Getting Started with Microsoft Intune

Simplify device management and enhance security in your Azure AD environment.

Microsoft Intune is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM). It helps organizations manage the devices and apps that employees use to access company data. This guide will walk you through the initial steps to get you up and running with Intune.

What is Microsoft Intune?

Intune is part of Microsoft's Enterprise Mobility + Security (EMS) suite. It allows you to:

Prerequisites

Before you begin, ensure you have:

Step 1: Accessing the Intune Portal

You can access the Microsoft Intune portal directly through your web browser.

https://intune.microsoft.com/

Log in using your Azure AD administrator credentials.

Step 2: Initial Configuration and Enrollment Setup

a) Setting the MDM Authority

The first time you access Intune, you'll be prompted to set the MDM authority. This is crucial as it determines which service will manage your mobile devices. For most organizations, this should be set to Microsoft Intune.

Important: Once set, the MDM authority cannot be changed. Ensure you select the correct option.

b) Configuring Device Enrollment

To manage devices, they need to be enrolled. Intune supports various enrollment methods depending on the device type and operating system.

Navigate to Devices > Enroll devices to explore the specific enrollment options and instructions for each platform.

Step 3: Creating Device Compliance Policies

Compliance policies define the rules that a device must follow to be considered compliant with your organization's standards. This is a fundamental aspect of securing your data.

To create a compliance policy:

  1. Go to Devices > Compliance policies.
  2. Click Create policy.
  3. Select the Platform (e.g., Android, iOS/iPadOS, Windows 10 and later).
  4. Define the settings for your policy, such as password requirements, encryption, and minimum OS version.
  5. Assign the policy to user groups.

Devices that do not meet these policies can be blocked from accessing corporate resources.

Step 4: Configuring Device Configuration Profiles

Configuration profiles are used to deploy settings and features to your managed devices. This can include Wi-Fi profiles, VPN settings, email profiles, security settings, and more.

To create a configuration profile:

  1. Go to Devices > Configuration profiles.
  2. Click Create profile.
  3. Select the Platform and Profile type (e.g., Settings catalog, Templates).
  4. Configure the desired settings.
  5. Assign the profile to user or device groups.

Step 5: Deploying Applications

Intune allows you to deploy applications to your managed devices. You can deploy required apps or make apps available for users to install from the Company Portal app.

To add an app:

  1. Go to Apps > All apps.
  2. Click Add.
  3. Select the App type (e.g., Microsoft Store app, Managed Google Play app, iOS/iPadOS app, Win32 app).
  4. Configure the app information and assignment.

Next Steps and Best Practices

This guide covers the foundational steps. As you become more familiar with Intune, consider exploring:

Tip: Start with a pilot group of users and devices before rolling out Intune to your entire organization. This allows you to refine policies and identify any potential issues.
Author Avatar

Azure AD Team

Published: October 26, 2023