Microsoft Intune is a great device management tool.
Use Cases and Deployment Scope
We utilized Microsoft Intune to manage our laptops and desktops, as well as our employee's personal devices. For corporate devices we are controlling WIFI access, installing Office, managing secure folder access, tightening security controls, and managing encryption. Personal devices must be enrolled to use company resources such as Teams and email. The devices are checked for security standards and can be remotely wiped in the case of loss or theft.
Pros
- Controlling Windows features and settings.
- It's very easy to implement and manage the certificates for Apple products.
- Robust configuration for managing a large number of devices.
Cons
- Deploying applications to Windows devices.
- Removing a policy from Microsoft Intune does not remove it from the endpoints.
- The update ring feature requires increased licensing.
Return on Investment
- Because the product is included in our MS 365 license, we were able to save $5000 a year by removing our existing MDM system.
- We have better control of Windows settings, such as Wi-Fi, anti-virus, and Office installs. No longer configuring each user manually saves our department hours per deployed PC.
- The use of dynamic groups greatly reduces the administrative overhead per device.
Usability
Alternatives Considered
Sophos Mobile
Other Software Used
Microsoft Defender for Endpoint, Microsoft 365, Windows Server


