MOBILITY

Endpoint and device management with Microsoft Intune

Laptops your team takes home. Phones with company email. Personal devices accessing SharePoint. Without a real MDM strategy, every one of those is a possible breach surface. We deploy Microsoft Intune so the right device with the right person at the right compliance level is the only way in. Below: why device management became a security control, how zero-touch deployment works, what compliance policies actually enforce, how BYOD is handled without touching personal data, and what happens when a laptop goes missing.

What we deliver

Autopilot zero-touch deployment

New laptops ship to your team's home or hotel and configure themselves on first sign-in. No more "drop by the office to set it up first."

Compliance & configuration profiles

BitLocker required, screen lock enforced, OS up to date — non-compliant devices blocked from M365 via Conditional Access.

App protection & deployment

Office apps, Adobe, line-of-business installers — pushed to enrolled devices, updated centrally, removed when the device is wiped.

BitLocker key escrow

Encryption keys auto-stored in the Microsoft Entra. Lost laptop? Recovered. Recovered laptop? Wiped from your dashboard.

BYOD with app protection

Personal phones can have work email without enrolling the whole device. Container the apps, not the user's personal data.

Why device management became a security control

When your data lives in Microsoft 365, the office network stops being the boundary of the business. The new boundary is the combination of an identity and a device — who is signing in, and on what. An unmanaged laptop with a weak password and no disk encryption, sitting in a café with a cached copy of your SharePoint, is outside every control you have built, unless the device itself is managed.

Microsoft Intune is how that management happens without the old baggage of imaging servers and domain joins. Devices enrol over the internet, policies follow the device wherever it is, and compliance is evaluated continuously rather than checked whenever the machine next visits the office. For a distributed or hybrid workforce, it is the difference between managing a fleet and hoping about one.

The pieces below — enrolment, compliance, app deployment, encryption escrow, BYOD containment — are one system, and the connective tissue is Conditional Access: the device's compliance state becomes a condition of reaching company data at all.

Autopilot: new laptops without the IT pit stop

The traditional new-starter routine — laptop shipped to the office, imaged by IT, couriered onward — adds days of delay and one unnecessary journey. Windows Autopilot removes it. The device ships from the supplier directly to your new starter, wherever they are; on first sign-in with their company account, it identifies itself to your tenant, and enrolment, encryption, policies and applications flow onto it automatically.

By the time the desktop appears, the machine is encrypted with the key escrowed, compliant with your policies, and loaded with the applications the role requires. Nobody in IT touched it. The same mechanism covers rebuilds: a machine in a bad state can be reset and rebuilt to a known-good configuration remotely, which turns "my laptop is broken" from a courier problem into an afternoon.

Compliance policies, and what non-compliance costs

A compliance policy is a definition of the minimum acceptable state of a device: disk encrypted with BitLocker, screen lock enforced, operating system current, the device not jailbroken or rooted. Intune evaluates every enrolled device against it continuously — not annually, not on request.

The enforcement is what makes it real. Through Conditional Access, compliance becomes a condition of access: a device that drifts out of policy — encryption off, OS too old — is blocked from Microsoft 365 until it is brought back in line. Nobody has to notice, chase, or ask nicely. The estate converges on the policy, because non-compliant devices lose access to the things people need to work.

Application deployment rides the same rails: Office apps, Adobe, line-of-business installers pushed to enrolled devices, updated centrally, and removed when the device is wiped or retired. The alternative — every machine hand-built, every update a per-desk errand — does not survive contact with a distributed team.

BYOD: work data on personal phones, without seizing the phone

Staff will read work email on personal phones whether or not you have a policy — the only question is whether company data is protected when they do. Fully enrolling a personal device is the wrong answer for most businesses: it is intrusive, staff resist it, and it creates obligations nobody wants.

App protection policies are the proportionate tool. Work apps — Outlook, Teams, OneDrive — run inside a managed container on the personal device: company data encrypted within the apps, a PIN or biometric required to open them, copy-paste into personal apps restricted by policy, and the ability to wipe company data from the work apps without touching the owner's photos, messages or anything else personal. The employee keeps a personal phone; the business keeps its data.

This is also the honest answer to the privacy question staff will ask: with app protection, the business manages its apps and its data — not the phone.

Lost laptops, and leavers

Every fleet eventually loses a device — a taxi, an airport, a theft. The difference between an incident and a shrug is preparation. BitLocker encryption is enforced by policy, and the recovery keys escrow automatically to Microsoft Entra, so encryption never depends on a user remembering to switch it on or on IT remembering to record a key. A lost device is unreadable to whoever has it, and is wiped remotely from the console the moment it is reported.

Leavers are the same discipline on a schedule: access revoked at the identity, company data removed from personal devices via app protection, and company laptops wiped and rebuilt for the next starter — a routine, not an improvisation. Between incidents, the device inventory Intune maintains carries its own operational value: what hardware exists, who has it, and which machines are ageing toward replacement.

Typical engagements

Frequently asked questions

Do we need Intune if we are a small business?

Size is not the trigger — the moment devices leave the office with company data on them, you need a way to enforce encryption, screen locks and updates, and to wipe a device you can no longer find. Intune is included in Microsoft 365 Business Premium, so for most SMBs the capability already sits inside a licence they should be on for its security features anyway. The gap is nearly always configuration and rollout, not procurement.

What is the difference between MDM and app protection (MAM)?

MDM manages the whole device — enrolment, encryption, compliance, apps, remote wipe — and is the right model for company-owned hardware. App protection (MAM) manages only the work apps and the data inside them, which is the right model for personal devices: work data contained, encrypted and wipeable without the business managing or seeing the rest of the phone. Most environments use both, split along the line of who owns the device.

Can the company see personal data on employees' phones?

Under app protection, no — the business manages Outlook, Teams and the other work apps and the data inside them, not the device. Personal photos, messages, browsing and apps are outside its reach, and a wipe removes company data from the work apps only. Being able to give staff that answer plainly is a large part of why BYOD programmes built on app protection get adopted rather than resisted.

What happens if a company laptop is lost or stolen?

The disk is already encrypted — BitLocker is enforced by policy, with recovery keys escrowed automatically to Microsoft Entra — so the data is unreadable to whoever has the machine. The moment the loss is reported, the device is wiped remotely from the Intune console and blocked from company resources. What turns a lost laptop into a minor event is that all of this was in place before the loss; none of it can be added afterwards.

How does zero-touch deployment work for a remote hire?

The laptop ships from the supplier straight to the new starter — home, hotel, another emirate. On first sign-in with their company account, the device registers with your tenant and Autopilot takes over: enrolment, BitLocker, compliance policies and the applications for their role, applied automatically. No imaging, no visit to an office, no IT hands on the machine. It is the standard way we onboard distributed teams.

Can you enrol devices we already own, or only new ones?

Existing devices enrol too. Company-owned Windows machines are brought into Intune and registered for Autopilot so that future resets rebuild them cleanly; phones and tablets enrol through the standard mechanisms for company devices; and personal devices come under app protection instead. Taking an existing unmanaged fleet into management is a phased engagement — policies applied in stages, so compliance enforcement arrives without a day of surprise lockouts.

Microsoft Cloud Solution Provider · Intune and Autopilot as standard, not as an upsell
Free IT Health Check →