Microsoft Intune: 7 Critical Answers Before You Buy Add-Ons
A business on Microsoft 365 Business Premium or E3 already pays for Microsoft Intune, whether or not anyone has ever opened it. It arrives inside the bundle rather than as a deliberate purchase, and it sits in the tenant doing nothing at all until somebody enrols a device. Then, on 1 July 2026, Microsoft changed what each plan contains — and the change was not the one most people assume it was.
This is the explainer we would give someone who asked, answering the seven questions people actually ask about Microsoft Intune: what it is, whether it is an MDM, where it came from, what you already own, what changed this year, what the add-ons cost, and what it does not do. Every figure and date below was read on Microsoft’s own pages on 18 September 2026, and each one is linked.
Prices here are Microsoft’s published United States list prices, in dollars, per user per month on annual billing, read on 18 September 2026. What you pay through a partner, in another currency, or on an agreement that has not yet renewed will differ. We are not going to publish a rand figure, because it depends entirely on your agreement and quoting one would be marketing rather than information.
What Microsoft Intune actually is, and whether it is an MDM
Microsoft’s own definition is short: “a cloud-based endpoint management service that secures and manages your organization’s devices and apps”. Supported platforms are Android, iOS/iPadOS, Linux, macOS, tvOS, visionOS and Windows, and the service “runs entirely in the cloud, with no on-premises infrastructure required”.
So yes, Microsoft Intune is an MDM. But that answer is only half of it, and the missing half is the one that matters for a small business.
Microsoft documents two management modes. Under mobile device management, devices are enrolled and “Intune then manages the whole device, including settings, security, and apps”. Under mobile application management, “Intune manages only the work apps and the data inside them, not the rest of the device” — which is how you protect company mail on a phone you do not own and cannot wipe.
The two run together. An enrolled company laptop can carry device policy and app policy at once; a personal phone can carry app policy alone. If somebody tells you Intune means taking control of staff phones, they have described one of the two modes and left out the one most small businesses should start with.
The third piece is identity. Microsoft Intune does not authenticate anyone: it “relies on Microsoft Entra ID” for sign-in, for the groups you target policy at, and for Conditional Access, to which it sends device compliance state. That last link is the whole point of the product, and we come back to it below.
Where it came from, and why that still shows
It is older than most people think. Microsoft’s own transcript of Brad Anderson’s Microsoft Management Summit keynote, published on 24 March 2011, contains the line “today we’re announcing the general availability, day one, of Windows Intune”. That was a PC patching and anti-malware service with a web console, fifteen years ago.
We are deliberately not reciting the full chain of renames after that, because we could not source each step to a Microsoft page we could open today, and a rename history assembled from third-party blogs is exactly the sort of thing that ends up wrong. What matters is the shape: a Windows PC service that grew mobile management, then app management, then an advanced tier sold separately.
That history is why Microsoft Intune feels like several products rather than one. It is.
You already own Plan 1, and you are probably not using it
Microsoft Intune is sold in three plans. Microsoft Intune Plan 1 is “the base service. Cloud-based unified endpoint management for devices and apps.” Plan 2 is “additive to Plan 1”. The Microsoft Intune Suite is also additive to Plan 1 and “Includes Plan 2”.
Few buy these directly. Microsoft’s own licensing page says most organizations “get Intune as part of a Microsoft 365 bundle” rather than buying the plans on their own. It also states plainly that Business Premium “includes Microsoft Intune Plan 1, a comprehensive device management solution that allows you to enroll, monitor, and manage devices”, in its own Business Premium device management guidance. Microsoft Intune Plan 1 is also in Microsoft 365 E3 and E5 and in Enterprise Mobility + Security E3 and E5.
Two licensing details cost people money, and neither is obvious.
The licence follows benefit, not installation. Microsoft’s rule is that a licence “is required for any user or device that benefits directly or indirectly from the Microsoft Intune service, including access through a Microsoft API”. Indirectly is doing a lot of work in that sentence.
Device-only licences are not a cheap substitute for user licences. There is a device-only subscription for kiosks and shared hardware, and Microsoft lists what it cannot do: “Intune app protection policies”, “Conditional Access”, and user-based features such as mail and calendar. If Conditional Access is the reason you are doing this — and it should be — a device-only licence does not get you there.
One genuine saving is worth knowing. Administrators do not need a licence to sign in and manage the service; unlicensed admin access is on by default for tenants created after July 2021, and can be switched on manually for older ones.
What changed on 1 July 2026, and what did not
Microsoft published a pricing and packaging update that moved several Intune Suite capabilities into the enterprise suites. The page is specific about the timetable: new capabilities began rolling out in June 2026, customers get “a 30‑day notice in Message Center”, and rollout “will be complete by August 1, 2026”.
Microsoft 365 E3 gained three Microsoft Intune capabilities: Remote Help, Advanced Analytics and Intune Plan 2. Microsoft 365 E5 gained all of those plus Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise Application Management. Enterprise Mobility + Security E3 gained the same three as E3. Microsoft’s Intune blog post of 1 July 2026 says the same thing in prose.
Now the part the coverage skipped. Business Premium received no Microsoft Intune capability at all. Its entry on that table reads “+50GB email, Copilot Chat enhancements, Copilot Chat Analytics”, and nothing else. If you run a small business on Business Premium and read a headline saying the Intune Suite is now included, it is not included for you.
The prices moved in the same update, effective 1 July 2026. Microsoft 365 E3 went from $36.00 to $39.00 and E5 from $57.00 to $60.00. Enterprise Mobility + Security E3 went from $10.60 to $12.00. Business Premium did not move at all and is still $22.00. Microsoft also states that “existing customers remain on current pricing until renewal”, so if your term runs into next year you have not seen any of this yet.
Read together, that is a coherent trade: E3 costs three dollars more and carries roughly ten dollars of former add-ons. It is a good deal for anyone already on E3, and an argument for E3 that did not exist in June. Whether it beats Business Premium on security overall is a separate question, and we work through it in our comparison of Business Premium and E3, where the endpoint answer is less flattering to E3 than you would expect.
What the add-ons cost if you are not on E3
Microsoft’s Intune pricing page lists each advanced capability separately, per user per month on annual billing. Remote Help is $3.50. Advanced Analytics is $5.00. Endpoint Privilege Management is $3.00. Enterprise Application Management is $2.00. Microsoft Cloud PKI is $2.00. Intune Plan 2 is $4.00.
The same page’s FAQ prices the whole Microsoft Intune Suite at $10.00 per user per month and says it “is the better value when deploying two or more modules at scale”. It also notes that Tunnel for mobile application management, firmware-over-the-air updates and specialised device management “are only available through Intune Plan 2 or the full Suite and not as standalone purchases”. Standalone Plan 1, for anyone with no Microsoft 365 subscription at all, is listed at $8.00.
Every one of those add-ons requires Microsoft Intune Plan 1 underneath it. None of them is a starting point.
The honest reading of that price list, for a business of this size: the two capabilities people actually want are Remote Help and Endpoint Privilege Management, at $6.50 a seat together. Before spending it, check whether the thing you want is already sitting unconfigured in Plan 1. It very often is.
Four things Microsoft Intune is not
This is the section a reseller has no reason to write, so here it is.
It is not an EDR. Intune configures endpoints and reports on them; detection and response is Microsoft Defender’s job, and which Defender you get depends entirely on your plan rather than on Intune. Answering an insurer’s endpoint-detection question with “we have Intune” is not an answer — a point we make at greater length about the controls underwriters check.
It is not a patching guarantee. Windows update rings, in Microsoft’s own description, “control client‑side update behavior such as deferral periods, restart settings, deadlines, active hours, and user notifications”. They shape what Windows Update does. They are not a patch engine, they say nothing about third-party software, and they can sit paused for 35 days without anyone noticing.
It does not patch your third-party applications in the base plan. Deploying and updating non-Microsoft applications from a hosted catalogue is Enterprise Application Management — the $2.00 add-on, now included in E5 and not in E3 or Business Premium. Plan 1 will install an application for you. It will not keep it current.
It is not an RMM, and it is not a helpdesk. There is no ticket queue here. Even screen sharing with a user is Remote Help, a separately licensed capability. Microsoft Intune replaces the configuration half of a traditional management stack; the human and process half is still yours to run or to buy.
And one thing it is not that catches careful people: it is not self-applying. A device can be enrolled, compliant against an empty policy set, and reported as perfectly healthy. Our note on remote systems hardening puts it bluntly — having Intune is not having a baseline.
The remediation scripts answer nobody gives you
“Best Intune remediation scripts” is one of the most-asked questions about this product, and almost every answer is a list of PowerShell. Here is the useful answer instead, and it is a licensing one.
Remediations — renamed from Proactive Remediations — are “script packages that can detect and fix common support issues on a user’s device before they even realize there’s a problem”. A detection script, a remediation script, a schedule, and a report.
Then read the licensing section of Microsoft’s own page. Remediations “require users of the devices to have one of the following licenses”: Windows Enterprise E3 or E5, which Microsoft notes is included in Microsoft 365 F3, E3 or E5; Windows Education A3 or A5; or Windows Virtual Desktop Access per user.
Microsoft 365 Business Premium is not on that list. Neither is Microsoft Intune Plan 1 on its own. Microsoft even requires an Intune Service Administrator “to confirm licensing requirements before using Remediations for the first time”, which is a consent click rather than an enforcement gate — the feature will run for you whether or not the entitlement exists.
So the honest answer to the scripts question, for a great many of the people asking it, is that the feature is not yours to use. That is worth knowing before you build a library on it.
A sane first ninety days
If the Microsoft Intune licence is already paid for, this is the sequence we would follow. The order is not arbitrary: reverse any two of these and you will lock someone out of their mail.
Enrol something small first. Windows automatic enrolment, an Apple MDM push certificate, a managed Google Play connection — whichever platforms you actually have. Start with IT’s own devices.
Write one compliance policy per platform. Microsoft’s compliance documentation describes these as “sets of rules and conditions that you use to evaluate the configuration of your managed devices”. For Windows, Microsoft’s own small-business recommendation is to require BitLocker, Secure Boot, code integrity, firewall, TPM, antivirus and real-time protection.
Check the tenant-wide setting almost everyone misses. “Mark devices with no compliance policy assigned as” defaults to Compliant, which Microsoft describes as “This security feature is off”. Leave it there and an unmanaged device passes your compliance gate by never being measured. Microsoft is explicit: if you use Conditional Access with compliance policies, change it to Not compliant.
Then require a compliant device in Conditional Access. Until a Conditional Access policy has its access control set to “Require device to be marked as compliant”, the compliance policy is a report and nothing more. This is the step that converts Microsoft Intune from an inventory into a control, and it is the one most half-finished deployments stop just short of. Roll it out to one pilot group with a break-glass exclusion before you touch everyone.
Apply a security baseline and a set of update rings. Baselines are preconfigured groups of Windows settings, and Microsoft warns that in almost all scenarios their defaults are the most restrictive available. Pilot ring first, always.
Last, app protection for personal devices. App protection policies work “independent of any mobile-device management (MDM) solution” and protect company data “without requiring device enrollment”. This is the cheapest genuine win in the product: a PIN on Outlook, no saving company files to personal storage, and a selective wipe that removes company data without touching anyone’s photographs.
Ninety days is generous for that list in a business of this size. It is not generous if you also have to decide what your policies should say, which is the part that actually takes the time.
Three dated changes worth diarising
Three things on Microsoft’s in-development page, updated 8 September 2026, will reach an ordinary small business within the next year.
31 October 2026 — Android integrity. Google has tightened its definition of “Strong Integrity” for Android 13 and above, and “Microsoft Intune will enforce this change by October 31, 2026”. Devices on Android 13 or later “without a security update in the past 12 months” stop meeting that standard, which can mean a conditional launch block or a non-compliant device losing access. Old personal Android handsets are the exposure here.
Later in 2026 — Apple minimum versions. After Apple ships iOS and iPadOS 27, Microsoft Intune moves its minimum to iOS/iPadOS 18. After macOS 27, the minimum becomes macOS 15. Already-enrolled Macs on older versions stay enrolled; new ones “are unable to enroll”.
Already past — Windows 10. Microsoft’s supported platforms page lists Windows 10 as an allowed rather than supported version: devices “can still enroll in Intune and use eligible features, but functionality won’t be guaranteed and can vary”. A green console does not mean a supported fleet. Our piece on Windows 10 Extended Security Updates covers what that costs and the six ways off it.
When the answer is no
Three situations where we would tell you not to start.
When identity is not fixed first. Microsoft Intune sends compliance state to Conditional Access, and Conditional Access is a Microsoft Entra feature. If MFA is not universal, if leavers keep their accounts, if half your admins are permanently excluded from policy, then device management is the wrong project this quarter. The gaps MFA does not close are a better place to spend the same fortnight.
When nobody will own it after go-live. This is not a product you configure once. Baseline versions freeze, update rings expire out of a pause, minimum OS versions move, and none of that announces itself. A deployment with no named owner reverts to an expensive inventory inside a year.
When the estate is ten laptops that never leave one building and never will. Cloud endpoint management earns its keep across distance, staff turnover and personal devices. If you have none of those, be honest about it and spend the effort on backup and on your identity configuration instead.
What to do this week
Open the Microsoft 365 admin centre and check which plan your users actually hold. Then open the Intune admin centre and look at three numbers: how many devices are enrolled, how many compliance policies exist, and whether any Conditional Access policy requires a compliant device. A small first number and a zero for the third is the common pattern, and it means the licence is doing nothing for you yet.
If you are on E3 or E5, check your Message Center for the packaging notice and find out what landed in your tenant during July. Microsoft Intune capabilities you are now entitled to do not switch themselves on.
If you are on Business Premium, take the July announcement off your list entirely. Nothing changed for you, and the work in front of you is the unglamorous configuration that was always available.
None of this requires a consultant. If you would rather it were somebody’s standing responsibility than another item on yours, that is what our systems hardening and automation work is for — and if you want a second opinion on a licensing mix before a renewal, say so. We do not resell Microsoft licences, so we have no interest in which of these you end up buying.