openskills.info
Microsoft Intune logoCourse Preview

Microsoft Intune

Microsoft Intune is Microsoft's cloud service for managing organization-owned and personal devices, the apps on them, and access to work data. It gives administrators one control plane for enrollment, configuration, compliance, app protection, updates, and remote actions.

itWindows and Microsoft infrastructure

Microsoft Intune

Microsoft Intune is a cloud-based endpoint management service. It manages devices and apps, reports their posture, and supplies signals that Microsoft Entra Conditional Access can use when deciding whether to permit access to organization resources.

Intune organizes endpoint management around three connected subjects: identities, devices, and apps. Microsoft Entra ID supplies identities, groups, authentication, and Conditional Access. Intune enrolls and configures devices, deploys and protects apps, and reports device or app state. Supported management paths cover Windows, macOS, Linux, Android, and Apple mobile platforms, although capabilities differ by platform.

The service is a control plane, not software that replaces the operating system. Administrators declare settings and assignments in the Microsoft Intune admin center or through Microsoft Graph. A supported management channel on each endpoint receives policy and returns status. The endpoint applies the setting through its operating system, an Intune component, or a managed app.

Two management boundaries

Mobile device management, or MDM, manages an enrolled device. Enrollment creates a management relationship and installs an MDM certificate. Intune can then deliver configuration profiles, compliance rules, apps, security policy, updates, and remote actions within the controls that the platform exposes.

Mobile application management, or MAM, protects organization data inside supported apps. Intune app protection policies can require an app PIN, restrict data transfer to personal apps, prevent saving to personal storage, or remove organization data selectively. MAM can work without enrolling the device. This makes it useful for personal-device scenarios where the organization needs control over work data but not the entire endpoint.

MDM and MAM are not competing modes. An organization-owned phone can use MDM for device configuration and MAM for stronger controls around work data. A personal phone can use MAM without MDM. Choose the least intrusive boundary that satisfies the access and data-protection requirement.

The control path

A typical managed-device flow has eight parts:

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources