Microsoft Intune
Microsoft Intune is Microsoft's cloud service for managing organization-owned and personal devices, the apps on them, and access to work data. It gives administrators one control plane for enrollment, configuration, compliance, app protection, updates, and remote actions.
itWindows and Microsoft infrastructure | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Microsoft Intune
Somewhere out there is a laptop, a phone, and possibly a kiosk bolted to a wall in a lobby, and somebody in IT needs to know what's installed on it, whether it's encrypted, and whether it deserves access to anything that matters. Microsoft Intune is Microsoft's answer to that problem: a cloud service that manages devices and apps, then reports back on what it found.
It doesn't replace the operating system, and it isn't software that lives permanently on the device either. Before services like this existed, IT staff relied on machines sitting on a wired office network, physically reachable by whoever held the keys, or walked room to room with a USB stick. Intune's job is to reach devices that are neither of those, wherever they are, from a web console.
Three ideas carry the rest of it. Everything is organized around identities, devices, and apps: identity decides who a policy targets, the device is usually where policy lands, and an app can sometimes be protected on its own, independent of the device underneath it.
Second, there are two different ways to manage something. MDM takes responsibility for a whole enrolled device: settings, security, updates, the works.
MAM manages only the organization's data inside a handful of apps, leaving the rest of a personal phone alone. Whichever one is loudest in a given deployment says a lot about whether the organization owns the hardware or just needs one inbox kept honest.
Third, and this is the one that trips people up: the console tells you what it decided, not what happened. Assigning a policy is a click. Getting a laptop to notice, download, and apply that policy is a conversation the laptop has on its own schedule, and the two are easy to mistake for each other.
That third point is the genuine surprise. A policy marked "assigned" hasn't necessarily reached anyone. A laptop closed in an airport lounge isn't broken, it just hasn't had the conversation yet. And "compliant" is a snapshot from the last successful check-in, not a live guarantee, which is exactly why Conditional Access — a separate Entra service, not Intune itself — is the thing that actually stops a risky sign-in, not the compliance flag sitting quietly on its own.
Where to go next depends on what you need explained. The Course tab builds the full architecture: enrollment, assignment, compliance, and how Conditional Access consumes it. The Cheatsheet is the fast lookup once that shape is already in your head. If Intune sits next to tools you're actively comparing it against, the Landscape tab has the field. And if a decade of version history sounds more useful than intimidating, the Timeline is there too.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://learn.microsoft.com/en-us/intune/fundamentals/what-is-intune
Supports
- Intune definition, cloud service model, supported platforms, admin center, and Microsoft Graph
- Device lifecycle, MDM and MAM modes, Entra identity dependency, groups, and Conditional Access integration
- Advanced capability and licensing boundaries
- https://learn.microsoft.com/en-us/intune/fundamentals/core-concepts
Supports
- Identity, device, and app pillars
- User affinity, userless devices, group targeting, RBAC, scope tags, and assignment choices
- App deployment, configuration, protection, updates, MAM without enrollment, and access-decision flow
- https://learn.microsoft.com/en-us/intune/fundamentals/endpoint-management
Supports
- Cloud control plane, managed endpoints, endpoint-family services, connectors, peer integrations, partners, and on-premises components
- https://learn.microsoft.com/en-us/intune/device-enrollment/guide
Supports
- Enrollment relationship, MDM certificate, enrollment restrictions, configuration and compliance delivery
- Personal and corporate ownership scenarios, platform requirements, pilot groups, and stale enrollment behavior
- https://learn.microsoft.com/en-us/intune/device-enrollment/windows/guide
Supports
- Windows automatic enrollment, Windows Autopilot, user enrollment, and co-management paths
- https://learn.microsoft.com/en-us/intune/app-management/protection/overview
Supports
- App protection on enrolled and unenrolled devices
- PIN, data-transfer, personal-storage, managed-app, and selective-wipe behavior
- MDM, MAM, full wipe, and selective-wipe distinctions
- https://learn.microsoft.com/en-us/intune/device-security/compliance/overview
Supports
- Tenant compliance settings, platform policies, rule evaluation, actions for noncompliance, and check-in timing
- Conditional Access consumption of compliance state and platform-specific capability differences
- https://learn.microsoft.com/en-us/intune/device-security/conditional-access-integration/overview
Supports
- Microsoft Entra ownership of Conditional Access
- Use of Intune device compliance and app management data as access signals
- https://learn.microsoft.com/en-us/intune/fundamentals/filters/troubleshoot
Supports
- Include and exclude filter evaluation and reporting for app and policy assignments
- https://learn.microsoft.com/en-us/intune/device-management/reports/overview
Supports
- Operational, organizational, and historical reporting for device health, compliance, activity, and trends
- https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security
Supports
- Endpoint security, policy overlap, compliance, Conditional Access, and advanced capability boundaries
- https://learn.microsoft.com/en-us/intune/fundamentals/licensing
Supports
- Intune Plan 1, additive plans, Suite packaging, license requirements, and co-management licensing context
- https://learn.microsoft.com/en-us/intune/configmgr/comanage/overview
Supports
- Concurrent management of Windows devices by Configuration Manager and Intune
- https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-identity-device-access-policies-common
Supports
- Pilot testing, Conditional Access, app protection, and compliance policy layering
- https://learn.microsoft.com/en-us/training/paths/endpoint-manager-fundamentals/
Supports
- Structured foundation-to-administration study path for Intune
- https://github.com/sindresorhus/awesome
Supports
- Starting point for awesome-list discovery
- https://github.com/awesome-foss/awesome-sysadmin
Supports
- Discovery of Chocolatey, Munki, and Snipe-IT in sysadmin software categories
- https://docs.chocolatey.org/en-us/getting-started/
Supports
- Windows packages, PowerShell automation, dependency handling, internal sources, and software deployment use
- https://github.com/munki/munki/wiki
Supports
- macOS repository, client, catalogs, manifests, required installs, removals, and Managed Software Center
- https://snipe-it.readme.io/docs/introduction
Supports
- IT asset assignment, custody, licenses, accessories, and distinction from endpoint configuration
- https://news.microsoft.com/2011/03/23/windows-intune-available-to-businesses-of-all-sizes/
Supports
- March 23 2011 general availability, cloud PC management, web console, and initial country coverage
- https://news.microsoft.com/recent-news/page/1587/
Supports
- October 2014 announcement that Windows Intune would become Microsoft Intune
- https://www.microsoft.com/en-us/microsoft-365/blog/2017/06/08/the-new-intune-and-conditional-access-admin-consoles-are-ga/
Supports
- June 8 2017 general availability of Intune and Conditional Access administration in the Azure portal
- Integrated MDM, MAM, Azure Active Directory, and Conditional Access experience
- https://www.microsoft.com/en-us/security/blog/2018/06/18/new-fasttrack-benefit-deployment-support-for-co-management-on-windows-10-devices/
Supports
- June 2018 FastTrack deployment support and simultaneous Configuration Manager and Intune management
- https://www.microsoft.com/en-us/microsoft-365/blog/2019/11/04/use-the-power-of-cloud-intelligence-to-simplify-and-accelerate-it-and-the-move-to-a-modern-workplace/
Supports
- November 4 2019 Microsoft Endpoint Manager announcement and convergence of Intune and Configuration Manager
- https://techcommunity.microsoft.com/blog/microsoftintuneblog/use-microsoft-endpoint-manager-filters-to-target-apps-and-policies-to-specific-d/2333342
Supports
- May 2021 public preview of filters for device-property refinement of assignments
- https://techcommunity.microsoft.com/blog/microsoftintuneblog/remote-help-enterprise-grade-assistance-tool-now-available/3275792
Supports
- April 5 2022 general availability of Remote Help for Windows
- https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/introducing-the-microsoft-intune-product-family/ba-p/3650769
Supports
- October 2022 announcement of Microsoft Intune as the endpoint product-family name
- https://www.microsoft.com/en-us/security/blog/2023/03/01/the-microsoft-intune-suite-fuels-cyber-safety-and-it-efficiency/
Supports
- March 1 2023 launch of the Microsoft Intune Suite
- https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-cloud-pki-launches-as-a-new-addition-to-the-microsoft-intune-suite/3982830
Supports
- February 2024 Cloud PKI availability and certificate lifecycle for Intune-managed devices
- https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune
Supports
- Proprietary paid Intune product and its endpoint-management role
- https://www.omnissa.com/products/workspace-one-unified-endpoint-management/
Supports
- Cross-platform enrollment, configuration, security, updates, compliance, access, telemetry, and paid subscription packaging
- https://www.ibm.com/products/maas360
Supports
- Proprietary paid multi-operating-system unified endpoint management and compliance
- https://www.hexnode.com/uem/
Supports
- Proprietary paid cross-platform enrollment, configuration, application, security, and remote endpoint management
- https://www.ivanti.com/products/ivanti-neurons-for-unified-endpoint-management
Supports
- Proprietary paid discovery, endpoint visibility, mobile, desktop, IoT, security, and remediation functions
- https://www.manageengine.com/products/desktop-central/features.html
Supports
- UEM, patching, application distribution, configuration, inventory, remote support, and free edition packaging
- https://www.jamf.com/products/jamf-pro/
Supports
- Proprietary paid Apple enrollment, configuration, applications, updates, restrictions, and remote commands
- https://soti.net/products/soti-mobicontrol/
Supports
- Proprietary paid mobile and specialized-device management, apps, content, status, and remote support
- https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq
Supports
- Microsoft 365 E5 developer subscription licensing, including Intune inclusion, sandbox provisioning, and development-only usage terms
- https://call4cloud.nl/mdm-vs-mam-personal-vs-corporate/
Supports
- MDM and MAM user scope overlap behavior: a user in both scopes is routed to MAM only and the device is never MDM-enrolled or evaluated for compliance
- https://call4cloud.nl/autopilot-dynamic-group-membership-updating/
Supports
- Dynamic group membership evaluation delay for Windows Autopilot profile assignment, and static or enrollment-time groups as the practitioner workaround
- https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/scope-tags
Supports
- Scope tags limit which Intune objects a scoped role can see, but Global Administrator and Intune Administrator roles bypass scope-tag restrictions
- https://learn.microsoft.com/en-us/windows/client-management/config-lock
Supports
- Configuration drift after a successful policy sync, and why most managed settings do not self-heal without Secured-core configuration lock
- https://patchmypc.com/blog/intune-policy-delivery-debugging-the-8-hour-sync-myth/
Supports
- Windows policy delivery mechanism: WNS push notification as the primary path within minutes, with the 8-hour cycle as fallback only
