No more typing reviews! Try our Samantha, our new voice AI agent.
Consultant at a manufacturing company with 1,001-5,000 employees
Real User
Sep 11, 2024
The enterprise application management feature is excellent
Pros and Cons
  • "What I like most about Intune is its seamless enrollment process, particularly the Autopilot method."
  • "The worst aspect is the reporting."

What is our primary use case?

I have worked on multiple projects during these four years and encountered various scenarios with Intune. The major issue I found is Intune's vastness; it has numerous features within a single MDM portal. We can deploy unlimited features from the Intune portal to manage devices and protect the environment. Intune's capabilities are extensive, but there is room for improvement in certain areas, particularly reporting. Intune's reporting functionality is still under development, and we can anticipate further advancements in this area.

I previously worked as a solution engineer and am currently a call center agent in IT. I have worked on all sorts of Intune-related issues, including those related to mobile devices, Windows devices, enrollment processes, and policies. My expertise includes Autopilot, GP enrollment, the enrollment process for Windows, iOS, and mobile devices, as well as configuration profiles for multiple devices and platforms. I have also worked on scripts. As an escalation engineer, I have dealt with a wide variety of user issues.

The primary benefit of implementing Intune is the ability to manage devices, including controlling access, deploying applications, and enforcing restriction policies. As administrators, we gain control over which applications and websites users can access on their devices. Additionally, we can seamlessly deploy applications and configure network settings according to our organization's or client's specific requirements. Intune enables us to manage devices, deploy applications, and enforce policies, ensuring that devices within our environment adhere to our company's standards.

My deployment is primarily cloud-based, but I also have knowledge of hybrid environments. I have limited on-premises experience, having only observed local Active Directory servers. I can configure them theoretically, but I wouldn't consider myself a trained engineer in that area. With hybrid environments, I understand how to implement and integrate the hybrid components with Intune for a seamless and error-free deployment.

How has it helped my organization?

We can integrate endpoints directly into Intune, enabling us to access the options on the Intune portal. Intune is a seamless feature that collaborates with various services within the Azure ecosystem, essentially relying on Azure for its functionality. An essential collaboration exists between Azure AD and Intune. Similarly, Defender, another Microsoft service, must be integrated with Intune to remediate threats. In essence, Intune is a unique entity that requires communication with other Azure services. Configuration and connectivity are necessary to achieve this integration. Once integrated, we can access other endpoints directly from the Intune portal.

The user interface is straightforward, and the configuration profiles are easily accessible to the administrator. There are multiple ways to implement a single setting or policy on a device, including the deployment of several policies. A new feature allows for the creation of policy sets that can be deployed to different locations within an organization, streamlining management for administrators across multiple regions. This is a valuable feature that saves time and increases efficiency. Policy sets can be created, and locations can be assigned to them, ensuring that any enrolled device or user within that location receives the predefined policies. Group tags further enhance this process by automatically applying policy sets to devices or users added to specific group tags. Overall, Intune offers numerous features that enhance administrator productivity, including the ability to efficiently manage and track policy deployments.

The enterprise application management feature is excellent. If we've deployed applications using the application management services, we can provide updates directly, eliminating the need to repackage them. With application management, if an application is deployed in a region with multiple devices, those applications automatically update once an update is available. It's one of Intune's best features and was recently integrated. While I need to explore it further, I've previously used it to deploy applications in a region, and any auto-updates from the store were applied seamlessly. This is a significant benefit of Intune.

The PKI process in Intune is excellent, though it can be complex for administrators. Intune's reporting has improved since last year's changes, and removing one PKI component has simplified the troubleshooting log collection. Once correctly configured, this reliable feature allows direct certificate deployment to users and devices, eliminating the need for constant password and user ID entry. Users can seamlessly log in with their certificate across various applications, such as email or VPN profiles, enhancing convenience and security. Overall, Intune's PKI capabilities significantly benefit streamlined authentication and access management.

How we use Copilot depends on the specific needs of the enterprise. For clients with an existing on-premises environment, which typically includes multiple servers and domain controllers, there's often a gradual desire to migrate to the cloud. In these cases, we recommend Copilot, where we can implement an Intune environment and facilitate the gradual transition of devices from SCCM to Intune. These scenarios represent the primary use cases for deploying Copilot for device management, as it offers an optimal solution for managing devices during the on-premises to cloud transition. For remote users unable to access the physical office, device enrollment ensures cloud-based management. In contrast, restricted environments necessitate on-site presence. While VPN offers an interim solution, enabling remote device management through on-premises connectivity, it incurs additional costs. Ultimately, we advocate for cloud adoption as a cost-effective and simplified approach to device management, aligned with the ongoing evolution towards cloud-based solutions.

Intune has significantly improved our organization. Firstly, it allows users to work securely from anywhere, as the device is managed and policies, settings, and restrictions are deployed over the cloud, regardless of the location. Additionally, we can deploy various policies and regulations for security, simplifying device management. From an admin perspective, Intune streamlines device management by allowing us to simultaneously deploy policies to multiple devices. Enrollment is also effortless, as devices can be shipped directly from the vendor to the user and ready for use. This eliminates the previous admin tasks of deploying custom OS images and managing policies via SSCM, ultimately improving productivity.

Intune's ability to secure hybrid work and protect data on company and BYOD devices involves security restriction and conditional access policies. These settings provide significant device security. For instance, we have unconditional access policies and app protection policies. These policies allow us to secure data users might share with other devices or native applications. With conditional access, we can require devices to be managed by Intune before accessing corporate data, ensuring they receive necessary restriction and protection policies to prevent sharing corporate data with unauthorized applications. This significantly enhances corporate data security. While user agents offer data security benefits, Microsoft Defender and Office 365's data loss prevention policies strengthen our overall protection.

Intune has helped save 90 percent of our costs.

The security provided by Intune is excellent. The security policies deployed through Intune significantly enhance device security, encompassing data protection, device restrictions, Wi-Fi settings, and proxy configurations. Additionally, Intune can deploy antivirus software if we have the appropriate licenses, further bolstering security. Overall, I'd estimate that Intune provides roughly 80 percent reliability in terms of security.

Intune's ability to integrate with Microsoft 365 and Microsoft Security for both cloud and co-managed devices is crucial because, in isolation, Intune is limited. To make its features work reliably and meet specific requirements, integration with Office 365, Defender, and local AD is necessary. This integration enhances security on devices and enables advanced features like data loss prevention through Office 365. While Intune offers security policies, integration with Office 365 unlocks their full potential for comprehensive device protection.

What is most valuable?

What I like most about Intune is its seamless enrollment process, particularly the Autopilot method. Autopilot allows bulk enrollment of devices, making it easy for end users, even those without technical expertise, to use their devices immediately. While there might be occasional error messages during configuration, when done correctly by the administrator, Autopilot is the best feature currently available.

Intune is excellent. It is constantly evolving, from the legacy portal to the current endpoint management; we are seeing a gradual number of changes, and many features have been implemented and added to the Intune portal. The interface is great and user-friendly. Even someone without much MDM experience but needing access to the Intune portal would be able to understand that these are Windows devices and these are the policies they can deploy. The portal's overall UI is user-friendly. Furthermore, the categorization of devices and policies on the portal is excellent. We can categorize devices, look for conditional access, and check for configuration compliance in a specific location. The categorization is the best way currently available.

What needs improvement?

The worst aspect is the reporting. We are still in the development phase of reporting, and it is not always accurate. Sometimes, we don't receive the correct report, devices aren't listed as they should be in the Intune portal, or deployed applications and user policies aren't reported by Intune even though they are present on a device. There is room for improvement in Intune's reporting capabilities.

If my organization has sensitive data we don't want to leak, deploying the policies can present technical challenges and potential loopholes. While 90 percent of end-users are not technical enough to find these loopholes, a user trained on Intune who understands the background processes and policy weaknesses could pose a security risk to the organization.

App protection policy and compliance state. Recently, I encountered a user scenario similar to one I've experienced as an administrator. If my device is enrolled in Intune but not through a corporate method, some loopholes allow administrative control of the device itself. We can un-enroll the device and remove the management profile, yet the Intune portal will still show the device as compliant because it captured the last compliance state. As long as the device reports to Intune, its compliance status in the portal remains unchanged, regardless of its actual state. Only when the device stops checking in with Intune will the last compliant state be displayed, with no indication of non-compliance. The device's Intune compliance state will show the last check-in time. We can leverage the newly integrated data loss prevention feature in Intune to improve the app protection policy, which is currently inconsistently effective. With the appropriate licensing, deploying data loss prevention policies can enhance our protection strategy.

I need to delve into reporting and analytics. The policies, restriction policies, enrollment limitations, and everything else are great. However, one current limitation is that we can't roll back security baseline policies deployed from the Intune portal to a device. Those changes are permanent if a security policy changes the device's registry. If an administrator mistakenly deploys settings from a baseline policy instead of a restriction policy, the only recourse is to reimage the device. In my opinion, baseline settings shouldn't be permanent. However, as developers of the Intune portal, there must be some significance to these clients.

Buyer's Guide
Microsoft Intune
September 2026
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Intune for four years.

What do I think about the stability of the solution?

I would rate the stability of Microsoft Intune seven out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Microsoft Intune eight out of ten.

How are customer service and support?

I was the Microsoft Intune Closure Engineer, working in a global support group. My role involved providing solutions for Microsoft, addressing tickets created by users or administrators worldwide. I would rate the overall Microsoft support an average of eight out of ten. The support process begins with a ticket being assigned to a junior engineer with basic understanding, which I'd rate a six. If the user's issue remains unresolved, it escalates to a level two engineer, improving the rating to an eight. In rare cases, unresolved issues are escalated to a senior engineer which would drive the rating up to nine out of ten.

Which solution did I use previously and why did I switch?

Before Intune was introduced, we had to use Office 365 for MDM, which had limited options. Then came the legacy Intune portal, followed by the endpoint management folder, the most recent portal we've used. I've also used Jamf and AirWatch a bit, but I'm not as proficient with them as with Intune.

How was the initial setup?

The initial deployment of Intune was complex, with deployment time dependent on the specific environment. For organizations with multiple sites, Intune deployment is particularly challenging and can take four to five months. The migration itself is not a simple task and can be time-consuming. Based on past experience, assessing existing security policies and applications from the on-premises environment is crucial before identifying what can be achieved with Intune, given its limitations compared to SCCM. While Intune can replicate some functionalities achieved through group policies, the migration process can still take a considerable amount of time, ranging from seven to eight months to even one and a half years, depending on the environment's complexity.

What's my experience with pricing, setup cost, and licensing?

Microsoft licenses are costly. Organizations should determine the best license to get the maximum features based on their requirements. Intune comes with multiple licenses, including E3, E5, standalone Intune, and a few more. Microsoft 365 is also an option. There are almost seven license lists where Microsoft Intune is present, except for the standalone license. It's definitely costly. Microsoft could look further into providing some cost-cutting measures for the licenses.

What other advice do I have?

I would rate Microsoft Intune eight out of ten.

Intune includes various features and categories, allowing management of operating systems like Linux, Windows, iOS, macOS, and Android. Its user interface, departmental organization, and enrollment process are all straightforward. However, based on my six years of experience with Microsoft products, including four years specifically with Intune, its reliability is around 80 percent. Occasionally, it doesn't report correctly, or devices fail to receive deployed configurations. In comparison, AirWatch seems more reliable. Despite this, considering my overall experience with Microsoft, it still offers one of the best management solutions. Intune's predecessor, SCCM, which manages devices on-premises, is more reliable because Intune is still developing.

I'm working on two accounts. Under one account, I have a growing number of devices. So far, there are approximately 300,000 Windows devices, 100,000 Android devices, and 250,000 iOS devices in one environment. The number of users is similar. In another environment, which I've been using, there are a large number of devices. It's taking time to load, but I would say there are approximately 400,000 to 500,000 Windows devices in this environment.

Intune is continually evolving. If a feature is currently unavailable or needs improvement, we typically provide feedback to the Intune development team, and they implement or enhance that feature in a future release. In new releases, developers add features, and if there's a need to further develop or enhance those features, we see those improvements in subsequent releases. Maintenance on the Intune portal is necessary to facilitate these dynamic changes. Additionally, the Intune environment itself requires maintenance. This includes managing user accounts and enrolled devices, as well as adjusting restriction and security policies as needed.

I recommend Intune because it offers multiple features within a single environment. Once deployed, you can manage iOS and other platforms from one location. However, there's a caveat: if you have a highly restricted or complex environment where security is paramount, such as in banking, federal agencies, or similar organizations, you might reconsider using Intune due to potential reliability concerns.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Director of Technology at a hospitality company with 51-200 employees
Real User
Top 5
Jul 31, 2025
Remote device management and customization enhance operational efficiency
Pros and Cons
  • "Microsoft Intune does help me save time in terms of management of various devices—I don't have to go to those locations to manage the devices at those locations, I can do it remotely, which is very helpful."
  • "It isn't easy to use. It's very complicated, but as long as you take the time to learn it, you can do just about anything you want with your device."

What is our primary use case?

Our main use case for Microsoft Intune is to manage some devices, and we haven't switched over to all of our devices yet. We've been testing it out for the last year to see how it manages devices, mainly tablets and some laptops. It's been a good experience and I have no complaints with it. It's not as easy as maybe some other products, but it is a lot more flexible. Overall, it's a very good product.

How has it helped my organization?

Microsoft Intune does help me save time in terms of management of various devices. We used to have five locations, and now we have three. I don't have to go to those locations to manage the devices at those locations. I can do it remotely, which is very helpful. It saves me a lot of time and trouble that I don't have to go to those locations to manage those devices.

We are using some of the advanced endpoint analytics in Microsoft Intune. For example, I can see what software is on each machine or device. I can see its usage, device specifications, all of that. So that's a good feature of it. We haven't really had to use it too much because we've just been trying to get our feet wet and make sure we understand what's going on and what it's doing over the past year.

What is most valuable?

The features I appreciate most about Microsoft Intune include the customization, where I can set up different profiles for different types of devices and configure those devices remotely and send it out to various devices. We have tablets in several locations and we can customize those tablets to do what we want at each location because each location is a little different. That makes it very useful.

What needs improvement?

It isn't easy to use. It's very complicated, but as long as you take the time to learn it, you can do just about anything you want with your device. It depends on your technical expertise. Anybody who's been a systems admin shouldn't have any problem with it. A casual user, the accidental techie, would have a problem with it; but it's not for those scenarios.

For how long have I used the solution?

I have used Microsoft Intune for about a year.

What do I think about the stability of the solution?

I assess the stability and reliability of Microsoft Intune overall as very good. It's a Microsoft product; it's stable, it works efficiently, subject to Microsoft interruptions, which we personally haven't experienced any. It's a cloud product, so you are at the mercy of the cloud.

What do I think about the scalability of the solution?

I expect Microsoft Intune to scale very efficiently with our growing needs. I haven't had any issues adding devices or laptops at this point, and we use Active Directory or Microsoft Entra. It integrates very efficiently with that. Of course, it's a Microsoft product, so it's been helpful. I have no complaints at this point.

How are customer service and support?

I would rate Microsoft's support or customer service for Microsoft Intune an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Microsoft Intune, we were using Miradore Mobile Device Management for our mobile phones. We're trying to consolidate everything into one solution.

The main factors that led us to consider the change to Microsoft Intune include our use of many different software to manage various things, and we're trying to consolidate our software and consolidate where we have to go to do different things.

How was the initial setup?

I had no problems deploying it. For me, it was pretty simple, and we don't have a large number of devices on it yet. We've just been evaluating it for the past year or so in terms of how it works with the devices. We also have Macs, and we only put it on one Mac, which was fine. Microsoft has increased its compatibility with Macs, so that's been helpful.

We did not purchase Microsoft Intune through the AWS Marketplace; we did that through a company called Insight, and it was part of our Microsoft subscription package and Azure package. They just added it in there.

What was our ROI?

We haven't had to pay for it; there has been no investment, just in terms of my time. If you're not a nonprofit, then you're going to pay whatever Microsoft is charging for it.

It does help me save time in terms of management of various devices. I don't have to go to different locations to manage the devices at those locations. 

What's my experience with pricing, setup cost, and licensing?

Because of our nonprofit status, we get things at a significant discount, so we haven't had to spend anything for Intune at this point.

What other advice do I have?

We haven't had any anomalies in endpoints with Microsoft Intune as of yet, but I imagine that will come up as we expand. We are in the process of opening a new museum, so a lot of our focus is purely on that at this point.

I would rate Microsoft Intune an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Intune
September 2026
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
System Administrator at Innover Digital
Real User
Top 10
Jul 30, 2025
Cloud-based system integrates well with on-premise resources and allows comprehensive device management but lacks server management features
Pros and Cons
  • "It's cloud-based with no need for on-premise infrastructure, you can access it anywhere and start working on it, and you will have the record of data in your hand anytime if you need it quickly."
  • "One thing I would suggest is that servers are not getting managed through Microsoft Intune."

What is our primary use case?

I have used Microsoft Intune for six months. I used it for MDM solution and MAM, but for the packaging, Autopilot configuration, compliance profiles, compliance policy creation and configuration profile creation, I worked for six months because we were moving assets from SCCM to Microsoft Intune. It was a migration project where I was part of the team. In that project, I worked on the packaging side where I was responsible for creating new packages that were already present on SCCM for laptops. The main use cases for Microsoft Intune are for compliance policy deployment and application deployment for laptops.

How has it helped my organization?

I assess the user experience of Microsoft Intune as good. It's cloud-based with no need for on-premise infrastructure. You can access it anywhere and start working on it. You will have the record of data in your hand anytime if you need it quickly. The benefits that Microsoft Intune brings depend on what you are using. It's directly integrated with Azure AD. If you are using on-premise Active Directory, there is a process to integrate easily and use those resources. This tool works beyond the boundary, which is why organizations use it.

What is most valuable?

What I appreciate about Microsoft Intune are the detection method and the supersedence option, dependencies we can add on, and multiple software we can install with a single package. That's a plus point inside the solution. It's directly integrated with Azure AD, and if you are using on-premise Active Directory, there is a process to integrate easily and use those resources.

What needs improvement?

I haven't worked extensively with Microsoft Intune to identify many areas for improvement. However, one thing I would suggest is that servers are not getting managed through Microsoft Intune. If that feature would be added, everything would be improved.

For how long have I used the solution?

I have used Microsoft Intune for six months.

What do I think about the stability of the solution?

When it comes to the stability and reliability of Microsoft Intune, I don't hear about any downtimes, crashes, or performance issues because it's server-based and those are managed by Microsoft only.

Which solution did I use previously and why did I switch?

We can discuss Microsoft solutions, Intune or SCCM.

How was the initial setup?

When implementing Microsoft Intune in my environment, it was straightforward. It's not as complex as other tools. It's easy to learn things, and I could easily work on it.

What about the implementation team?

I was part of a team working on a migration project where we were moving assets from SCCM to Microsoft Intune. I worked on the packaging side where I was responsible for creating new packages that were already present on SCCM for laptops.

What was our ROI?

Everything about ROI and measurable benefits in terms of time saving, cost saving, and resource saving depends on the organization and their requirements. Products get acquired based on requirements. If you have maximum servers, you will go with a solution that patches the software most frequently and is good with compliance. If you are going to manage only laptops and workstations, you should go with a solution that is easy and very low cost to manage.

What's my experience with pricing, setup cost, and licensing?

I don't have any information about the pricing of Microsoft Intune.

Which other solutions did I evaluate?

Regarding the key differences between Microsoft Intune and JAMF or Ivanti products, there are many things increasing inside Ivanti now. They are working on the cloud part and coming up with new features. I haven't worked on the new features and updates, so I cannot share much experience on that part.

What other advice do I have?

My advice to others considering Microsoft Intune for their organization depends on the infrastructure they have in place. Based on that, they can determine if Microsoft Intune will be best for them. If they are going to manage laptops and desktops only, it will be beneficial for them. They can apply MDM and MAM on those devices if there are few and remote devices. Laptop, iPad, mobiles, Android, iOS, everything can be managed through it. MacOS and Linux can also be managed. On a scale of 1-10, I rate Microsoft Intune a 7 out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mohammed-Azam - PeerSpot reviewer
Technical Consultant at Stefanini North America and APAC
Real User
Top 5
Jul 11, 2025
Effective management of diverse devices with strong security features
Pros and Cons
  • "Microsoft Tech Support is good, providing solid support."
  • "The granular support for other device types in Microsoft Intune could be improved."

What is our primary use case?

The main use cases for Microsoft Intune are to manage all types of devices, especially Windows.

What is most valuable?

The selling points for Microsoft Intune are very good. You don't have to enroll the devices, however, you can still push an app through some policy and with a few restrictions. If you want to push one single app to end-user devices, once you push it, you can also push it along with the security that they cannot copy your data or misuse it. This is one of the key benefits.

Microsoft Intune can be used with co-management. There are clients who don't fully want to go with Microsoft Intune as they are already spending with SCCM or other platforms. They want to partially transition into Microsoft Intune, then later fully transition into it. That's when the co-management works, and that feature is available in Microsoft Intune.

The user experience of Microsoft Intune is good. It's a very old tool, and many engineers are available in the market. There are multiple knowledge articles and videos about this tool. The user experience is good since users understand their path and how to proceed. If users understand that, it's easy for them. In that way, it deserves ten out of ten as users know how to work on this tool.

Everything has remained the same in terms of Enterprise Application Management in Microsoft Intune. App discovery still requires user initiation for installation, whereas auto-installations occur silently and remain on the device screen.

The PKI tool is cloud-based, and they are doing excellent work. In terms of complexity, they reduce the task. You cannot keep giving certificates to all the devices one by one, and the PKI tool handles that. They provide the certificate and stamp on it for the device seamlessly, so you never know the device is secured with this type of certificate.

What needs improvement?

The granular support for other device types in Microsoft Intune could be improved. Microsoft Intune works well with Windows, however, we are not as well-suited for Mac devices. If you're looking to support Mac, consider other products such as AirWatch or Jamf. MobileIron is not that effective. That said, Jamf is good for Mac. Microsoft Intune offers numerous features for Windows, allowing for substantial customization; however, for Mac, it lacks this capability.

In the next releases of Microsoft Intune, a feature to renew the certificate automatically would be beneficial. Currently, for Wi-Fi certificates, we need to do it manually, which can cause most devices to disconnect and reconnect, resulting in big issues for clients facing connectivity problems. The renewal should happen automatically, and that is something they need to work on.

For how long have I used the solution?

I have been working with Microsoft Intune for approximately five to six years.

How are customer service and support?

Microsoft Tech Support is good, providing solid support. That said, it often depends on the representative. There are levels of support; level two and level three offer great assistance, while level one primarily collects data and doesn't provide as great of support.

How would you rate customer service and support?

How was the initial setup?

The deployment is okay. It depends, from client to client. It's not like every console needs some time for deployment. So for example, if you're already on the on-prem margin of Intune, then we have a certified vendor who would deploy in the initial phase. I'm talking about initial deployment, where you configure Intune, you log in to a new Intune, and then you add users, and then you add the devices and things like that. So the initial deployment for that, we have certified vendors. Even our company is a certified company that does this deployment. We have certain tools for direct migration. However, if you're trying to deploy from a different console, like AirWatch or a mobile app or things like that, it may take maybe three months, for example. We need to be ready with all the profiles. We need to be ready with all the products. We need to be ready with all the app deployments. We need to be ready with multiple things. That way, once the device is enrolled, it gets what it needs. It gets the certificate. It gets the apps, and the user experience is seamless. 

Obviously, it needs some time. We have worked on two clients and it takes three months minimum.

What was our ROI?

The cost-effectiveness of Microsoft Intune is about 90%. Most clients, specifically with Windows devices, adopt it, so it's effective. The licensing model has advantages, as they bundle services such as Azure AD with Office 365, which many clients find valuable, leading to Microsoft Intune's dominance in the industry.

What's my experience with pricing, setup cost, and licensing?

The pricing for Microsoft Intune has different types of packages. Currently, if you go with all the packages, the mid-variant of the top-level package such as E3 or E5 offers benefits such as AD and Azure AD. If you require all these tools, it could be cheaper, however, if you do not need certain tools and still want Microsoft Intune, it is not that cheap. It can be quite expensive. 

Additionally, if you are already on one cloud-based platform and moving to Microsoft Intune, the transaction will also involve some costs since deployment is necessary. 

Cost-wise, it varies from project to project. If the client wants to move, they may need to go for the E5 license; the difference between E3 and E5 is not significant. If your organization has a large number of Windows devices, Microsoft Intune is a valuable tool. But for Mac users, Jamf would be recommended.

Which other solutions did I evaluate?

If you're looking to support Mac, you need to look at other products such as AirWatch or Jamf. MobileIron is not that effective; however, Jamf is good for Mac.

What other advice do I have?

Copilot in Microsoft Intune is a new tool used for answering questions, similar to ChatGPT or Gemini. There are two types of Copilot; even in Workspace ONE, there are similar tools. The licensed version is not used as it comes with a price, and our client doesn't want to go with that. The basic level of Copilot is given, which can answer a few questions, however, it is still under the learning phase. If I ask a question, it sometimes gives an exact answer, yet at other times, it suggests going somewhere else to find it, and there is no button available there. In the paid version, it can perform simple tasks such as pushing or adding devices to a group, however, it wouldn't truly help with the current level of AI. We may need more complex AI for this type of console.

On a scale of one to ten, I rate Microsoft Intune a nine.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1597719 - PeerSpot reviewer
Team Lead, Cybersecurity at a financial services firm with 1,001-5,000 employees
Real User
Top 10
Oct 30, 2024
Improves productivity and is free with our license but it isn't very flexible
Pros and Cons
  • "We work completely in a Microsoft environment. Its interface is similar to other Microsoft solutions that we are using such as Microsoft Defender. So far, for our administrators, it is easy to use."
  • "At the moment, we need more flexibility. We have some offices migrating to Windows 11 remotely. Sometimes, it is difficult to manage image installation because we have to collect some information before starting image deployment. Currently, Intune cannot collect the information needed for deploying new images."

What is our primary use case?

We are using Intune for managing endpoint devices with zero-trust principles. The devices are not domain-connected because most people work from home. We do not trust these computers, so we use Intune to deploy and enforce policies related to updates, software installation, and management of admin users.

When we are using Microsoft products on mobile devices, we are using Intune to enforce policies on them.

Our usage is very simple. We are using Intune to manage devices that we do not trust. We are using Windows 365, and we install all applications only on these virtual PCs in the cloud. We do not have anything on endpoint devices. Not even a simple document can be downloaded there. We just have an access point to Windows 365 machines in the cloud. We are a financial company. There are not too many enterprise applications that we can use. We prefer to use zero trust. This means no there is no data on company devices at all. It is only on the cloud machines. It is easier to control one perimeter than 10,000 or 20,000 machines. We can reduce the attack surface in this way.

How has it helped my organization?

Intune increases the productivity of our IT team. 

There is a reduced cost of ownership and management. We do not need a lot of additional training. Administrators can share roles because its interface is similar to other Microsoft solutions. With one or two days of training, administrators can start working with it. There are a lot of Windows specialists in the market.

What is most valuable?

We work completely in a Microsoft environment. Its interface is similar to other Microsoft solutions that we are using such as Microsoft Defender. So far, for our administrators, it is easy to use. 

What needs improvement?

At the moment, we need more flexibility. We have some offices migrating to Windows 11 remotely. Sometimes, it is difficult to manage image installation because we have to collect some information before starting image deployment. Currently, Intune cannot collect the information needed for deploying new images.

For how long have I used the solution?

We have been using Microsoft Intune for three years. I also used it for two years in my previous work.

What do I think about the stability of the solution?

Intune is a stable product with no significant issues. We have standardized hardware. We do not have a wide variety of endpoints.

What do I think about the scalability of the solution?

Intune is quite scalable. We started with 3,000 machines, and we now manage 15,000 machines. Our endpoints will probably grow.

How are customer service and support?

I have not interacted with Microsoft technical support personally, but I was satisfied with their support in my previous company.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have not used any other solution in my current company.

How was the initial setup?

We are using the public cloud for access, but everything is closed. There is no public access to infrastructure. Access is only through the cloud. There is no VPN or any other way.

I was involved in the security assessment in the beginning. The initial setup was quite easy because we did not look for very complicated functions. We did face some issues with the multi-user mode but resolved them. It took us about a month.

It requires maintenance. You have to review regular policies and adjust policies when something changes in the environment or you deploy new applications. Its maintenance is mostly done in-house. Only in a very complicated situation, we involve a third-party consultant.

What about the implementation team?

We performed the deployment with the assistance of a third-party consulting company, not resellers. Three engineers from our team were involved.

What's my experience with pricing, setup cost, and licensing?

Cost is not my department, but the product is included in the E5 license that we already pay for every user, so no additional cost is incurred.

Which other solutions did I evaluate?

We have not evaluated other options because Microsoft Intune is included in our E5 licensing. I would prefer to use the VMware solution, but that is not possible because Intune is included with our existing license. Buying any other solution will result in additional costs.

What other advice do I have?

I recommend doing thorough homework and testing everything in a test environment. After ensuring that everything works fine, proceed with the final deployment.

It is not the best solution. It requires a bit more effort in management, but it works. It is not so flexible, but considering it is free for us, it is okay.

We are doing experiments with Copilot to see how we can use it. For some users, it is deployed, and we will be testing it actively. We are mainly using it to make emails, presentations, and documents better for the end users who will read them. We are an international company, and English is not the primary language for 99% of people. Copilot makes the documents more readable. We have not yet tested Copilot in Intune for security functions. We have SIEM and other security tools for insights. At the moment, we do not have a big need to start experimenting with Copilot in Intune. After we finish with the end-user use cases, we can switch focus on daily operations for IT teams.

Intune has not helped us consolidate vendors because we do the installation on the cloud. On endpoints, we have nothing.

I would rate Intune a seven out of ten because it is not so flexible.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
James Cook - PeerSpot reviewer
Infrastructure Engineer at SpiritUK
Real User
Top 20
Sep 29, 2024
Integrates well with Microsoft products and helps with security and compliance
Pros and Cons
  • "For our clients, the conditional access feature along with different compliance policies that they can set is valuable."
  • "The mobile management is good for iPhone and iPad, but the Apple Mac management needs improvement. That is probably because Microsoft does not have low-level access to Apple Mac hardware. If you are doing basic things, it is okay, but if you want to image Apple Macs and do things like that, then Jamf is much better."

What is our primary use case?

It is being used for device management. We have a couple of clients using it at the moment. They have Windows, Android, and iPhone devices that are managed by it. We have another client with only three devices, but they are Windows SE devices with the cut-down version of Windows.

They are using the latest version because it is always kept up to date online.

How has it helped my organization?

Microsoft Intune pretty much brings all of our endpoint and security management tools into one place. I cannot think of the ones where it does not do what we need. Apple Mac management could be better. It makes IT and security operations much easier and much more convenient.

We use the Enterprise Application Management features of Intune Suite. That is what the data manager is set to. These features are good. So far, we have had no problems with that.

Implementing applications is easier than MaaS360. There are definitely time savings. It is a lot smoother and a lot more well-integrated with Azure AD, etc.

The integration with Microsoft 365 and Microsoft Security for both cloud and co-managed devices is very important. That is the key thing for us. Almost all of the clients have Microsoft Office 365. We have only two clients who use Google G Suite, so this whole integration is very important.

It has helped us consolidate vendors.

Its benefits can be realized within a couple of weeks. It is very good because it works. Conditional access and compliance work from anywhere, so it is very good.

What is most valuable?

For our clients, the conditional access feature along with different compliance policies that they can set is valuable.

All the remote tools you can use on the mobile are also valuable. Features such as passcode reset for the device lock are helpful, so you can set a code and get people back into the device.

What needs improvement?

The Apple Mac management is a bit basic. The mobile management is good for iPhone and iPad, but the Apple Mac management needs improvement. That is probably because Microsoft does not have low-level access to Apple Mac hardware. If you are doing basic things, it is okay, but if you want to image Apple Macs and do things like that, then Jamf is much better.

Their support needs to be improved.

For how long have I used the solution?

I have been using this solution for about eight years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is definitely scalable.

How are customer service and support?

Their support is absolutely useless. They used to be good, but now, there are separate departments. We had an issue with conditional access where the client did not like the fact that single sign-on was working and automatically logging them into everything. They found it to be a security issue. It was not a good thing. We were trying to disable that, but then conditional access would not work. Their support could not figure it out. They would say that it is Entra and then they would say that it is Intune. I found out what it was. It was a token that was coming from a single sign-on.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

We use Jamf. We are still using IBM MaaS360 for some of the clients, but it is getting phased out for Intune.

MaaS360 does not integrate with all Microsoft products as well as Intune for obvious reasons. A lot of our clients want Intune for data protection, conditional access, etc. It is more about protecting their data and making sure that the devices are compliant and meeting certain policies. 

The user experience of Intune is good. It is a lot less clunkier than MaaS360. We do most of the setup, so the users are not really affected by it.

Jamf is mainly for Apple Mac management. Intune is mainly for Windows management and mobile management. Intune does not have the same level of integration with Apple Mac, so you cannot image them properly. It supports very basic imaging. Jamf is a much better tool for managing Apple Mac.

How was the initial setup?

You have to use Azure because it is a part of the Microsoft environment.

I am the lead engineer involved in setting it up and configuring all the policies. It is straightforward.

From a maintenance point of view, there is no maintenance you have to do because Microsoft does it all in the cloud. You might need to tweak a few things on an app after you send it out, but those are general tweaks to make things run better. You do not have to put updates on or do things like that.

What about the implementation team?

We do not use any external help. We just use Microsoft documentation.

What's my experience with pricing, setup cost, and licensing?

We work in the charity sector, so a lot of our clients get Microsoft Premium licenses or Business Premium for free. They get ten licenses free, and a lot of our clients do not have more than ten staff members. They are getting the tool for free, so its cost is not an issue.

Which other solutions did I evaluate?

We did not evaluate other solutions.

What other advice do I have?

It is good. If your clients want to protect their data and they are using Microsoft tools, then Microsoft Intune is definitely the one that they should be using.

We are not using it to its fullest. There is a lot more we could do. I work for an MSP, so we are bound by what the client wants to do. If the client does not want to advance anything, we will not advance it.

In terms of IT productivity, it does not benefit us directly because we are an MSP, but it is a lot easier to use than MaaS360 and other ones we have tried. Similarly, it does not save us costs because we are an MSP. We charge people to implement a solution, and that is it. If we are paid to manage it, we obviously try to manage it, but it does not save us any money.

It does not affect our security because we do not use it ourselves. We just install it for other people.

Overall, I would rate Microsoft Intune an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Pratik Dave - PeerSpot reviewer
Director at Destino Infotech Pvt Ltd
Real User
Apr 18, 2024
A user-friendly UI, comprehensive visibility, and a seamless experience
Pros and Cons
  • "One of the biggest advantages of Microsoft Intune is that it brings the management of Windows, macOS, iOS, Android, and even Linux under a single pane of glass."
  • "A new Intune feature allows application packaging, but it incurs additional licensing costs for a significant number of applications."

What is our primary use case?

Our primary use of Microsoft Intune is for device management and improve security. Initially, it focused on management for Windows devices. However, over time, its capabilities have expanded to encompass mobile device management in general, as well as management for other platforms like iPO, Android and Mac OS devices.

To ensure our devices are manageable regardless of location, we transitioned from an on-premises device management solution to Microsoft Intune. This cloud-based approach allows us to manage devices from anywhere, eliminating the need for them to be on our company network or VPN. Intune empowers us to remotely take actions on devices, including software installation, user identification, performance checks, and even triggering a remote lock if a device is compromised.

How has it helped my organization?

While most of our devices are company-owned, we also manage a small number of personal devices. Regardless of location, Intune allows us to manage them all.

Intune streamlines mobile application management by offering a single pane of glass for all devices across platforms, including iOS, Android, MacOS and Windows. It integrates seamlessly with the respective app stores for each platform.

Intune is a key component of a zero-trust security architecture. With Intune, we can manage our entire device fleet from a single platform. This enables us to enforce compliance policies. Intune verifies if devices meet our organization's security standards. We can implement zero-trust access control. Non-compliant devices are blocked from accessing company resources. Secure devices are granted access. Intune helps consolidate security management. It simplifies device security by offering features like compliance checks, security posture assessments, and configuration management - all in one place. Finally, Intune reduces management overhead: Intune streamlines device management by eliminating the need for multiple tools for tasks like patching and application deployment. While it may not offer the full functionality of specialized tools, it provides a comprehensive solution for core device security and configuration needs.

Intune offers comprehensive visibility and IT control over devices across various platforms. This allows for remote management, although integration with additional solutions or configuration might be necessary in some cases. However, Intune provides a single point of control for all our devices. Key functionalities include remote device control. We can manage devices remotely and trigger various actions. As well as advanced features to locate devices, enforce data synchronization, and more. It's important to note that certain advanced functionalities, like admin-level remote control, require device approval and may not be as robust as solutions offered by competitors, such as TeamViewer. Additionally, to access features like privileged email access, privileged device management, and advanced remote assistance, additional licensing is required, resulting in increased costs.

For users, Intune offers a seamless experience. Once their devices are enrolled, they typically don't need to do anything further. This is especially true for end users. For administrators, Intune is also an easy-to-use solution. Being cloud-based, it's accessible from a web portal just like any other SaaS application. The company portal experience is straightforward. Once users understand the basics, they can easily check device compliance and install applications. Overall, the user experience is very positive. However, device enrollment might require some training. Not everyone is comfortable managing their devices themselves. Even though the enrollment process is fairly simple and intuitive, some user training and change management might be necessary, especially for mobile device management in Intune. This is because multi-factor authentication is sometimes required to enroll devices, and some users may need help understanding and completing this step.

It provides a centralized solution for viewing all our devices. It also simplifies enrollment for Windows devices. Once we enable automatic enrollment for on-premises devices or upon user sign-in to company applications, enrollment can be seamlessly done through mobile devices. The most significant benefit is undoubtedly patching. Intune automates the process of keeping devices updated with the latest Windows updates and feature updates. This significantly reduces administrative overhead. After setting up the policies, we can be confident that updates are being applied without needing to constantly monitor them. Intune also offers improved visibility into device compliance. Unlike traditional Group Policies, which may only show successful application but not actual implementation, Intune displays the real-time status of enforced policies on each device. This allows us to see if features like BitLocker encryption or security restrictions are truly active, providing greater confidence in our device security posture. In essence, Intune offers a significant improvement in terms of device visibility and configuration management.

Intune's device compliance policies offer organizations valuable visibility into device settings. This includes essential requirements like BitLocker password complexity and minimum Windows or OS versions. Additionally, these policies allow for the deployment of custom compliance settings. This lets us measure compliance against any specific criteria. For example, one of my clients uses Intune to verify if CrowdStrike is running on the required version and if devices have downloaded the latest updates. By ensuring compliance, we can be confident that devices are secure against the latest vulnerabilities and security risks. This provides an extra layer of assurance. When used in conjunction with conditional access, Intune can block non-compliant devices. This guarantees that only compliant devices can access our organization's resources and applications. From a security standpoint, this offers significant peace of mind.

Application deployment in Intune offers several features that streamline the process. These features include applicability rules. We can deploy applications only to devices that meet specific criteria, such as operating system version or name. This ensures users receive the applications they need and avoids unnecessary installations. Device filtering allows us to exclude devices that don't require the application, further optimizing deployment efficiency. While Windows Win32 applications require packaging, the process is straightforward. Although automation would be ideal, packaging becomes easier with practice. Microsoft could potentially improve Intune by allowing seamless import of SCCM application packages. This would eliminate the need for repackaging and streamline migration. Overall, Intune simplifies application deployment for administrators. Features like self-service installation through the company portal empower users and reduce administrative burden. Packaging requirements vary depending on the application type. Standard applications like Office 365 are straightforward to deploy. Additionally, Intune integrates directly with app stores for iOS and Android apps, eliminating the need for manual packaging for these platforms.

Intune excels at securing hybrid work environments and protecting data on both company-owned and BYODs. It allows for selective wiping of company data from these devices without affecting personal information. However, for data downloaded from company applications like OneDrive, additional security policies might be necessary to ensure its security on downloaded devices, especially BYODs. The good news is that Intune allows the management of BYODs, enabling the deployment of settings, configurations, and security measures to assess the device's security posture. Notably, it's very easy to deploy for BYODs with its mobile application management for iOS and Android. For securing data within applications on Windows devices, Microsoft's Windows Information Protection capabilities seem to have been replaced. There's now a category requirement, likely used to secure data accessed through the Edge browser on privileged devices. This ensures data remains secure when users access it through Edge. It's important to note that some aspects of data security on BYODs might require additional configuration to guarantee complete protection.

Microsoft security signals identify the settings configurations we need to enforce on the devices. Then, it's up to organizations to deploy those settings or configurations. So, it's a good thing. It helps us understand what additional security we need to enable on the devices. Microsoft signals do help us do that, but it may not be enough. We might have various other compliance requirements that not everything would be covered under Microsoft signals, I believe.

Intune's endpoint privilege management is a valuable feature. It allows granting privileges to specific applications instead of giving local admin rights to users or entire devices. This can improve security by minimizing the attack surface. While EPM requires an additional license, it's a worthwhile consideration for many organizations. I've experimented with it in a lab setting, but we haven't deployed it for production use yet.

It has significantly boosted our IT department's productivity by automating many tasks. For instance, we no longer need to create custom images with Autopilot; we can simply deploy application settings configurations. Additionally, Intune seamlessly handles Windows updates and feature updates once they're configured. It's a set-and-forget system. Application deployment is also significantly simplified, saving admins valuable time. Overall, Intune improves IT productivity and empowers users with self-service features. Once trained, users can handle tasks like application installation, device compliance checks, and remediation actions for non-compliant devices.

While Intune isn't designed to identify security breaches directly like Defender does, it plays a crucial role in minimizing our attack surface. This is achieved by deploying the latest updates, configurations, and endpoint security policies. In my experience, Intune has significantly improved our overall security posture by reducing vulnerabilities, but it's not a replacement for breach detection tools.

Intune helps save costs by consolidating multiple endpoint management solutions. For instance, we might have separate solutions for iOS devices, Android devices, and Mac devices. By bringing everything together into a single solution with Intune, we can save on both platform licensing costs and administrative costs. Additionally, Intune reduces the need for additional per-device licensing fees that may have been incurred with separate solutions.

The user interface is well-designed and easy to navigate. It has a simple and well-structured layout, which makes it a pleasure to use. I'm very happy with the overall experience of the Intune portal. They also seem to be continuously improving it, with updates made on a monthly basis.

It streamlined our mobile device management by allowing us to manage both iOS and Windows devices under a single solution. This consolidation reduced the number of consoles and overall management tools required.

The integration of Microsoft Intune with Microsoft 365 and Microsoft Defender for Cloud strengthens cloud management and support for hybrid environments. This unified approach bridges the gap between cloud-based and on-premises device management, allowing organizations to leverage existing infrastructure while transitioning to cloud solutions.

What is most valuable?

One of the biggest advantages is that it brings the management of Windows, macOS, iOS, Android, and even Linux under a single pane of glass. This means we can manage all our devices from one central location.

A particular advantage is its tight integration for managing Windows devices. Since Intune is a native Microsoft product, it offers a more comprehensive and streamlined experience compared to many third-party solutions.

For mobile device management, Intune includes all the capabilities and features we'd expect from other vendors. However, it goes a step further by allowing us to secure Office 365 apps without needing full device management. This is a significant advantage when compared to other MDM solutions.

What needs improvement?

We package Win32 applications and import existing packages using solutions like SCCM or third-party tools. While Intune doesn't currently offer third-party application patching, we rely on third-party solutions for that functionality.

A new Intune feature - Enterprise App management allows to deploy Microsoft and Third party apps and keep them up to date but it incurs additional licensing costs. Ideally, this feature should be included in the base license. Similarly, the privilege endpoint management feature also requires additional licensing.

Intune would benefit from offering some core features at no extra cost. The most valuable improvement, in my experience, would be the ability to identify inactive devices through reports. Customizable reporting capabilities within Intune would simplify overall management and allow us to track device activity and inactivity more effectively.

For how long have I used the solution?

I have been using Microsoft Intune for over 10 years.

What do I think about the stability of the solution?

Microsoft Intune is an extremely stable product with a small amount of glitches over the years.

I would rate the stability 10 out of 10. 

What do I think about the scalability of the solution?

Intune is cloud-based and therefore highly scalable. I have clients with over 40,000 devices.

How are customer service and support?

The quality of Microsoft's technical support varies based on the level we have. Premium support offers faster escalation for complex issues, while basic support may have longer wait times for a response. However, there's a strong online community around Microsoft Intune. Searching questions online through Google can often lead us to solutions from this community.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Jamf, Microsoft Configuration Manager, Altiris Symantec Endpoint Management Suite, and Cisco Meraki Systems Manager. Microsoft is considered a leader in endpoint management solutions. While Jamf excels in specific areas, Microsoft Intune is generally recognized as the market leader due to its comprehensive capabilities. Intune also integrates seamlessly with other solutions such as compliance checks, conditional access policies, and mobile application management. Microsoft Intune offers several advantages over competitors, providing a comprehensive suite of mobile device management capabilities.

How was the initial setup?

The time it takes to implement Intune depends on two factors: the features we want to enable and the size of our organization. Enabling basic management features for common devices like iOS, Android, Mac, and Windows typically takes one to two weeks. This includes enrolling devices and setting up core functionalities. For a full Intune implementation with all its capabilities, the timeline can vary depending on the organization's size. However, simply enrolling devices and exploring basic features can be done in a couple of days.

While the step-by-step guided scenarios make the initial deployment process easier, it still requires familiarity with Intune and some experience using it.

What's my experience with pricing, setup cost, and licensing?

It is available for individual purchase at a low per-device cost. However, it's also included as part of the Microsoft 365 suite license. Additionally, Intune offers various tiers with advanced features at an extra cost.

What other advice do I have?

I would rate Microsoft Intune 9 out of 10.

We have around 20,000 users on Intune and 4 people who work directly with it.

Intune requires annual maintenance to renew push certificates and tokens for business managers. For Windows devices, we might also need to deploy the latest application. Additionally, it's recommended to periodically review devices that are inactive, outdated, or haven't reported to Intune for a set amount of time. While Intune offers a "set and forget" approach for initial configuration, some ongoing maintenance is necessary to ensure its smooth operation.

I recommend Microsoft Intune to others.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Mike Sanlon - PeerSpot reviewer
CTO at Sojitz Logistics Corporation of America
Real User
Feb 22, 2024
Provides great visibility, helps consolidate our endpoint devices, and our vendors
Pros and Cons
  • "Fortunately, now everything is streamlined into a single, unified platform."
  • "I would like some integration with the Microsoft reporting platform Power BI."

What is our primary use case?

Microsoft Intune serves as our central platform for device management, ensuring timely patching and secure access through conditional controls.

We leverage Intune to automate device onboarding, ensure patch deployment and device compliance, and generate compliance reports. We prioritize patching devices identified as non-compliant through these reports.

How has it helped my organization?

Microsoft Intune has played a crucial role in enabling remote work for our facilities under our BYOD policy. It has been essential for our success.

Consolidating all our endpoint security management tools into a single platform significantly improves our IT and security operations. This streamlined approach provides us with the advantage of using only one reporting stack, and it yields synergies that surpass the capabilities of individual solutions from separate vendors.

Integrating Intune with other Microsoft services has streamlined authentication through single sign-on. We're now transitioning to passwordless authentication for enhanced security and convenience within our unified environment.

Last week, for example, someone traveling to China had their laptop stolen. Fortunately, thanks to Intune, we were able to remotely wipe the device, protecting their data.

The incident reporting and analytics tools enable us to monitor our devices' compliance status near-continuously. As licensed customs brokers subject to Department of Homeland Security inspections, this allows us to generate reports quickly and efficiently, reducing inspection time from thirty minutes to three to four minutes.

Intune gives us full visibility into our devices and IT control across all platforms. This has significantly streamlined our management process. Previously, two people in our ten-person department spent their entire time monitoring platforms and fixing issues. Now, only one person devotes 75 percent of their time to these tasks. This means we're accomplishing more with fewer people and less time overall.

It's great, but the issue with any platform like it is the delay between deploying something and it rolling out remotely. However, it's probably the best option available in terms of keeping us informed about what's happening outside our server room or hosting environment.

Microsoft Intune has been instrumental in securing our hybrid work environment and protecting data on company-owned devices (BYOD). Before Intune, if someone lost their phone, wiping it meant erasing all their personal data - photos, documents, everything. Today, with Intune, we can selectively remove only our applications and data. This allows users to recover a lost phone and restore their personal information. Intune empowers us to be more proactive, eliminating the worry of accidentally wiping a misplaced device.

Microsoft Security Signals has become an invaluable addition because it provides centralized reporting capabilities. This one-pane-of-glass view empowers us to easily communicate our security posture internally to management and externally to regulatory agencies and auditors.

I'm impressed with the Intune endpoint privilege management feature. It's allowed us to reduce even the admin team's permissions significantly. Now, they typically lack access to most things, but the system elevates their privileges just in time for them to complete specific tasks and then demotes them again afterward. This least-privilege approach has been fantastic, and the built-in integration across the entire Microsoft stack is a major advantage. It saves us the hassle of purchasing and integrating a separate solution – it's simply there and works seamlessly.

Implementing least privilege access through Endpoint Privilege Management has significantly improved our organization's attack surface. For example, our Microsoft Secure Score was around 60 percent before adopting the solution, and it's now up to 98 percent. This reduction in the attack surface has also enabled us to implement various remediation measures and establish context-based security. For instance, even if users enter the correct password and complete two-factor authentication, we can require additional authentication if they log in from an unfamiliar location, such as a new country or state. This multi-layered approach provides us with an enhanced sense of security.

Intune has helped reduce the risk of security breaches in our organization.

We had another deployment solution for Apple iOS and Mac devices. Additionally, we also managed a few Linux boxes with an unsupported management architecture. We were able to migrate all of those devices to Intune.

Intune has helped consolidate vendors. 

What is most valuable?

The integration with macOS and mobile devices specifically iOS, iPhones, and iPads was challenging in the past, requiring separate solutions and manual processes. Fortunately, now everything is streamlined into a single, unified platform.

What needs improvement?

I would like some integration with the Microsoft reporting platform Power BI.

For how long have I used the solution?

I have been using Microsoft Intune for five years.

What do I think about the stability of the solution?

Microsoft Intune is stable.

What do I think about the scalability of the solution?

The scalability is good.

Which solution did I use previously and why did I switch?

We used System Center Configuration Management, and we did it all on-prem. When Covid hit we switched to Intune.

How was the initial setup?

Microsoft documentation has traditionally been criticized for its complexity and search difficulty. While some improvements have been made, many users still rely on online forums and YouTube videos for basic setup and troubleshooting. As a result, the onboarding experience can feel less polished compared to competitors like Malwarebytes, which offer more hand-holding during installation and configuration. Unfortunately, navigating Microsoft products often requires independent research and trial and error, which can be a barrier for new users.

What's my experience with pricing, setup cost, and licensing?

Consolidating vendors has lowered our licensing costs. However, some features included in Microsoft's Intune might be 50 percent more expensive if purchased separately from another vendor. Specifically, if we consider upgrading Azure Active Directory or Entra to the P2 level, adding Intune capabilities, and acquiring the full Intune suite, Microsoft offers a significantly lower per-user cost compared to external vendors. With Microsoft, it's just a couple of dollars per user, while external vendors typically charge $10-$14 per user for similar functionality.

I would rate the price a four out of ten with ten being the most expensive.

Which other solutions did I evaluate?

We evaluated several options, primarily security solutions like Malwarebytes and Sophos, which offer remote management capabilities. Ultimately, we opted for Intune.

This is a case where remote management was initially implemented as an afterthought, primarily driven by anti-phishing and anti-malware threat response needs. Subsequently, it became the sole platform for endpoint management, despite limitations in its functionality and granularity compared to solutions like Intune.

What other advice do I have?

I rate Microsoft Intune an eight out of ten.

I'm conflicted about consolidating our vendors. On the one hand, it would simplify things considerably, which is appealing. However, I worry about relying solely on one supplier, preferring a layered approach with multiple vendors. Ideally, we'd maintain a multi-vendor setup, but the current complexity makes it challenging. There are currently vulnerabilities related to Microsoft's primary factor authentication, including several unpatched zero-day exploits. These represent ongoing security concerns.

It's crucial for our organization that the Intune suite integrates seamlessly with Microsoft 365 and Microsoft Security, both for cloud-based and co-managed devices. This is especially important considering the recent trend of moving data back on-premises. We believe a hybrid environment offers the best of both worlds, but many tools are cloud-only, making them incompatible with our on-premises servers or unable to manage them effectively. Thankfully, the Intune suite has addressed this gap, providing us with much-needed flexibility and functionality.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Second Line Support Engineer at ATOS
MSP
Top 20
Jul 30, 2025
Monitoring and managing device compliance effectively improve user experience
Pros and Cons
  • "The best features of Microsoft Intune include helping to know if computers are configured correctly and if users have access to apps or the platform."
  • "Automation has room for improvement in Microsoft Intune for fixing some errors."

What is our primary use case?

I use Microsoft Intune to check if laptops are compliant or not, and to check if applications are added to user profiles. Sometimes there are applications users cannot find in the Company Portal or on their laptops, so we try to add them to their profiles. We can check if there are issues with Windows updates and verify if they have the latest version. We can check by hostname or serial number of the laptop if a user's computer is compliant or has access to the enterprise company platform resources.

What is most valuable?

The best features of Microsoft Intune include helping to know if computers are configured correctly and if users have access to apps or the platform. It provides an excellent overview of all machines for the company and helps determine if those machines are facing issues. It is particularly helpful when laptops face issues with upgrading or migrating to Windows 10 or Windows 11.

What needs improvement?

Automation has room for improvement in Microsoft Intune for fixing some errors. The knowledge and database in support can also be improved. If errors aren't in the database, we need to check forums or Google to understand and troubleshoot them. The most important improvement needed for Microsoft Intune is to have a comprehensive database about what each error means exactly and what steps to take for troubleshooting.

For how long have I used the solution?

I have been using Microsoft Intune for about four years.

What do I think about the stability of the solution?

The stability of Microsoft Intune rates at nine out of ten.

What was our ROI?

Microsoft Intune has saved approximately 30% of time.

What other advice do I have?

Users are mostly satisfied with Microsoft Intune because it helps them understand what's happening on their laptops. For some issues, I can assist depending on Microsoft Intune access. When comparing Microsoft Intune with other tools, the pricing is acceptable and it's easy to use. I recommend Microsoft Intune; it should be used in companies using Windows. I rate Microsoft Intune eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Akhileswar Reddy - PeerSpot reviewer
Endpoint Management | Microsoft Intune Administrator | Device Enrollment & Compliance at Tata Consultancy
Real User
Top 20
Jul 9, 2025
User-focused management and deploy applications efficiently with straightforward dashboards
Pros and Cons
  • "My favorite feature of Microsoft Intune is the dashboard; the dashboard is very simple and user-friendly, and any person, even without prior knowledge, can understand it easily by seeing the interface dashboard."
  • "The main issue with Microsoft Intune is that for Windows, we can support only Windows 10 and 11 operating systems."

What is our primary use case?

We are managing different platforms including iOS, Android, and Windows using Microsoft Intune. We are not supporting Mac. For Mac, our organization uses JAMF Pro. 

We use Microsoft Intune for application deployment, creating compliance policies for organizational devices and BYOD devices, creating configuration profiles, managing users, and troubleshooting for end users' enrolled devices. I provide level two technical support for end users.

What is most valuable?

My favorite feature of Microsoft Intune is the dashboard. The dashboard is very simple and user-friendly. Any person, even without prior knowledge, can understand it easily by seeing the interface dashboard. Everything is available in one place. 

For example, if you go to devices, all platforms will be shown. When you select one platform, such as Windows, everything will be on the same page, including application deployment, configuration profiles, compliance policies, future updates, and enrollment types. Anyone can easily understand it when compared to the SCCM tool.

What needs improvement?

For platforms such as iOS, Android, and Windows, Microsoft Intune is very good. When it comes to Mac, everyone uses JAMF Pro for patching and upgrading. I suggest they can improve Mac-related features and platform-related features. We cannot manage servers in Microsoft Intune because it is completely cloud-based.

The main issue with Microsoft Intune is that for Windows, we can support only Windows 10 and 11 operating systems. We cannot deploy large application files. For that, our organization uses SCCM only. We also cannot manage older versions of devices from Microsoft Intune, such as Windows 7, Windows 8, and Windows 9, as it does not support them.

For how long have I used the solution?

I have been using Microsoft Intune for the last three years.

What do I think about the stability of the solution?

Everything is good with Microsoft Intune. They are releasing many updates recently. Previously, we were using Company Portal for deployment. Now, they have introduced web-based enrollment. 

Without the Company Portal, a user can directly register the device by using the Outlook application. In the last two years, they have introduced many changes. The performance and everything is good with Microsoft Intune. For us, Microsoft Intune responds very well. They handle it and provide us with complete data without any issues. Follow-ups are also very good.

How are customer service and support?

We mostly connect with Microsoft whenever we are unable to resolve issues. 

We can check with Microsoft subject matter experts. We log an incident and check with the Microsoft subject matter expert. Based on the priority of the incident, if we create a priority one incident, they try to get in touch within one to two hours. 

They assign one agent who connects with our architect. They try to help us with the root cause analysis of the issue. Mostly, it takes some time because they need to examine all the logs. Root cause analysis takes considerable time to find the exact solution. 

For Microsoft Intune support, I give an eight out of ten. While they are SMEs who can fix issues quickly, the cases we have raised with Microsoft take too much time, which affects end users and the organization.

How would you rate customer service and support?

Positive

How was the initial setup?

One person is required for the deployment of Microsoft Intune, though it depends on the requirement.

Which other solutions did I evaluate?

When it comes to pricing, Microsoft Intune is very good compared to other tools such as Tanium, Ivanti, and JAMF. Those are very high-cost tools. 

Microsoft Intune is less costly when compared to them and provides many features and benefits. On a single E3 or E5 subscription, a user can enroll ten to 15 devices. A single user can enroll 15 devices. They can access company resources such as Outlook, Teams, and everything without any issues.

What other advice do I have?

Copilot in Microsoft Intune was recently introduced. I am working as L2 L3 support. We are using Microsoft Copilot. We are testing Microsoft Copilot for troubleshooting issues in a non-real-time environment. We are testing it for normal cases, such as Microsoft blogs or when new issues arise for users. 

If a client asks to deploy multiple applications, then a team will be required. Our client is a US-based health sector company, and we are users of Microsoft Intune without any partners. 

I rate Microsoft Intune nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.