No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1209912 - PeerSpot reviewer
CSO at a tech services company with 11-50 employees
Reseller
Top 20
Sep 11, 2024
Is cost efficient and easy to deploy, but the support is subpar
Pros and Cons
  • "The Mobile Device Management in Intune is a valuable feature."
  • "We've faced significant pushback with Copilot as our clients aren't seeing a favorable cost-benefit analysis."

What is our primary use case?

We've experimented with and deployed Autopilot for building and deploying software through Intune, utilizing Intune policies to modify Azure AD joined systems, now referred to as Entra joined. This covers the entire scope of Intune that we've explored and implemented.

We are a consulting company with extensive experience in deploying Intune. We utilize Intune for hybrid join Entra machines. For clients who have the necessary licenses, while Intune is not a full-fledged Remote Monitoring and Management solution, it can serve as an effective replacement for RMM if you are a Managed Service Provider.

How has it helped my organization?

While more mature tools exist for securing hybrid work and protecting data on BYOD and company devices, Intune is a viable option for clients who want to leverage MDM with their Premium or E3 license, especially if cost is a major concern. Despite some challenges with Samsung Knox and iOS devices, Intune has shown improvement, and these issues are less frequent. As Microsoft doesn't have a native phone, limitations are inevitable.

What is most valuable?

The Mobile Device Management in Intune is a valuable feature.

What needs improvement?

Microsoft recently separated Defender into Security. Intune does not centralize all endpoint and security management tools into one place. It used to be more centralized.

The Microsoft support has been subpar for some time now. Troubleshooting issues often require us to involve a partner, which isn't an ideal or easily manageable solution given the challenges with Microsoft support. We need a reliable partner, but that partnership might still require Microsoft's assistance.

We've faced significant pushback with Copilot as our clients aren't seeing a favorable cost-benefit analysis. Many are opting for ChatGPT Enterprise instead of integrating Copilot into their workflows. We initially expected significant value from Copilot, but Microsoft's pricing is excessive, and the product itself is not exceptional. It remains quite rudimentary in its current state.

Microsoft should not rely on partners to fix issues. While users can open tickets with Microsoft, they often cannot resolve the problems themselves and must engage a partner. This is not an à la carte solution. Perhaps when Copilot eventually becomes available, it will address this. It's not Intune's fault, as it is used frequently.

Buyer's Guide
Microsoft Intune
July 2026
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,563 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Intune for ten years.

How are customer service and support?

The technical support is not good.

Which solution did I use previously and why did I switch?

We tried numerous solutions prior to Intune, but Microsoft's inclusion of it within their licensing model incentivized us to adopt it. Since we were already paying for the license, it made sense to leverage its full potential and maximize our investment.

What's my experience with pricing, setup cost, and licensing?

If you're subscribing to Premium or E3, there are no additional costs for Intune, it's included. However, with lower-tier plans, you don't get the full suite of security features. Depending on your specific licenses, you might have some level of Advanced Threat Protection, Endpoint Detection Response, or other Defender tools, but not the complete package. Generally, for around 300 users, you get decent protection with Defender for desktop and server – it's a good value. But with E5 licenses, you're at the enterprise level, and you get what you pay for, so expect add-ons. I don't think Microsoft would position Intune as a primary security product anymore, given their recent cloud changes and the focus on Defender. Intune is useful for patching, but it's not a comprehensive security solution in itself. That's why Microsoft has rebranded their security offerings under security.microsoft.com.

What other advice do I have?

I rate Intune six out of ten.

Many of our clients with premium or E3 or above licenses use Intune because it's included in their Microsoft solution. They prefer to leverage a Microsoft product over a third-party alternative. Additionally, Intune allows us to maximize the value of our clients' existing licenses. Therefore, if a client has a premium license, has under 300 users, or is on E3 or above, there's no reason to use another solution when Intune is readily available.

Microsoft recently transitioned from Intune to Endpoint, then back to Intune. Additionally, they moved certain security aspects of Purview into a separate deployment, as is the case with their ATP Defender Suite. This shift signifies a move away from a single, unified management interface to a more distributed model.

We use the enterprise application management feature to roll out apps. While there are better tools available for app discovery, deployment, and automatic updating, Intune's inclusion in the Microsoft bundle keeps costs down. Although Intune may not be the ideal solution for automated application deployment or MDM, its integration with Microsoft licenses makes it a worthwhile option, especially with the expectation of future improvements from Microsoft.

We use the Advanced Endpoint Analytics but it is no longer in Intune. It's been moved over to the security portal for Defender.

The endpoint analytics feature, which helps proactively detect and remediate anomalies and endpoints, is now part of Microsoft Defender formerly known as Advanced Threat Protection. Gartner rates it very highly. To perform threat hunting, we need the appropriate licensing, such as a P2 Defender license. This functionality is not available within Intune. We are transitioning from the older Advanced Threat Protection to the newer Microsoft Defender platform. Previously, configuration was done through Intune, but now we manage it through the Microsoft security site.

My advice for any organization that is already paying for a Premium or above Microsoft license is to deploy Intune because it makes financial sense. Intune is not a bad tool but if they run into any issues, the Microsoft support is no good so they need to rely on a good partner to help resolve the issue.

Microsoft cannot fully replicate the functionality of a Remote Monitoring and Management tool. However, it could incorporate certain RMM features into its existing products or develop new tools that complement RMM solutions.

By implementing Intune, we are exposing aspects of our infrastructure to the cloud that traditionally would remain on-premises. This means relying heavily on Microsoft's infrastructure and security. As we saw a few years ago with the Department of Justice's issues, which were clearly Microsoft-related, placing all our trust in one provider can lead to potential problems. However, despite these concerns, we have not encountered any security issues with Intune to date. But at the end of the day, we are maximizing our license.

Intune deployment is straightforward if you're well-prepared, whether for a hybrid setup or a purely Azure-based one. Packaging new apps is generally well-documented, but troubleshooting can be trickier. There are helpful PowerShell scripts available, though they might not be easy to find.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Microsoft Support Engineer at a tech vendor with 10,001+ employees
Real User
Aug 6, 2024
It helps consolidate our endpoints, simplifies mobile device management, and provides a smooth user experience
Pros and Cons
  • "Intune significantly simplifies application deployment, mobile application management, and policy enforcement, such as restricting user access to specific applications, thereby enhancing overall environment security."
  • "Since GMS is unavailable in China, we currently rely on device administrator enrollment for managing Android devices there."

What is our primary use case?

We use Microsoft Intune to manage mobile devices across almost all platforms, including Android, Windows, and Linux, which was recently added just a few months ago.

Previously, we relied on on-premises infrastructure using SCCM to manage mobile devices alongside other tools. Intune is a cloud-based solution that empowers administrators to manage cloud devices, implement policies, and deploy applications. While other MDM platforms exist, Intune is a top choice due to its feature set.

How has it helped my organization?

Microsoft Intune consolidates our endpoint and security management tools into a single platform. While still under development with new security features on the horizon, the current capabilities offer administrators ample tools to fortify the environment.

Intune simplifies mobile device management by consolidating endpoint and security tools into a single platform. This centralized approach enables IT administrators to efficiently manage various aspects, including Windows updates, Wi-Fi and VPN policies, application restrictions, and user account creation, all within the Intune interface, significantly streamlining the overall management process.

The user experience is quite smooth for most users because administrators handle all necessary configurations. Options like Windows Autopilot and zero-touch deployment enrollment significantly simplify the process, minimizing user intervention and effort required to set up and use devices.

I currently support Microsoft admins and have handled numerous cases related to Enterprise Application Management. Many companies utilize this tool to manage their in-house applications. While not all companies employ this method, most larger organizations do. These companies often deploy their enterprise applications using Intune, which offers a feature that allows admins to protect application data through mobile application management policies. To enable MAM, applications must be wrapped with the Intune Software Development Kit to communicate with Intune services. This process is valuable as it empowers admins to safeguard sensitive data. Intune provides SDK options for both iOS and Windows applications.

There are two methods for automatically updating the application: independent updates within the application itself or updates to the application package managed through Intune. The chosen method depends on the enterprise application's configuration. Recently introduced Azure application registration simplifies the process by requiring registration before deployment, enhancing security through authentication.

We utilize advanced endpoint analytics within the Intune suite, and the recent release of Windows Autopilot's version has expanded the range of analytics tools available to administrators. While Intune provides data on devices and users under its management, more in-depth reports can be accessed through Log Analytics or Azure Monitor. However, Intune's analytics are sufficient for gathering reports on managed devices.

The advanced endpoint analytics feature within the Intune suite allows us to access detailed information about our devices. This includes data on device counts, specific settings for bulk administration or devices, and the ability to filter devices based on our needs.

I have experience with several MDM solutions. While Microsoft Intune is excellent for managing thousands of user devices, it may not be ideal for specific use cases like bulk printer or Jabra device management, which could present challenges. However, Intune shines in organizations with large numbers of users, especially when integrated with existing on-premises infrastructure or SCCM. This integration can streamline operations and reduce staffing needs. For example, a ten-person IT team might only require two to five people dedicated to Intune management with on-premises support. While I cannot provide a full sales pitch, I confidently recommend Intune to anyone seeking a robust MDM solution.

Copilot in Intune is valuable when integrated with back-end data, such as our existing tools and libraries. This integration empowers administrators to assess information effectively. However, the tool's effectiveness hinges on the quality of data input and query formulation. As users are still familiarizing themselves with Copilot, its adoption varies across environments, with some users enabling it and others disabling it.

Copilot in Intune simplifies IT operations by quickly responding to inquiries about integrated systems. Users won't need to search for specific details as Copilot offers a variety of solutions.

Intune offers more than device management; it also aids in user management. Regardless of the platform, Intune provides various options for device enrollment. Intune prevents mixing personal and corporate data, whether using a corporate or personal device. It also offers robust security features, enabling granular control over user access to applications, resources, and other tools.

In a hybrid environment, security management depends on whether devices are co-managed and how policies are configured in Intune. Intune offers various features, including remote actions, to address these scenarios. However, I discovered an issue with BYOD devices on iOS: wiping an enrolled device deletes all data, not just corporate data. This is a problem that needs to be addressed internally.

With the endpoint privilege management feature, the admin can create an EPM policy. If a user tries to access a resource, the admin will be prompted to grant or deny access based on the policy.

Suppose I need to access data, logs, or files on a Windows device that a global administrator restricts or requires approval for. In that case, I can configure an EPM policy to remind users that additional authorization is necessary. For instance, I encountered cases where users frequently mistakenly assigned test applications to production environments. To prevent this without restricting access or privileges, we configured an EPM policy to prompt users specifically when assigning that application to a production environment. This approach demonstrates how EPM policies can be tailored to address various requirements.

EPM provides an additional layer of authentication for accessing a resource, application, or permission. For ASR, we can define rules by which users can access the resources.

Intune has significantly improved productivity by simplifying tasks like certificate authority restoration. For example, using a deployed CA server certificate, I've set up a Wi-Fi profile with auto-authentication. Previously, expiring certificates required manual reissuance, but Intune automates this process by revoking certificates when they approach their expiration threshold. This threshold, configurable within the certificate profile, can be set as a percentage of the certificate's lifespan. A revocation request is triggered when the threshold is reached, ensuring a new certificate is issued for the device or user profile before the old one expires.

Intune's integration with Microsoft 365 and Microsoft Security for both cloud and co-managed devices is beneficial because it offers a centralized platform. We can directly assign licenses within Intune instead of using the separate M365 admin portal to create users, simplifying the process. Intune synchronizes features and functions from M365, streamlining management. However, purchasing new licenses still requires accessing the admin center. Despite this, Intune effectively synchronizes information to endpoints.

What is most valuable?

While conditional access isn't solely limited to Intune, we can also effectively implement and manage conditional access policies through Azure. However, Intune significantly simplifies application deployment, mobile application management, and policy enforcement, such as restricting user access to specific applications, thereby enhancing overall environment security. Furthermore, Intune automates numerous tasks previously requiring manual configuration by administrators, streamlining the process by creating simple policies for desired outcomes.

What needs improvement?

There are specific devices we can focus on. For example, due to GMS restrictions in China, we face limitations. However, BlackBerry UEM can enroll Android devices as Android Enterprise, though the exact method is unclear. We could explore whether Intune can replicate this functionality. Since GMS is unavailable in China, we currently rely on device administrator enrollment for managing Android devices there. This suggests potential opportunities to develop solutions or collaborate with Chinese partners to create new features within Intune for managing Android devices in the Chinese market.

For how long have I used the solution?

I have been using Microsoft Intune for three years.

What do I think about the stability of the solution?

While some specific tenants experience occasional outages and bugs, our monitoring team is actively tracking an upcoming issue affecting certain tenants in specific regions. Both the support and broader teams are diligently working to resolve this. Aside from this, Microsoft Intune is demonstrating overall stability.

What do I think about the scalability of the solution?

If an organization has the budget, they can easily scale Microsoft Intune.

How are customer service and support?

Microsoft's technical support for Microsoft Intune and the broader Microsoft environment consists of several tiers. Customers can choose between broad commercial support, Pro support, or Premier support, the latter including dedicated Customer Success Account Managers and Incident Managers to facilitate access to specialized engineers. Support engineers are categorized into levels one, two, and three. We collaborate weekly with global subject matter experts to address ongoing issues and cases. For complex or backend problems, we engage the product group using a specific request form. While Microsoft previously employed support staff primarily in the US and Canada, they now utilize vendors in India and the Philippines, offering varying levels of expertise. To enhance support quality, Microsoft should invest in training these engineers and consider opportunities for full-time employment, rather than incurring the costs of recruiting and training new staff.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?


How was the initial setup?

An organization migrating to the cloud typically requires an Azure subscription as a starting point. While our FastTrack Team offers full migration solutions, IT administrators can also independently move operations to the cloud by purchasing an Azure subscription, tenant, and licenses and configuring policies, privileges, and workloads. Existing on-premises infrastructure can be synced to the cloud using Azure AD Connect, enabling management within a hybrid or pure Azure AD environment. The ease of migration depends on the administrator's experience, and Microsoft support is available for those requiring assistance.

One to two solution architects are enough for the deployment.

Several factors influence the time required for deployment. For instance, with a user base of 100, deployment can be achieved within a week. However, environments with thousands of users and devices, especially on-premises setups, present greater challenges. Customers or administrators migrating to the cloud and adopting Intune often follow a phased approach. They typically start by deploying and testing a subset of policies to assess manageability and feasibility before proceeding with application deployment. As a result, the overall deployment timeline varies significantly across organizations and can extend to several weeks.

What's my experience with pricing, setup cost, and licensing?

Microsoft services are slightly more expensive than competitors but offer advantages and disadvantages. Even if they charge a premium, they aim to provide equal value.

Which other solutions did I evaluate?

I have experience with SOTI MobiControl, Jamf Pro, and AirWatch. SOTI MobiControl excels at managing specific devices, offering a list of compatible models upon request. Intune, however, struggles with printer management and Zebra device compatibility. Its network security features are limited due to ongoing development, and it lacks in-built policies for third-party applications, hindering compatibility and communication with external devices and manufacturers. While custom policies can be implemented, comprehensive built-in options would be beneficial.

What other advice do I have?

I would rate Microsoft Intune eight out of ten.

Intune requires no maintenance after initial deployment, but ongoing subscriptions are necessary for each user as individual licenses are needed monthly. Microsoft continually updates the service to support the latest operating systems and applications, so ensuring our environment is up-to-date is crucial for optimal performance.

Microsoft Intune is a good tool, and to simplify operations, I recommend a full cloud environment over a hybrid environment.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Microsoft Intune
July 2026
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,563 professionals have used our research since 2012.
Danny Nagdev - PeerSpot reviewer
Founder at LetsReflect
Real User
Mar 28, 2024
Very helpful for managing remote devices, but it is very costly
Pros and Cons
  • "Being able to manage the devices remotely is most valuable. We can push security requirements through Microsoft Intune."
  • "Cost is the biggest factor for us right now. Microsoft Intune and AD P1 together in a bundle is a good thing to have, but it is very costly compared to other products in the market. Otherwise, Microsoft Intune is the best."

What is our primary use case?

We are mainly using Microsoft Intune for the security of people who are working from home. It is being used for BYOD.

We enforce and push policies and enforce security requirements through Microsoft Intune. We also use it for deploying applications and monitoring the devices remotely.

How has it helped my organization?

Microsoft Intune has simplified our mobile application management a lot. Managing devices that are in users' homes is very tough without Microsoft Intune. Remote management is very easy because of Microsoft Intune.

For maintaining our device security, the best feature is that it works with Azure Active Directory Premium One license. There is conditional access, which is something very unique, so if a machine is compliant and Microsoft Intune is installed on it, only then users can access our Office 365 data. It is not just a feature of Microsoft Intune but also of AD P1.

Microsoft Intune brings all of our endpoint and security management tools into one place. It has made our IT and security operations easy. With a single console, we can manage our devices.

Microsoft Intune provides full endpoint visibility and IT control across device platforms.

Microsoft Intune is simple, and it does not interfere at all with users. Users do not even know that Microsoft Intune is installed on the machine.

Application deployment through Microsoft Intune has affected the IT productivity in our organization. Previously, our IT department used to take remote control of the machine using some software. They used to manually do the installation, whereas now, they can simultaneously push an application on all the machines through Microsoft Intune. That saves us a lot of time and manpower.

Microsoft Intune has been helpful for securing hybrid work and protecting data on company and BYO devices. We have deployed BitLocker policies through Microsoft Intune to ensure that the data is encrypted on those devices. We have also disabled USB pen drives and other things on remote machines.

Microsoft Intune has improved our IT productivity a lot because we have remote users. If our users were local, it would not help much, but because we have remote users across the country, it helps a lot.

The improvement in IT productivity has also saved us costs. Previously, we needed more people to do the installations, remote monitoring, and all that, whereas now, with the single console of Microsoft Intune, all these tasks are much easier. A single person can manage hundreds of computers. We need three people less now.

Microsoft Intune has helped to reduce the risk of security breaches in our organization.

Microsoft Intune has helped us to consolidate vendors. With Microsoft Intune, security management is there and mobile device management is also there. Both these things could have been from a different vendor.

Microsoft Intune integrates well with other Microsoft products. It works well with other Microsoft products. There is a seamless integration.

What is most valuable?

Being able to manage the devices remotely is most valuable. We can push security requirements through Microsoft Intune. We previously used to do this through group policy for Active Directory, and now, we use Microsoft Intune for managing devices. This is the best thing about Microsoft Intune.

Apart from Microsoft Windows, we can do remote device management of Android and iOS devices. We can enforce security policies for Android and iOS devices.

The user interface of Microsoft Intune is good. It is easy to use.

What needs improvement?

Cost is the biggest factor for us right now. Microsoft Intune and AD P1 together in a bundle is a good thing to have, but it is very costly compared to other products in the market. Otherwise, Microsoft Intune is the best.

Their support can also be better.

For how long have I used the solution?

I have been using Microsoft Intune for the last two years.

What do I think about the stability of the solution?

It is very stable. I have not had any issues. I would rate it a 9 out of 10 for stability.

What do I think about the scalability of the solution?

It is definitely scalable. I would rate it a 9 out of 10 for scalability.

How are customer service and support?

Their response time is poor, and the resolution capability is not good. Even after having a call with their customer care, there is a 50/50 chance of them solving the problem.

I would rate their support a 6 out of 10.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We did not buy any similar solution previously.

How was the initial setup?

For some customers, it is a hybrid deployment, and for some customers, it is a pure cloud deployment. Our customers are medium and large enterprises. They are not small businesses.

Its deployment is of medium complexity. If it is a hybrid environment, it is fairly complex. If it is a pure cloud environment, it is easy.

The deployment duration depends on the number of users we have or the number of computers we have. For a setup with 100 users or 100 computers, it takes about two weeks. It may require some troubleshooting and tweaking.

What about the implementation team?

One person is required for its deployment.

It does not require much maintenance from our side. It is normally always up to date. Once it is set, we do not need to touch it.

What's my experience with pricing, setup cost, and licensing?

I recently got to know that the AD P1 license is compulsory to use Intune Autopilot, which was surprising for me. Earlier, this was not the case. It is the wrong thing to do. We now need to purchase AD P1 licenses for us and for our customers. I would rate it a 7 out of 10 for pricing.

Which other solutions did I evaluate?

We evaluated a few solutions.

What other advice do I have?

I would recommend Microsoft Intune to others. If somebody has a Microsoft environment, Microsoft Intune is definitely the best solution for managing people who are working from home or remotely. 

It is improving day by day. New features are coming up.

I would rate Microsoft Intune a 7 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
System Engineer at a computer software company with 51-200 employees
MSP
Top 20
Aug 7, 2025
Replaces on-premise tools and enables us to almost completely manage a machine
Pros and Cons
  • "We were able to deploy about 65 computers in under two weeks to a completely remote user base without touching any of the machines."
  • "Every time we call, we get bounced to a new team... there is no cohesive end-to-end support, which is very frustrating and time-consuming."

What is our primary use case?

The main use cases that I had or have with Microsoft Intune include laptop deployments coupled with Autopilot and day-to-day management of laptops, including patching.

How has it helped my organization?

We were able to deploy about 65 computers in under two weeks to a completely remote user base without touching any of the machines. This year was a pure cloud environment. We got rid of their Active Directory joins, and they are running purely in a cloud environment.

What is most valuable?

The features that I find the best with Microsoft Intune are its ability to completely replace all the on-premise tools for group policy and similar functions. It now gives the ability to almost fully and completely manage a machine. 

When I first started, the user experience was okay, but it has improved significantly over the last few years.

What needs improvement?

Autopilot still leaves room for improvement regarding monitoring deployments and troubleshooting deployments.

For how long have I used the solution?

I have dealt with Microsoft Intune for approximately four and a half to five years.

How are customer service and support?

I would rate Microsoft support as six out of ten. This is a challenging area because every time we call, we get bounced to a new team. This is an area they could improve. Each time you call in, they tell you that it is not their team's responsibility. You get partway through the solution, and then they say that at this point it becomes another team's responsibility, so you have to start over with them. There is no cohesive end-to-end support, which is very frustrating and time-consuming.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before using Microsoft Intune, we were using a fully manual process, and we transitioned from fully manual to fully automated.

How was the initial setup?

It is straightforward in terms of the UI, but it can be complex to set up because you are working blind with everything on the machine.

What's my experience with pricing, setup cost, and licensing?

Microsoft Intune is not cheap. Microsoft has consistently separated features and charges additional fees, which makes it a much steeper climb from a budgeting aspect because you need to buy something new frequently.

Which other solutions did I evaluate?

We did not consider other options. Microsoft Intune was our preferred and first choice, and we were going to look at anything else only if it failed, which it did not.

What other advice do I have?

We are not using Copilot in Microsoft Intune yet. We are just starting to use the advanced endpoint analytics in the Microsoft Intune suite. Initially, we could not use them because we did not have licenses for them, so we are just transitioning over to them. The advanced endpoint analytics are helping us with detecting and remediating anomalies and endpoints. We have used these capabilities to find old certificates and unexpected web browser extensions, but since we are just getting started, I am not sure of its full capabilities.

I would wholeheartedly recommend Microsoft Intune to others but advise being prepared for an ever-growing cost.

I would rate Microsoft Intune an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer961707 - PeerSpot reviewer
Enterprise Mobility Engineer at a computer software company with 11-50 employees
MSP
Top 20
Sep 3, 2024
Offers ease of use but needs to improve the tunnel gateway
Pros and Cons
  • "I have seen a return on investment right from the start of the tool's usage."
  • "The tool's tunnel gateway is not very good, making it an area where improvements are required."

What is our primary use case?

My company has over 7,000 devices, including mobile devices, Windows, and Mac. The tool is only used to manage my team's mobile devices.

What is most valuable?

The solution's most valuable features are its ease of use and control of the MAM and MDM policies and configuration. The tool is straightforward and easy to use, while it also integrates with Azure. It has been a good product so far.

The tool has improved the way my team works as it is a cloud-based tool, so we don't have to manage on-prem servers. We also use apps on Microsoft Office 365, which is also one of the main reasons why we use Microsoft Intune.

I use the enterprise application management features of the tool, and my experience with it has been pretty good. Microsoft tells us that there are no bug issues with the updated versions or current versions, so there are no issues in the tool.

I use Microsoft Intune's Cloud PKI, and it helps manage the complexity of certificate management in infrastructure pretty well. There are no issues with certs or updating them.

Microsoft Intune has not affected my IT productivity, but it is not a very Android-friendly tool. We have had a lot of Android issues and compatibility problems with our VPN or tunnel. The tool is not very Android-friendly.

The maintenance of the tool is a lot less now for our company.

With the day to day device management tasks, the tool has been great, and there have rarely been any issues with it.

The mobile application management policies, specifically conditional access policies and app protection policies, are good features for managing diverse mobile environments. The DLP part is very strong.

What needs improvement?

The tool's tunnel gateway is not very good, making it an area where improvements are required. I wish it weren't so Azure's security group-based tool with which you can have local accounts. More personalization should be possible in the tool. One negative about Microsoft Intune is it acts too much as one of Azure's group-based products.

For how long have I used the solution?

I have been using Microsoft Intune for half a year. I am just a customer of the solution.

What do I think about the scalability of the solution?

I think the scalability is pretty easy and a lot easier to manage since we don't have to deal with the on-premises side. We use the cloud for extra storage, so it has been great.

How are customer service and support?

My experience with the solution's technical support has been very good, but for other teams, it has not been very good. I rate the technical support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

My company previously had some on-premises tools, but now it is cloud-based, so we save all the money on the network infrastructure and data centers. We don't need servers or storage, and it helps us save money.

How was the initial setup?

When it comes to the product's deployment phase, I have taken part in the mobility side. In our company, we went through a migration, so there is always a lot of planning and testing and all that goes with it. Overall, it is fairly easy to use because it is deployed on a SaaS model.

The solution is deployed using a dedicated SaaS model. I think other teams have deployed it using an on-premises model.

The solution's deployment phase took a year and a half to test and set up everything. There was a lot of stuff involved.

What was our ROI?

In our company, prior to our migration, we already had Office 365 licenses, so it saved us around 4,00,000 for around a year.

I have seen a return on investment right from the start of the tool's usage.

What's my experience with pricing, setup cost, and licensing?

I don't really know how much it costs, as my company pays for a bunch of licenses. The tool is cheaper than our company's other MDM tools.

What other advice do I have?

My company has a few of Microsoft Intune's compliance policies that have helped us with some of the issues with sync interval with the compliance that we have noticed. The sync interval or the turnaround is not as quick as our company would like it to be currently. I understand that we can't control the sync interval.

I rate the tool a seven and a half out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Intune Administrator at Vvolve management consultants
Real User
Top 20
Sep 2, 2024
An easy platform for device management, security, and productivity
Pros and Cons
  • "Intune saves time, and it is very easy to use. It allows us to manage applications completely."
  • "If we could remote into a device, it would be great. Currently, we cannot directly connect to the user device. We have to use other tools such as VMware for connecting to devices."

What is our primary use case?

Intune is a cloud-based platform for mobile application management and mobile device management. We can deploy applications on user devices and enroll user devices. We can enroll devices as per the organization's security policies. The devices comply with all the policies of the organization. We can also change the policies at the backend via Intune.

How has it helped my organization?

Intune helps with enrollments and securities. We can control the access to devices and users. We can specify what users can do. We can give role-based access. For example, a person working as a normal user does not require the same access as a manager. We can give access to users based on their roles. For example, a manager can add users to a particular group, but users cannot do that. We can restrict a user from doing certain activities. For example, we can restrict the user from using a camera or microphone. We can do such a configuration at the backend and deploy it to the user device.

Intune is very helpful for IT and security operations. If Intune is not there, we have to manually connect to user devices and deploy the changes. If we have thousands of devices, doing this manually on each and every device is very difficult. With Intune, we just configure the required settings and deploy them to a thousand devices in a single group. In a single step, we can add devices to a group. We can apply configuration easily. It is very helpful. It saves time. Adding or configuring devices manually takes a few months, whereas the same thing can be done with Intune within minutes.

We have had a very good experience. It is a Microsoft product. Everything related to a user is available. We have user names, user devices' names, and user licenses. We can also check the device compliance. We can see whether the device complies with the company policies or not.

Application updates and patching are available through Intune. We can also change group policy settings and registry settings of a device via Intune. We can change these settings without connecting the device. We can do that by deploying the PowerShell script or configuration profiles. For example, a kiosk device should stay up for hours and hours. It should not go to sleep. You can configure such devices to not go to sleep until 999 minutes. It is a very long time. If we enable such settings and add a particular user device group in the configuration, after the device starts syncing with the policy, no device will go to sleep.

With the Advanced Endpoint Analytics, we can see the application installation status. If we deploy a script to the user, we can see the status. We can see if it is a success or if there is a conflict. We can monitor the changes in user devices and check the compliance status. We can see if any app such as CrowdStrike is not updated.

With the help of Advanced Endpoint Analytics, we can proactively detect and remediate anomalies in endpoints. We can then reach out to users.

Intune saves us a lot of time. If we package an application using virtual packaging or physical packaging, it will take nearly two to three hours to package a single application. If we do this in Intune, it takes just minutes to add applications and deploy users. We can also monitor the particular application status in Intune.

The devices that are linked with Azure Active Directory are automatically linked with Intune. That makes the enrollment and management of BYO devices easy.

Intune has affected IT productivity in our organization. By saving time, it has automatically improved productivity.

Intune certainly saves costs. Without a cloud-based solution like Intune, we would require more IT staff.

What is most valuable?

Microsoft releases updates every second Tuesday. We can deploy those updates from Intune. We can also do patching through Intune. We can do quality updates and feature updates from Intune. We can also monitor the application status in Intune. We can see which applications are installed, pending, or available to install. We can see these things in Intune.

It is user-friendly. We can also troubleshoot any issues.

Intune saves time, and it is very easy to use. It allows us to manage applications completely.

What needs improvement?

If we could remote into a device, it would be great. Currently, we cannot directly connect to the user device. We have to use other tools such as VMware for connecting to devices.

If there are any issues, we should be able to connect through the Intune portal. The administrator should not have to go anywhere from the portal. He should be able to do everything from the portal.

Intune does not show whether a device is online or offline. It just shows the last login. It would be useful to know whether a device is online or offline.

We can see the issue related to updates in the Intune portal, but we cannot do anything from the Intune end. We have to connect to the user's device manually. We also need a better understanding of why the update is not happening on a particular device. It will decrease the time to troubleshoot the issues.

At times, there have been slowness issues with the company portal. It takes time to load and does not show the application status.

It would be great if there is a way to generate a PowerShell script to do certain things. Learning the PowerShell script is not easy, so such a feature would be helpful. Based on what we want, if it can automatically generate a script, it would be helpful.

It is not necessary, but it would be great if they added a messaging system in Intune. For example, when it is a shared device, a number of users log in to the device. In the case of any issue, it would be great to be able to directly message a user from Intune. Currently, there is no option for that, but if it could be done, it would be a very good thing.

For how long have I used the solution?

I have been working with this solution for the last 18 months.

What do I think about the stability of the solution?

It is 100% stable.

What do I think about the scalability of the solution?

It is very scalable.

We have about 12,000 devices and 20,000 users.

How are customer service and support?

So far, I have not raised any questions with them.

Which solution did I use previously and why did I switch?

I have worked with Microsoft SCCM. It is similar to Intune but not as user-friendly as Intune. Intune is very easy to understand. Its framework is very good. Microsoft SCCM is very old.

I have not worked with any other vendor. 

How was the initial setup?

I am involved in the deployments, enrollments, troubleshooting errors, and monitoring in Intune. I take care of adding devices, users, and licenses, deploying policies, and configuring policies and scripts.

Its deployment does not require much. We just need a license to operate it. Our management takes care of that. There are a few licenses that are active only for nine hours. After nine hours, the roles are deactivated.

It does not require any maintenance from our end.

What's my experience with pricing, setup cost, and licensing?

Intune is linked with Microsoft. We can deploy the Microsoft E365 license to users by Intune. There are different types of licenses, such as device administrator licenses, E5 licenses for device enrollment manually, and P1 and p2 licenses for device enrollment automatically. These are the licenses required for the administration.

Which other solutions did I evaluate?

I did not evaluate any other option. This was my first project, and I started as an Intune administrator.

What other advice do I have?

It is a very good tool. It is easy to learn. You can expect quick assistance from Intune.

Before using Intune, I would recommend learning about Windows. Learn about the registry, configurations, and group policies. If you know these, it is easy to learn Intune.

You can face enrollment errors if the prerequisites are not met. For example, to upgrade from Windows 10 to Windows 11, you need to have some amount of free space or RAM. If you do not care about the prerequisites and just enroll the device, it causes issues. It will affect the device, and you need to enroll the device again.

I would rate Intune a nine out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Aekantak Vashistha - PeerSpot reviewer
Cloud Engineer III at Insight
Real User
Top 20
Aug 8, 2024
Intune centralizes device, application, and policy management, enhancing IT efficiency and security, though some custom deployments require additional innovation.
Pros and Cons
  • "I like how Intune brings everything into one place. For example, you can set up conditional access to applications and devices inside Intune. I also like the segregation inside the Intune devices. You can segregate them by Windows, iOS, iPadOS, macOS, and Android. You can sort it by platform, so you don't need to go into the devices section."
  • "I rate Microsoft support four out of 10. Support is one area where Microsoft needs to improve a lot. I recently raised a ticket for a Microsoft Azure issue, and it took two and a half weeks for support to reply. They need to improve support across their entire catalog of products."

What is our primary use case?

You can use Intune to manage devices for any size project, from a small business to an enterprise-level project. You can manage hundreds of thousands of devices. Intune can manage on-prem and cloud services. We are working with large enterprises mostly.

How has it helped my organization?

Intune encompasses all devices, applications, and policies that can be deployed within an organization through a single portal. In the event of an outage, it simplifies the management and resolution of issues or policy adjustments. It allows for the management of security profiles, applications, and devices from one portal across any operating system platform.

Consolidating everything in one location enhances the efficiency and productivity of IT administrators. Since adopting Intune, our IT team's productivity has increased by 20 to 30 percent. Additionally, the integration of Copilot has further improved our efficiency by 5 to 10 percent.

However, there are exceptions. Certain applications cannot be deployed easily via Intune. Win32 deployment is necessary for these, which can be challenging as it demands extensive testing to release a custom package from Intune. More innovation is needed to deploy custom applications, which would greatly benefit us. For most enterprise scenarios, application deployment is relatively straightforward.

Hybrid environments call for innovation, particularly with hybrid enrollments using GPO. While most autopilot hybrid scenarios and co-management run smoothly, I have encountered issues with hybrid GPO enrollments due to their complexity.

Intune is a leading secure solution in the Indian market. It allows the creation of any conceivable security policy. With the addition of Purview and DLP modules and integration with Microsoft Defender for Endpoint, security has never been a concern, and our security posture is nearly impeccable.

Intune has also facilitated vendor consolidation. It is our primary recommendation for an MDM solution because it offers the productivity and features that would otherwise require integration of multiple solutions from other vendors. The industry is now transitioning from on-premises Intune to cloud-based management.

Intune enables the deployment of any security solution. Although it does not integrate, it allows for the deployment of a wide range of security measures.


What is most valuable?

I appreciate how Intune consolidates everything in one location. For instance, it allows the setup of conditional access for applications and devices directly within Intune. The segregation feature within Intune devices is also beneficial. Devices can be categorized by Windows, iOS, iPadOS, macOS, and Android, and sorted by platform, eliminating the need to navigate the devices section.

The app management feature has seen significant improvements. Initially, navigating the app section was quite challenging, but now, all my concerns have been addressed. It's possible to deploy or manage any application, with reports and app-protection policies accessible in the same section, which is quite convenient.

I would rate the user experience at nine out of 10. Having utilized various MDM solutions from Microsoft, Cisco, and VMware, I find Intune to be superior. We employ Microsoft Defender for Endpoint and DLP policies in Purview, along with multiple security policies such as baselines and BitLocker for encryption. This integration simplifies the administration of security features from other tools in one place.

The most sophisticated analytics we've utilized are group policy analytics. As a consultant, I often handle multiple migrations, primarily from on-premises to the cloud. Group policy analytics are particularly useful in these scenarios as we migrate on-premises policies. If Intune lacks support, we must either start anew or seek alternatives.

Copilot is beneficial as it supports various CSPs or policies. Despite extensive use, one cannot be fully versed in everything about Intune. Whenever there's confusion, Copilot is a valuable resource to clarify and ensure the feasibility of creations within Intune. Copilot assists in profile creation and assignment considerations.

My perspective on tools like Copilot is that they are artificial; the intelligence aspect is still emerging in the AI industry. Nevertheless, Copilot is a well-maintained and informed tool.


What needs improvement?

Microsoft currently restricts deployment to PowerShell or XML scripts, so it would be beneficial to support additional scripts such as command scripts, C languages, or TypeScript to enhance systematic compliance.

While the UI has been updated, it could be made more accessible. Navigating to a specific section in Intune requires multiple clicks through different areas before arriving at the intended destination, indicating the UI could benefit from further improvement.

The process of application discovery and deployment is relatively seamless. Nonetheless, there is room for enhancement in the reporting aspect. Intune still lacks comprehensive reports, and notably, its failure reporting does not succinctly communicate the full extent of an error.


For how long have I used the solution?

I have used Intune for more than six and a half years. 

What do I think about the stability of the solution?

I rate Intune 10 out of 10 for stability.

What do I think about the scalability of the solution?

With Linux and Chrome OS now supported, the scalability has reached 100 percent. Every device or endpoint operating on our OS can be enrolled in Intune. 

How are customer service and support?

I would rate Microsoft support as four out of ten. Support is an area where Microsoft could significantly improve. I had an issue with Microsoft Azure recently, and after raising a ticket, it took two and a half weeks to receive a response. There is a need for enhanced support across all their product offerings.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We have utilized Cisco Meraki, VMware Workspace ONE, and Jamf for managing Apple devices. However, Intune stands out among these options because it overcomes application deployment limitations that others have. While some support only Apple or Windows devices, Intune excels in compatibility, supporting Android as well. Moreover, Intune can implement more security policies than any other MDM solution available.

How was the initial setup?

Hybrid enrollment is typically complex, yet cloud autopilot simplifies the process considerably. It's possible for anyone to grasp cloud deployment within five to ten minutes. While the most intricate enrollments, involving thousands of devices, may take two to three weeks, a cloud-based deployment can be accomplished in approximately one week.

What about the implementation team?

This was completely in-house.

What's my experience with pricing, setup cost, and licensing?

Intune is considered moderately priced. It is available as part of a bundle with Microsoft 365 E3 or E5 licenses. While the E5 licenses are somewhat costly, Intune offers some more affordable solutions.

Which other solutions did I evaluate?

Yes, we evaluated Cisco Meraki and VMware workspace One.

What other advice do I have?

I give Microsoft Intune a rating of nine out of ten. Intune stands out as one of the top solutions in the market, and its capabilities are expanding with the integration of cloud PCs, Chrome OS, and Linux systems. For any large enterprise, I endorse both Intune and Defender.

The recent CrowdStrike outage, which is the largest in IT history, affected only systems without Microsoft Defender but with CrowdStrike. This incident underscores the importance for enterprises to transition towards deploying Intune and Defender for enhanced security.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
End User Computing Architect at a consultancy with 10,001+ employees
Real User
Apr 16, 2024
Simplifies IT and security operations and enrolling endpoints is a breeze
Pros and Cons
  • "A valuable feature is user enrollment, where users can enroll their devices in their organizations themselves."
  • "The current Intune reporting functionality could benefit from some improvements."

What is our primary use case?

We use Intune to manage endpoints as a centralized enterprise solution. Instead of relying on Active Directory or an on-premise system, we directly manage employee devices using Microsoft Intune. Intune, a cloud-based SaaS product, simplifies endpoint management. From a user perspective, it's an improvement. Users no longer need to be on the office network. They can set up their devices anywhere with an internet connection, whether at home or another location.

Security is also enhanced. By using Intune as a mobile device management solution, we can implement security controls and restrictions on endpoints. Intune helps us achieve a balance between user experience and security.

How has it helped my organization?

Managing remote employee devices with Microsoft Intune is easy. Intune acts as a central platform for deploying controls, policies, and applications to our endpoints. It simplifies the delivery of these configurations to our remote workforce.

Intune simplifies our mobile application management. Once implemented across the organization, it will eliminate our reliance on on-premises solutions. Previously, managing endpoints required using our System Center Configuration Manager. Now, Microsoft offers a unified solution called Microsoft Endpoint Manager. Intune, a key component of this suite, allows for convenient device enrollment over the internet, streamlining endpoint organization.

Intune helps bring our endpoints and security management tools into one place.

Consolidating endpoints and security management tools simplifies IT and security operations. This unified approach offers a single solution or console for all tasks. Role-based access control ensures each administrator only sees and modifies what's relevant to their role. For example, the security team can access Intune solely for security-related functions, while the patch management team has its own set of permissions. This centralized management is significantly easier to handle than using multiple third-party tools. Intune provides a comprehensive solution where everyone can configure settings – security, endpoints, controls, etc. – within a single platform.

Intune offers endpoint visibility and IT control across various device platforms. It simplifies troubleshooting and device management compared to other solutions. Intune excels in providing a comprehensive solution. We can manage applications, security controls, and patching processes all within Intune. This eliminates the need to rely on three separate solutions. With Intune, everything is consolidated into a single platform, allowing for combined reporting and streamlined issue resolution.

Enrolling endpoints with Intune is a breeze! The overall user experience is excellent, easily a nine out of ten.

There are three critical features of Intune for maintaining our devices' security. Endpoint encryption ensures data on the device is scrambled even if it's lost or stolen. Intune supports BitLocker encryption for Windows devices and file-level encryption for Mac devices. Defender is a comprehensive security solution that helps protect devices from malware, viruses, and other threats. Compliance policies in Intune allow us to define security requirements for devices. These policies can enforce encryption, complex passwords, and other security settings. If a device doesn't meet the compliance policy, it can be restricted from accessing organizational resources. Intune can also send notifications to users or administrators when a device becomes non-compliant.

In the initial stages of migrating from our on-premises solution to Intune, we relied on device compliance policies. We configured these policies to require the latest antivirus signatures, specifically targeting developer devices. This ensured compliance and minimized the risk of non-compliance impacting their work. While compliance policies were initially used, we've since transitioned to Microsoft Defender, which now plays a major role in our device security strategy.

Intune's application deployment feature has significantly improved efficiency in our IT department. As one of its key functionalities, Intune allows deployment of a variety of applications with different extensions, such as .DXE or .MSI files. However, for applications requiring custom license scripts, batch files, or executables, Intune provides its own Windows app deployment toolkit. This toolkit facilitates the conversion of these files into a format compatible with the Intune app store and its update system.

The user interface is easy to navigate. Microsoft provides monthly updates that introduce new features. Previously, they provided pie chart visualizations for complaint and policy control status reports. These have been transitioned to standard chart formats. Overall, the UI continues to improve with each Microsoft update.

Company-owned devices are subject to a different set of policies. These policies may be very strict, restricting certain functionalities, or they may prioritize security above all else. On the other hand, for BYOD programs, we provide users with certain privileges for their mobile devices and laptops. We create a secure, isolated environment in a sandbox to manage the devices within that environment. Security is a major consideration for both BYOD and company-owned devices.

Intune has increased our IT productivity for patching and security by around 15 percent.

Microsoft Intune helps our organization reduce the risk of security breaches by eight percent by deploying zero-day patches in conjunction with Defender and Sentinel.

Intune has helped us consolidate vendors with the driver deployment and onboarding.

We manage configurations for Microsoft 365, co-managed devices, Azure, Defender security controls, and DLP controls within Intune. This centralized platform allows us to configure roughly 80 percent of these services and controls in a single location.

What is most valuable?

A valuable feature is user enrollment, where users can enroll their devices in their organizations themselves. This streamlines the process and saves IT time.

Another key benefit is zero-day productivity. During enrollment, the user has access to the applications and settings the organization needs them to have, making them ready to work immediately. Intune essentially pre-configures the device based on the user and organization during enrollment.

Finally, Intune offers easy patch management for various endpoints, including Windows 10, 11, and Macs. Deploying upgrades and monthly patches is significantly simpler compared to other solutions, both from Microsoft and third-party vendors.

What needs improvement?

The current Intune reporting functionality could benefit from some improvements. Specifically, a report that tracks patch deployment status would be valuable. Ideally, I'd like a report that provides device-level details on applications and controls deployed. However, it seems like other organizations might be more interested in control-centric reports, showing details like what control was deployed, the number of devices affected, and other relevant device data. Overall, reporting is the area where we're encountering the most challenges with Intune.

For how long have I used the solution?

I've been using Microsoft Intune as a comprehensive solution for the past six years. While I had some experience with it before 2019, it was limited to mobile device management. Since 2019, I've been managing the full Intune suite as an administrator, overseeing Windows endpoints, Mac endpoints, Android and iOS.

What do I think about the stability of the solution?

I would rate the stability of Microsoft Intune eight out of ten.

What do I think about the scalability of the solution?

Microsoft Intune excels in scalability, earning it a nine out of ten rating. It empowers organizations to migrate to the cloud and manage all their endpoints seamlessly. This includes a wide range of platforms like Windows, macOS, mobile devices, and even Linux. Intune simplifies endpoint management by offering a centralized solution for all these platforms.

How are customer service and support?

The response time and technical knowledge of the support team is not what it used to be.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used an on-premises solution, Microsoft Endpoint Manager, to manage our devices. The pandemic necessitated a shift to the cloud.

How was the initial setup?

The initial deployment of Intune can be complex because it is linked to Microsoft Entra, which itself is a complex product. This complexity depends on the desired outcome. Intune's deployment complexity hinges on whether users will enroll their devices themselves or if the IT team will enroll them and grant access. A proper pre-assessment is crucial to determine if Intune's complexity aligns with our desired outcome.

Our deployment took two months to complete because of the internal security approvals we required.

Three administrators were required for the deployment.

What's my experience with pricing, setup cost, and licensing?

The price for Intune is fair.

What other advice do I have?

I would rate Microsoft Intune eight out of ten. There are some improvements concerning the reports and there are other design-related concerns that we are looking at in Intune.

We don't have the tunnel option because we primarily work in a restricted computer environment. Our organization uses Microsoft Intune to manage applications within a dedicated sandbox environment. We perform frequent updates to ensure everything is current.

During the initial onboarding process, we encountered some challenges, and multiple teams were involved in resolving them. For example, users from India might experience issues like broken URLs or restricted access due to their ISPs. Similarly, in China, certain URLs might be blocked by some internet service providers. To address these issues, we initially involved additional administrators from each region on the administrative side. However, we've since transitioned to a centralized management structure with a core team of five to six members overseeing the entire organization.

We maintain a separate development Intune environment for User Acceptance Testing specific to the Asia Pacific region. Since our production environment is also located in Asia Pacific, we essentially have two Intune instances: one for development and one for production. We also have around 290,000 devices.

We have a team of five Intune administrators. The only maintenance required for Intune is the updates.

I recommend Microsoft Intune.

Based on the number of users and devices you're enrolling, I recommend having separate UAT and production Intune environments for larger deployments. For simpler environments, a single Intune license is sufficient to manage your devices and integrate with your Enterprise and Microsoft 365 solutions.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MichaelSoliman - PeerSpot reviewer
Owner at Alopex ONE UG
Real User
Top 5Leaderboard
Jan 18, 2024
Streamlines device and application management across diverse platforms, offering centralized control, security compliance, and enhancing organizational efficiency
Pros and Cons
  • "One of the most valuable aspects of Microsoft Intune is its seamless integration with Azure Active Directory, offering capabilities akin to Group Policy Objects."
  • "Having a dedicated configuration server that assists in modifying the configuration service, and creating personalized structures, interfaces, and web services could enhance usability."

How has it helped my organization?

While Microsoft Intune offers centralized management and policy enforcement, it doesn't consolidate all endpoint and security management tools into a single platform. To comprehensively safeguard systems, additional solutions such as Microsoft Defender for Endpoint are necessary.

Achieving comprehensive endpoint visibility and IT control across various device platforms is a complex task, considering the diversity and freedom inherent in different systems. However, when it comes to deploying and managing devices like tablets, mobile phones, laptops, and specialized devices in Germany, a systematic and organized approach is crucial. Particularly noteworthy is the ability to configure IoT devices, such as numerous thermostats, water control systems, or sprinkler devices. Without a solution like Intune, scaling becomes a challenging issue, especially when dealing with thousands of such devices. Therefore, the use of a system like Intune becomes imperative in addressing these scaling challenges and ensuring effective device management.

On a scale of one to ten, I would rate my user experience with Intune as a six. The lack of intuitiveness makes it cumbersome to track and understand what needs configuration, especially when dealing with aspects like OneDrive and having to cross-reference settings across different areas of Intune.

In the context of securing hybrid work with Intune, our experience involved a two-day effort to configure the certificate for the Conditional Access server. However, once this initial setup was completed, we successfully configured VPN access for mobile phones. Despite the initial complexity, especially for a large company, Intune delivered on its advertised promises and proved effective in fulfilling the intended security functions.

Intune's effectiveness in securing data on company and BYOD devices is based on distributing security configuration data. While valuable, Intune has limitations, and comprehensive protection against cyber threats requires a sophisticated approach, including hybrid artificial intelligence solutions like Microsoft Defender for Endpoint. While Intune aids in system configuration, detecting and preventing attacks demands a more advanced defense strategy, comparable to sophisticated endpoint protection. Hybrid AI, with continuous human input, enhances threat evaluation, recognizing nuanced situations like suspicious timings in actions on developer endpoints.

It positively impacted IT productivity within the organization by enabling the secure addition of thousands of mobile phones to the VPN. In this regard, it performed effectively.

It played a crucial role in mitigating the risk of security breaches by securely distributing VPN certificates. While effective in this aspect, it's important to note that this alone is not sufficient. Endpoint security, such as developer endpoints, is analogous to having specialized tools for reading and managing complex systems.

It significantly contributed to cost savings. Manual configuration for each mobile phone would have taken approximately an hour per device per year, amounting to three or four thousand hours annually. However, with Intune, we accomplished the task in two days for five thousand devices, equivalent to around one hundred sixty hours. This resulted in substantial efficiency, reducing the effort from an ongoing five thousand hours per year to a one-time investment of a hundred sixty hours.

What is most valuable?

One of the most valuable aspects of Microsoft Intune is its seamless integration with Azure Active Directory, offering capabilities akin to Group Policy Objects. This integration provides a centralized platform for managing and enforcing policies, ensuring the stability of configuration data across devices, resembling the familiar functionalities of traditional group policies in an on-premises Active Directory environment.

In utilizing Intune's endpoint privilege management feature, I've primarily focused on configuring VPN access and certificates, although I'm not an Intune specialist. It's versatile enough for both configuring VPN access and managing large-scale IoT servers. For instance, in building management systems, especially in large structures like bank buildings, where numerous actuators are involved, configuring and securing them becomes a complex task. Intune proves valuable in this context. However, it's essential to recognize that while Intune serves as a powerful tool, relying solely on it is insufficient for comprehensive system security.

The integration of Intune capabilities with Microsoft 365 and Microsoft Security is crucial. As mentioned earlier, securing your machine requires tools like a developer endpoint, and relying solely on Intune may not be sufficient. While Intune allows configuration and deployment of Defender for Endpoints, having a dedicated tool is essential. The unique selling point of Microsoft lies in its seamless integration, especially notable for those working with Linux systems, where Microsoft's comprehensive integration sets it apart.

What needs improvement?

In terms of configuration, my experience with Intune is somewhat mixed. The configuration tool appears to be scattered throughout the Intune interface, requiring frequent navigation back and forth. The web interface, while functional, isn't particularly user-friendly, leading me to find PowerShell a preferable option. However, using PowerShell involves investing time in developing scripts. The challenge lies in the complexity of navigating between profiles and MDM configurations. Multiple windows need to be open simultaneously to grasp the overall configuration landscape.

I wish there was an improvement in the configuration process, as currently, it involves navigating through different locations with multiple windows open. Having a dedicated configuration server that assists in modifying the configuration service, and creating personalized structures, interfaces, and web services could enhance usability.

For how long have I used the solution?

I have been working with it for three years. 

What do I think about the stability of the solution?

When evaluating stability, it's essential to consider the multitude of adversarial attempts, particularly from military opponents engaging in hacking activities. Microsoft has demonstrated its capability to withstand and defend against such sophisticated attacks, setting a high standard for security.

How are customer service and support?

Considering the extensive number of support calls, I believe Microsoft handles them as effectively as possible. I would rate its customer service and support eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In the past, we utilized Windows services.

What about the implementation team?

The number of people required for deployment depends on the specific tasks at hand. For instance, implementing the VPN solution involved five individuals, including specialists for firewalls and virtualization for the server endpoint. If the focus is solely on Intune-related tasks, one expert may be sufficient. However, in typical scenarios where Intune is used for onboarding machines or mobile device management, you'll need administrators with access to the relevant machines. It functions as a collaborative administration tool, and the required personnel would depend on the number of departments involved.

What's my experience with pricing, setup cost, and licensing?

The pricing is inherently reasonable, as Microsoft leverages market insights to maintain the total cost of ownership at around ninety to ninety-five percent of what would be incurred in an on-premise scenario. Microsoft products inherently benefit from economies of scale and global reach, making them cost-effective.

What other advice do I have?

It aids in vendor consolidation; otherwise, we would have had to manually configure around three thousand mobile phones.

It impacts the security posture positively when you are aware of what you configure and can update configurations promptly. However, as mentioned, the need for artificial intelligence in Endpoint Protection remains crucial.

I would recommend subscribing to reputable YouTube channels that focus on Intune or related topics. Building a strong foundation and gaining practical experience is crucial to understanding the intricacies of Intune. Overall, I would rate it eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Amel Benali - PeerSpot reviewer
Head of Technology at a manufacturing company with 501-1,000 employees
Real User
Jan 17, 2024
Streamlines device management, enhances security and improves IT productivity through its features
Pros and Cons
    • "It would be beneficial to have a more straightforward understanding of Intune's capabilities, presented in a simplified manner."

    What is our primary use case?

    It serves as our EDM, enabling remote computer management. We install various applications directly for users, granting us administrator-level control over the computers.

    We utilize it exclusively within the IT department to manage all hardware from a single location.

    How has it helped my organization?

    It consolidates all endpoint and security management tools into a single platform. This allows us to efficiently determine the required applications for each employee. Having Azure Active Directory integrated into the complete environment further simplifies the process. Additionally, its compatibility with Android-based devices is a significant advantage, enabling the management of both Windows PCs and Android devices from a unified platform.

    It offers complete visibility and IT control across various device platforms, saving us a significant amount of time. The alternative, handling devices individually each time there's a change in employee or any other scenario, is much more time-consuming.

    When it comes to the user experience of Intune, the initial setup is quite straightforward, but delving deeper into its functionalities demands additional training and familiarity. This complexity can be considered a drawback. The policies that can be configured sometimes lack clarity, and understanding the limitations for users who aren't global admins can be unclear.

    We don't utilize the MAM tunnel feature for remote access to corporate resources. Instead, we rely on TeamViewer for remote support when dealing with any issues.

    It significantly enhanced our organization's efficiency, particularly in terms of time savings. While I don't have the specific numbers at the moment, the impact was substantial. Especially when we operated with a small IT team, the investment in the license cost was undoubtedly worthwhile.

    In terms of securing hybrid work environments and safeguarding data on company and personal devices, there's flexibility to fine-tune policies for preventing certain actions. Currently, our approach restricts employees from installing unauthorized software, acting as a deterrent to Shadow IT. However, we haven't explored the full spectrum of possibilities with policies to uncover additional security measures.

    The impact of Intune on the organization's security is essentially a peace of mind for me. If there's ever a report of a stolen computer, I can swiftly lock it without much concern. The speed at which this can be done is particularly reassuring, especially in the current landscape of hybrid work where such incidents tend to occur more frequently than before.

    It has significantly impacted IT productivity in our organization. Onboarding and offboarding processes have become much faster. Simply Intuning the device and managing it through the internal portal or even within the VPN network streamlines the workflow. This is especially beneficial since our company supports hybrid work, extending flexibility to the IT staff as well. Inventory management has also seen a notable improvement, with less time spent. Now, we not only have a count of devices but also know which accounts they are associated with. Compared to our previous reliance on paper and Excel, this is a whole new level of efficiency. Overall, it has been an extremely positive experience for us.

    While it's challenging to directly quantify cost savings, Microsoft Intune has certainly resulted in significant time savings for our organization. As we didn't have a comparable system before, it wasn't a matter of moving from something else to Intune. However, the investment has proven valuable, especially evident in the offboarding process. Previously taking fifteen to twenty minutes per device, it has now been streamlined to just a few clicks, around five minutes. This efficiency has been particularly impressive and has undoubtedly saved us considerable time.

    What is most valuable?

    Its most valuable aspect is the seamless onboarding and offboarding of new users, whether it's for a computer or a mobile device. This process is remarkably straightforward. Additionally, while not explicitly security features, there are safeguards in place that enhance safety. For instance, if a user reports their computer as stolen, you can promptly lock it and erase all data remotely. This means you can secure the hardware even without physical possession of the device. It goes beyond safeguarding just the Microsoft 365 user account; it extends protection to the hardware itself. It also served as a means to efficiently manage our inventory. Through Intune, I could easily access a comprehensive list of all the computers, tablets, and company-owned devices. This streamlined the process of accounting for new devices in our stock, eliminating the need for separate tracking outside of the Intune platform.

    The capabilities of the Intune suite are seamlessly integrated with Microsoft 365 and Microsoft Security. This integration, especially with Microsoft 365, is crucial for us as it enables clear visibility into the association of devices with specific employees. Additionally, it facilitates tracking the usage of applications by different groups. The integration with Azure Active Directory further enhances the importance of the overall integration for our operations.

    What needs improvement?

    It would be beneficial to have a more straightforward understanding of Intune's capabilities, presented in a simplified manner. This way, one wouldn't need to be an Intune specialist or spend hours trying to grasp the intricacies of policies and functionalities. While I've used Intune extensively and have practical experience, I've found that to explore its full potential, significant time is needed for both understanding capabilities and seeking out relevant training. The current understanding of what actions or functionalities are available for configuration is not as clear as it could be. Enhancing the clarity of these policies, whether in terms of functionality or features, would be beneficial for users managing Intune.

    For how long have I used the solution?

    I have been working with it for three years.

    What do I think about the stability of the solution?

    It provides excellent stability. We didn't face any downtime. I would rate it ten out of ten.

    What do I think about the scalability of the solution?

    Scalability has been excellent. We began with a pilot involving just a few devices and swiftly expanded to over two hundred without experiencing any degradation in performance or functionality. I would rate it ten out of ten.

    How are customer service and support?

    In terms of tech support or customer support, our experience has been somewhat mixed. Since we work with partners rather than directly with Microsoft Intune, and these partners are internal and cross-charged within the same company, there have been instances where support was not entirely satisfactory. This could be attributed to a lack of in-depth understanding on their part. However, it's important to note that they are not directly affiliated with Microsoft, and the level of support might vary accordingly.

    How was the initial setup?

    The initial setup was complex.

    What about the implementation team?

    Our setup is hybrid, specifically with Active Directory. The initial configuration necessitated an on-premises presence. However, once the setup is complete, the entire system operates in the cloud, making it predominantly cloud-based after the initial on-premises setup. I was involved in certain aspects of the deployment process. The complexity arose not necessarily from the intricacies of the tasks themselves but from the coordination required. As we lacked global admin privileges, there was a need for extensive collaboration between our team, global admins, and the Intune team at Microsoft.

    In terms of maintenance, once it's up and running, there's not much ongoing effort required. It's essentially a set-and-forget situation. Occasionally, we might need to handle reports and views, especially when there's a new release. In such cases, there might be minor adjustments, like making something visible or invisible, but overall, the maintenance workload is minimal.

    What's my experience with pricing, setup cost, and licensing?

    Regarding the pricing, my experience was with a nonprofit, where we enjoyed a substantial discount. While I can't provide insights from a business perspective, it's worth noting that the pricing may differ significantly, and the discount we received might not be reflective of standard business rates.

    What other advice do I have?

    It's advisable to start with a straightforward approach, avoiding unnecessary complexity initially. However, it's equally important to have a well-thought-out plan for maximizing the platform's capabilities. Assign someone the responsibility of owning and creating a roadmap for ongoing improvements and enhancements. The idea is not just to go live and consider the implementation complete; rather, to plan for continuous refinement and utilization of additional features over time. Overall, I would rate it eight out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.