Scalability | Handled by the service; grows with licenses and enrollment | Bounded by on-premises site servers and distribution points |
| Compliance | Fits requirements that cloud controls can satisfy | Fits mandates that require on-premises control of specific data or processes |
| Resource Allocation | No management servers to maintain | Hardware, licensing, and staff needed for Configuration Manager infrastructure |
| Provisioning | Windows Autopilot, no imaging | Operating system deployment task sequences and imaging |
How to Choose the Right Intune Design Model
Choose cloud-native if you can; choose co-management if existing infrastructure or control requirements will not let you get there yet. Cloud-native is the destination Microsoft is building toward, and co-management is the bridge for organizations that cannot cross in one step.
New deployments, smaller estates, and geographically dispersed workforces fit the cloud-native model, since every device only needs an internet connection to be managed. Organizations with a large Configuration Manager estate, imaging-based provisioning, or sites with restricted connectivity fit co-management, sliding workloads to Intune as constraints fall away.
Both models depend on certificates for Wi-Fi, VPN, and passwordless authentication. Intune deploys these through SCEP and PKCS certificate profiles backed by a certification authority, or through Microsoft Cloud PKI, an Intune Suite add-on released in February 2024. A working grasp of how PKI issues and validates certificates makes either design model easier to secure. For a grounding in the platform itself, see our Introduction to Microsoft Intune.
How Encryption Consulting Helps
Encryption Consulting’s PKI Services design and deploy the certificate infrastructure that Intune-managed devices rely on, from SCEP and PKCS certificate profiles to the certification authorities behind them. Our Windows Hello for Business implementation service builds passwordless sign-in on top of Intune-managed devices, while PKI-as-a-Service delivers managed PKI without on-premises overhead, a natural fit for cloud-native deployments. CertSecure Manager then automates the lifecycle of every certificate your Intune profiles issue, so expirations never take down Wi-Fi or VPN access. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
What is the difference between co-management and tenant attach?
Co-management enrolls a Windows device in both Configuration Manager and Intune and assigns each management workload to one of the two tools. Tenant attach only uploads Configuration Manager devices to the Intune admin center so administrators can view them and run actions from the cloud console. Tenant attach devices are not enrolled in Intune, and no workloads move.
Is hybrid MDM still available in Microsoft Intune?
No. Hybrid MDM, the legacy model that set Configuration Manager as the MDM authority for an Intune subscription, was deprecated on August 14, 2018 and retired on September 1, 2019. Devices left on hybrid MDM stopped receiving policy, apps, and security updates. Organizations that want to use Configuration Manager and Intune together should use co-management instead.
Which Intune design model does Microsoft recommend?
Microsoft’s migration guidance points new deployments to the cloud-native model, with devices joined to Microsoft Entra ID and managed only by Intune. Co-management is positioned as the path for organizations with existing Configuration Manager infrastructure, letting them move workloads such as compliance policies and Windows Update to Intune one at a time.
What identity model does each Intune design model use?
Cloud-native devices are Microsoft Entra joined, so they authenticate directly against Microsoft Entra ID with no dependency on on-premises Active Directory. Co-managed devices need a cloud identity in one of two forms. Existing Configuration Manager clients must be hybrid Microsoft Entra joined, meaning joined to on-premises Active Directory and registered in Microsoft Entra ID. Devices provisioned through Windows Autopilot can instead be Microsoft Entra joined only.
Can Intune deploy certificates without an on-premises PKI?
Yes. Microsoft Cloud PKI, an Intune Suite add-on released in February 2024, issues and manages certificates from the cloud without on-premises certification authority servers. Organizations with an existing PKI can instead use Intune SCEP or PKCS certificate profiles, which connect Intune to a certification authority through the Certificate Connector.
Design Your Intune and PKI Integration
Picking a design model is the first step; giving those devices trusted identities is the second. Explore PKI-as-a-Service for managed certificate infrastructure that fits either model, or talk to an Encryption Consulting advisor about integrating PKI with your Intune deployment.
- Key Takeaways
- The Intune Journey: From Windows Intune to Cloud-Native Management
- What Are the Different Design Models in Microsoft Intune?
- Comparison Between Intune Design Models
- How to Choose the Right Intune Design Model
- How Encryption Consulting Helps
- Frequently Asked Questions
- Design Your Intune and PKI Integration
