Microsoft Intune

Microsoft Intune

Microsoft Intune is an online service that lets companies and schools centrally manage the laptops, phones, and tablets of their employees or students. Over the internet, it can be used to install programs, enforce security rules, and remotely lock or wipe lost devices.

In a large company, thousands of people often work with laptops and phones. Someone has to make sure that the right programs run on all these devices and that the data is protected. A single technician cannot possibly handle thousands of devices one by one. Microsoft Intune solves this problem over the internet: the IT department sets rules at a central location, and all enrolled devices follow them automatically. The service belongs to Microsoft and is paid for as a subscription, similar to a streaming service. Experts also call such tools device management, or use the English abbreviation MDM for Mobile Device Management.

What companies get out of it

The main reason is security. A company laptop holds customer data, contracts, and internal documents. If the device is lost on a train, the IT department can lock it remotely and wipe the data with just a few clicks. Without such a system, all that would be left is hoping the finder is honest.

Then there’s the time saved. A new employee today often has their laptop shipped directly from the manufacturer to their home. They log in with their company account, and the device sets itself up accordingly: software, printers, Wi-Fi access, security settings. In the past, a technician would have had to set up each device individually.

Laws also play a role. The General Data Protection Regulation requires companies to adequately protect personal data. Anyone who can prove that all devices are encrypted and security updates are enforced is in a much better position during an audit.

The path from the rulebook to the phone

First, a device is registered with Intune. For company phones, this usually happens at the time of purchase; for private devices, the user installs an app and logs in. From that moment on, the service knows the device and can communicate with it.

The IT department then defines what are called policies. These are simply lists of requirements: a passcode of at least six digits, an encrypted hard drive, screen lock after five minutes. These requirements are assigned to user groups, for example everyone in accounting. The device regularly checks with the server to see if there are new instructions, and then implements them itself.

An important point is the separation of personal and professional use. On a private phone, Intune usually only manages a shielded area containing the company apps. IT can delete this area but cannot see private photos and messages. A common misconception is that the company can read everything through Intune. Technically more would be possible, but in Germany it is usually neither common practice nor legally permitted.

From the school iPad to the cloud invoice

When all iPads at a school have the same apps and the App Store is locked down, such a management system is often behind it. Sometimes it’s Intune, sometimes a competing product like Jamf or VMware Workspace ONE. The company phone used during an internship, on which certain settings can’t be changed, is usually also following such a policy.

In business news, Intune mainly appears as part of Microsoft 365. It is included in the more expensive business subscriptions and thus contributes to the cloud revenues that Microsoft reports every quarter. The device management market is considered lucrative because companies rarely switch systems once they’ve been introduced.

Intune is increasingly being mentioned in connection with AI as well. Microsoft is building in assistants that flag suspicious devices or suggest security settings. But the core remains mundane: it’s about managing many devices uniformly and without manual effort.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.