Device management in smaller organisations often begins only after a laptop is misplaced in a taxi or a departing employee refuses to return company files stored on their personal phone. Businesses upgrading to Microsoft 365 Business Premium acquire Microsoft Intune Plan 1 as part of their subscription, yet many tenants leave these capabilities entirely unconfigured because the administration portal appears intimidating.
Device management does not require hundreds of complex configuration profiles. A practical Intune deployment focuses on three core outcomes: securing company data on personal mobiles without invading employee privacy, applying consistent configuration to corporate laptops, and satisfying the baseline requirements of Cyber Essentials.
Buying Microsoft 365 Business Premium without configuring Intune leaves your primary security layer dormant. Intune provides the device-level controls that make Conditional Access and Microsoft Defender effective across your entire organisation.
MAM vs MDM: Deciding Your Management Boundary
The most common design mistake made by IT managers is attempting to enrol every personal mobile device into full Mobile Device Management (MDM). Full device enrolment prompts users to install management profiles that grant administrative visibility over the entire device, which inevitably triggers resistance from staff worried about their private photographs, personal messages, and browsing history.
Microsoft Intune provides two distinct management models to solve this dilemma.
| Management Model | Scope of Control | Ideal Device Types | User Privacy Impact | Key Capabilities |
|---|---|---|---|---|
| MAM (App Protection) | Corporate data inside approved applications only | Personal smartphones (iOS & Android), BYOD tablets | High privacy: personal files, photos, and personal apps remain untouched and unmonitored | PIN protection on Outlook/Teams, copy-paste restrictions to personal apps, selective corporate wipe on departure |
| MDM (Device Enrolment) | Entire operating system and hardware configuration | Company-owned Windows laptops, company desktops, corporate mobile handsets | Organisation manages the full operating system and hardware inventory | BitLocker encryption enforcement, Windows update rings, automated application deployment, remote factory reset |
For personally owned mobile phones, App Protection Policies (MAM without enrolment) deliver exactly what the business needs. Corporate emails, Teams chats, and OneDrive documents are encrypted inside protected containers. When an employee leaves the company, an administrator triggers a selective wipe from the Microsoft Intune admin centre. The corporate account and its stored data disappear immediately from the device, while personal photos and WhatsApp messages remain completely intact.
Corporate-owned Windows laptops require the opposite approach. Full MDM enrolment ensures the operating system is patched, storage is encrypted, and endpoint security controls are actively enforced before the machine connects to company resources.
Essential Windows Policies for UK Cyber Essentials
Cyber Essentials requires organisations to prove five foundational technical controls across every device accessing business data: firewalls, secure configuration, user access control, malware protection, and security update management. Intune translates these requirements into automated configuration profiles and compliance checks.
Configuring a compliant Windows baseline requires five distinct policy sets in Intune.
1. BitLocker Silent Disk Encryption
Cyber Essentials mandates disk encryption across all portable devices. Configuring BitLocker through the Endpoint Security blade ensures encryption runs silently during device setup without requiring user interaction.
The policy must enforce 256-bit XTS-AES encryption on the operating system drive, require a Trusted Platform Module (TPM), and automatically back up recovery keys to Microsoft Entra ID. Backing up recovery keys to Entra ID prevents permanent data loss when a motherboard firmware update triggers a BitLocker recovery prompt.
2. Windows Update Rings
Under the Cyber Essentials scheme, all critical and high-risk security updates for operating systems and business applications must be installed within 14 days of release. Unmanaged Windows machines frequently postpone reboots for weeks, creating an immediate compliance failure.
Configure two update rings in Intune to balance stability and prompt patching:
- Pilot Ring (10% of users): Quality update deferral of 2 days, deadline of 5 days, grace period of 2 days. This group includes IT personnel and tech-savvy staff who catch edge-case issues early.
- Production Ring (90% of users): Quality update deferral of 5 days, deadline of 7 days, grace period of 2 days. This ensures every laptop receives and enforces monthly security patches within the required 14-day window.
3. Microsoft Defender for Business Antivirus and Firewall
Microsoft 365 Business Premium includes Microsoft Defender for Business. Configure an Endpoint Security Antivirus policy to enforce real-time cloud protection, daily signature definitions, and behavioural monitoring. Pair this with an Endpoint Security Firewall policy that enables the domain, private, and public firewall profiles, blocking all unsolicited inbound connections by default.
4. Device Restrictions and Secure Configuration
Use the Settings Catalogue or Device Restrictions template to enforce baseline operating system hardening:
- Maximum inactivity screen lock timeout set to 15 minutes or less.
- Alphanumeric password or Windows Hello for Business PIN required upon waking.
- Removal of standard user local administrator privileges to prevent unapproved software installations.
- Disabling of legacy insecure protocols such as SMBv1.
5. Device Compliance Policies and Conditional Access
A configuration policy pushes settings to a computer, but a compliance policy verifies that those settings remain active. If a user disables their firewall or fails to apply an update, Intune flags the device as non-compliant.
Connecting this compliance state to Microsoft Entra Conditional Access creates an effective security perimeter. If a machine falls out of compliance, Conditional Access blocks access to SharePoint, Exchange, and Teams until the issue is resolved. Review our guide on Microsoft 365 consultancy for assistance aligning identity controls with endpoint protection.
Comparison: Intune Capabilities Across Microsoft 365 Licences
Licensing determines which device management features are available in your tenant. Many UK businesses pay for third-party mobile device management tools because they are unaware of what their current Microsoft subscriptions provide.
| Feature / Capability | Microsoft 365 Business Standard | Microsoft 365 Business Premium | Intune Suite Add-On |
|---|---|---|---|
| Approximate Cost (ex VAT) | £10.30 per user / month | £19.70 per user / month | Additional £8.20 per user / month |
| Mobile Application Management (MAM) | No | Yes (Intune Plan 1) | Yes (Intune Plan 1) |
| Windows MDM & Settings Catalogue | Basic MDM only | Full Intune Plan 1 | Full Intune Plan 1 |
| Windows Autopilot Provisioning | No | Yes | Yes |
| Endpoint Privilege Management | No | No | Yes (Advanced add-on) |
| Remote Help Screen Sharing | No | No | Yes (Advanced add-on) |
For the vast majority of UK SMEs with fewer than 300 users, Microsoft 365 Business Premium provides all the endpoint management tools required. The additional Intune Suite add-on is rarely justified for smaller businesses unless specific requirements exist for automated privilege elevation or specialised cloud certificate management.
Four Common Intune Deployment Pitfalls
Deploying Intune without proper planning leads to frustrated users, locked devices, and broken workflows. In our consultancy work across UK businesses, four specific errors occur repeatedly during rollouts.
1. Missing MDM User Scope Configuration
An administrator assigns Business Premium licences to staff, instructs them to sign into Windows with their Microsoft 365 credentials, and discovers the computers appear in Microsoft Entra ID as registered devices rather than Intune-managed endpoints.
This failure happens when the MDM User Scope in the Entra admin centre remains set to "None". Before enrolling any Windows machine, open Identity > Mobility (MDM and WIP) > Microsoft Intune and ensure the MDM user scope is configured for "All" users or scoped specifically to your pilot group.
2. Policy Conflicts Between Group Policy and Intune CSPs
Organisations migrating from on-premises Active Directory to cloud-native management often join machines to Intune while legacy Group Policy Objects (GPOs) remain active on the local network. When an on-premises GPO and an Intune Configuration Service Provider (CSP) target the same registry key with differing values, Windows attempts to apply both, resulting in erratic configuration flips and persistent policy error codes.
Audit and decommission overlapping GPO settings prior to targeting devices with Intune profiles. Moving to cloud-native Entra ID join rather than Hybrid join eliminates this complexity for modern laptop deployments.
3. Mistaking Check-In Latency for Policy Failure
Administrators accustomed to on-premises management expect policies to apply instantaneously. Microsoft Intune relies on a cloud check-in schedule. Newly enrolled Windows devices sync approximately every 3 minutes for the first 15 minutes, every 15 minutes for the next two hours, and then settle into an 8-hour background cycle.
Applying a new configuration profile and immediately checking the device produces false reports of failure. Forcing a manual sync via Settings > Accounts > Access work or school > Info > Sync accelerates testing during deployment phases.
4. Enforcing MFA on Windows Autopilot Without Named Locations
Windows Autopilot allows a company to ship a shrink-wrapped laptop directly from the hardware distributor to a remote employee. The worker unboxes the machine, enters their company email and password, and Intune automatically installs applications and configures security settings.
If your Conditional Access policies enforce strict device-compliance or complex multi-factor authentication rules during initial device registration without excluding the Intune Enrolment cloud app, the Autopilot Out-of-Box Experience (OOBE) fails before the user can complete setup. Proper configuration requires carefully structured Conditional Access policies that allow enrolment while securing routine operational access.
Step-by-Step Intune Rollout Plan for UK Businesses
A structured Intune implementation minimises disruption and ensures technical controls are verified before production rollout. Follow this four-stage sequence:
- Phase 1: Foundation and Identity. Verify Business Premium licensing, configure the MDM User Scope, and build dynamic Microsoft Entra security groups for corporate devices and mobile users.
- Phase 2: Mobile MAM Deployment. Build App Protection Policies for iOS and Android. Restrict corporate data sharing to managed applications and verify selective wipe capabilities on a test handset.
- Phase 3: Windows Endpoint Hardening. Create BitLocker, Defender Antivirus, Firewall, and Update Ring profiles. Deploy these to a dedicated pilot group of test laptops and verify policy application in the Intune reports.
- Phase 4: Compliance and Conditional Access. Create device compliance rules and link them to Conditional Access policies. Once verified on pilot hardware, expand enrolment across the entire organisation.
Organisations planning wider tenant governance, data classification, or migration to modern cloud infrastructure can learn more about our SharePoint migration and architecture services.
Is Your Microsoft 365 Tenant Properly Secured?
EJK Consultancy helps UK businesses configure Microsoft Intune, deploy effective security baselines, and achieve Cyber Essentials compliance without disrupting staff productivity.
Book a Microsoft 365 Assessment
Written by Dan Kennedy
Managing Consultant at EJK Consultancy
Dan is a Microsoft Certified consultant with over 25 years of hands-on IT experience, specialising in Microsoft 365 migrations, SharePoint architecture, Power Automate automation and Microsoft Copilot readiness. He works directly with UK businesses to solve real workplace technology problems.
