Intune device management — Autopilot enrolment, compliance policy, application deployment and remote wipe across company and personal devices.
What Intune is for
Two questions that used to be answered by a domain controller and a locked office, and are not any more:
Which devices are allowed to reach our data? When everything lived on the network, the answer was “the ones plugged into it”. Now your data is in Microsoft 365, reachable from any device with valid credentials — including an unpatched personal laptop with no screen lock and a browser full of extensions.
How do we get company data off a device we do not control? A laptop in the back of a taxi, a phone sold on marketplace, a contractor at the end of an engagement.
Intune answers both. Compliance policy decides what may connect; enrolment and app protection decide what can be removed.
Managed devices and protected apps
The distinction matters and is worth getting right, because applying the wrong one causes genuine friction.
Full enrolment for company-owned hardware. The organisation manages the device: configuration, applications, updates, encryption, and remote wipe of the whole thing.
App protection for personal phones. No device enrolment. Company data is controlled inside company applications — a PIN required to open Outlook, copy-paste into personal apps blocked, company data removable on demand — while the device itself, and everything personal on it, remains untouched and invisible to you.
Attempting full enrolment on staff-owned phones is where BYOD programmes get resisted, usually correctly. People do not want their employer managing their personal phone, and they are right not to.
Autopilot changes onboarding
Traditional device provisioning meant a technician imaging a machine, installing software, and either delivering it or shipping it. For a business hiring someone in another state, that meant couriering hardware to head office first.
With Autopilot, the device identity is registered at purchase. The machine ships from the supplier directly to the person. They switch it on, sign in with their work account, and it joins the tenant, applies policy, installs their applications and is ready to use.
This pairs directly with how we handle procurement, and it is what makes remote onboarding work properly rather than approximately.
Compliance is the part that gets skipped
Having the capability is not the control. The control is a policy that continuously checks encryption, screen lock, operating system version and security agent presence, and blocks non-compliant devices from company data until they are fixed.
Deployments that enrol devices but never enforce compliance are common. They give you an inventory and a remote wipe button, which is worth having, and none of the actual prevention.
Check your licensing first
Intune is included in Microsoft 365 Business Premium and in E3 and E5. It is not in Business Standard or Business Basic.
A significant number of businesses on Business Standard are paying for add-ons that Business Premium would have included, or are missing security capability they assume they have. It is worth a licensing review before buying anything.