Try our new research platform with insights from 80,000+ expert users
reviewer2595294 - PeerSpot reviewer
Engineer, Systems Admin . at a financial services firm with 5,001-10,000 employees
Real User
Dynamic groups enhance security while cumbersome deployment process needs refinement
Pros and Cons
  • "Dynamic groups allow us to set conditions for automatic membership, eliminating the need for user intervention or manual review and ensuring a seamless workflow."
  • "Dynamic groups allow us to set conditions for automatic membership, eliminating the need for user intervention or manual review and ensuring a seamless workflow."
  • "Microsoft Intune's app deployment presents challenges for non-MSI and non-store apps, particularly EXEs, requiring the use of a Win32 wrapper tool and adding overhead to the process."
  • "Microsoft Intune's app deployment presents challenges for non-MSI and non-store apps, particularly EXEs, requiring the use of a Win32 wrapper tool and adding overhead to the process."

What is our primary use case?

We use Microsoft Intune to manage mobile devices for our parent company and our independent subsidiaries. These devices are not directly corporate-owned but belong to individuals or subsidiaries with whom we work. We enroll both their and our corporate devices in Intune to manage policies, ensure optimal security settings through compliance reviews, and deploy a VPN client for secure access to our internal network resources.

How has it helped my organization?

Microsoft Intune has provided valuable insight into the status of our independent computers, which previously lacked a management agent and had no standardized security policies. We could not enforce password expiration policies, hardened passwords, or even minimum password requirements, with some users relying on six-character passwords. By enrolling these devices in Intune, we have enforced more robust security measures, such as a minimum eight-character password length, and gained visibility into device compliance to ensure adherence to best security practices for data protection.

The Intune user experience is good, especially with the many improvements made to the web interface over the years. It has always been designed as a simpler interface than Configuration Manager, and Microsoft has done a good job in achieving this goal.

What is most valuable?

Dynamic groups are more efficient than static groups, which require manually adding members. This was cumbersome, especially when onboarding new people, as it necessitated manually adding them to the appropriate groups. Dynamic groups allow us to set conditions for automatic membership, eliminating the need for user intervention or manual review and ensuring a seamless workflow.

What needs improvement?

Microsoft Intune's app deployment presents challenges for non-MSI and non-store apps, particularly EXEs, requiring the use of a Win32 wrapper tool and adding overhead to the process. Additionally, deploying device-specific installers, such as VPN clients, is complicated by the inability to target users directly, necessitating knowledge of device names that may not be readily available. Furthermore, the web interface lacks detailed information for MDM-enrolled devices, such as the user's UPN, requiring the use of Graph Explorer API and necessitating Global Admin consent to access device properties. Enhancing app deployment, enabling user-targeted device application deployment, and improving the web interface, particularly for MDM-enrolled devices, by providing comprehensive device information and customizable columns, would significantly streamline Intune's usability.

Microsoft Intune should enhance flexibility and features to better match the granularity available in systems like SCCM.

Buyer's Guide
Microsoft Intune
May 2025
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Intune for over five years.

What do I think about the stability of the solution?

Microsoft Intune has been stable, and I have not noticed any specific stability issues. While we've encountered problems with other services like Exchange, Intune has remained unaffected.

What do I think about the scalability of the solution?

Scaling Intune is challenging due to the various device types we manage. Our parent company's mobile devices were already enrolled, and we've added our independent Windows devices, with plans to include corporate devices soon. A key hurdle is the lack of visibility into user attributes in Intune, hindering our ability to create dynamic groups effectively. Ideally, we want to automatically segregate devices based on user properties like primary use, but currently, dynamic groups seem limited to device properties. This forces manual group assignment after user enrollment, which is inefficient and reliant on user notification. Improved dynamic group functionality, particularly the ability to leverage user attributes, would significantly streamline device management.

How are customer service and support?

Customer support has been reasonable overall. However, there have been cases, such as issues with BitLocker recovery keys, where support was less effective, leading to multiple hand-offs and delays.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before Intune, the independent devices were unmanaged without any agent. For corporate devices, we previously used SCCM.

How was the initial setup?

The initial deployment of Microsoft Intune was fairly straightforward, despite a few challenges due to our unusual configuration of two on-premise domains syncing to our Azure tenant. This dual user sync caused issues because some users remained on the older domain, leading to conflicts when automated systems modified on-premise account attributes. These modifications triggered Azure to switch the sync to the other account, resulting in login failures for users with cached credentials from the old account. While we've mostly identified the cause and the fix, we still encounter this issue occasionally.

What about the implementation team?

The deployment was handled in-house. Our organization benefited from having skilled personnel and guidance from our parent company.

What was our ROI?

The return on investment includes successfully distributing applications like a VPN client and Office 365. As a result, independent devices now have better application access, encouraging even non-enrolled entities to request Intune enrollment.

Which other solutions did I evaluate?

We considered Tanium for managing independent devices, but it's a comprehensive endpoint management tool with more functionality than we needed. Management felt it would introduce unnecessary overhead. Since all our corporate devices are currently managed with Intune, adding independent devices would require segregation. Ultimately, we opted for Intune due to its ease of use, allowing us to create targeted policies from scratch.

What other advice do I have?

I would rate Microsoft Intune a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Microsoft Support Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
It helps consolidate our endpoints, simplifies mobile device management, and provides a smooth user experience
Pros and Cons
  • "Intune significantly simplifies application deployment, mobile application management, and policy enforcement, such as restricting user access to specific applications, thereby enhancing overall environment security."
  • "Since GMS is unavailable in China, we currently rely on device administrator enrollment for managing Android devices there."

What is our primary use case?

We use Microsoft Intune to manage mobile devices across almost all platforms, including Android, Windows, and Linux, which was recently added just a few months ago.

Previously, we relied on on-premises infrastructure using SCCM to manage mobile devices alongside other tools. Intune is a cloud-based solution that empowers administrators to manage cloud devices, implement policies, and deploy applications. While other MDM platforms exist, Intune is a top choice due to its feature set.

How has it helped my organization?

Microsoft Intune consolidates our endpoint and security management tools into a single platform. While still under development with new security features on the horizon, the current capabilities offer administrators ample tools to fortify the environment.

Intune simplifies mobile device management by consolidating endpoint and security tools into a single platform. This centralized approach enables IT administrators to efficiently manage various aspects, including Windows updates, Wi-Fi and VPN policies, application restrictions, and user account creation, all within the Intune interface, significantly streamlining the overall management process.

The user experience is quite smooth for most users because administrators handle all necessary configurations. Options like Windows Autopilot and zero-touch deployment enrollment significantly simplify the process, minimizing user intervention and effort required to set up and use devices.

I currently support Microsoft admins and have handled numerous cases related to Enterprise Application Management. Many companies utilize this tool to manage their in-house applications. While not all companies employ this method, most larger organizations do. These companies often deploy their enterprise applications using Intune, which offers a feature that allows admins to protect application data through mobile application management policies. To enable MAM, applications must be wrapped with the Intune Software Development Kit to communicate with Intune services. This process is valuable as it empowers admins to safeguard sensitive data. Intune provides SDK options for both iOS and Windows applications.

There are two methods for automatically updating the application: independent updates within the application itself or updates to the application package managed through Intune. The chosen method depends on the enterprise application's configuration. Recently introduced Azure application registration simplifies the process by requiring registration before deployment, enhancing security through authentication.

We utilize advanced endpoint analytics within the Intune suite, and the recent release of Windows Autopilot's version has expanded the range of analytics tools available to administrators. While Intune provides data on devices and users under its management, more in-depth reports can be accessed through Log Analytics or Azure Monitor. However, Intune's analytics are sufficient for gathering reports on managed devices.

The advanced endpoint analytics feature within the Intune suite allows us to access detailed information about our devices. This includes data on device counts, specific settings for bulk administration or devices, and the ability to filter devices based on our needs.

I have experience with several MDM solutions. While Microsoft Intune is excellent for managing thousands of user devices, it may not be ideal for specific use cases like bulk printer or Jabra device management, which could present challenges. However, Intune shines in organizations with large numbers of users, especially when integrated with existing on-premises infrastructure or SCCM. This integration can streamline operations and reduce staffing needs. For example, a ten-person IT team might only require two to five people dedicated to Intune management with on-premises support. While I cannot provide a full sales pitch, I confidently recommend Intune to anyone seeking a robust MDM solution.

Copilot in Intune is valuable when integrated with back-end data, such as our existing tools and libraries. This integration empowers administrators to assess information effectively. However, the tool's effectiveness hinges on the quality of data input and query formulation. As users are still familiarizing themselves with Copilot, its adoption varies across environments, with some users enabling it and others disabling it.

Copilot in Intune simplifies IT operations by quickly responding to inquiries about integrated systems. Users won't need to search for specific details as Copilot offers a variety of solutions.

Intune offers more than device management; it also aids in user management. Regardless of the platform, Intune provides various options for device enrollment. Intune prevents mixing personal and corporate data, whether using a corporate or personal device. It also offers robust security features, enabling granular control over user access to applications, resources, and other tools.

In a hybrid environment, security management depends on whether devices are co-managed and how policies are configured in Intune. Intune offers various features, including remote actions, to address these scenarios. However, I discovered an issue with BYOD devices on iOS: wiping an enrolled device deletes all data, not just corporate data. This is a problem that needs to be addressed internally.

With the endpoint privilege management feature, the admin can create an EPM policy. If a user tries to access a resource, the admin will be prompted to grant or deny access based on the policy.

Suppose I need to access data, logs, or files on a Windows device that a global administrator restricts or requires approval for. In that case, I can configure an EPM policy to remind users that additional authorization is necessary. For instance, I encountered cases where users frequently mistakenly assigned test applications to production environments. To prevent this without restricting access or privileges, we configured an EPM policy to prompt users specifically when assigning that application to a production environment. This approach demonstrates how EPM policies can be tailored to address various requirements.

EPM provides an additional layer of authentication for accessing a resource, application, or permission. For ASR, we can define rules by which users can access the resources.

Intune has significantly improved productivity by simplifying tasks like certificate authority restoration. For example, using a deployed CA server certificate, I've set up a Wi-Fi profile with auto-authentication. Previously, expiring certificates required manual reissuance, but Intune automates this process by revoking certificates when they approach their expiration threshold. This threshold, configurable within the certificate profile, can be set as a percentage of the certificate's lifespan. A revocation request is triggered when the threshold is reached, ensuring a new certificate is issued for the device or user profile before the old one expires.

Intune's integration with Microsoft 365 and Microsoft Security for both cloud and co-managed devices is beneficial because it offers a centralized platform. We can directly assign licenses within Intune instead of using the separate M365 admin portal to create users, simplifying the process. Intune synchronizes features and functions from M365, streamlining management. However, purchasing new licenses still requires accessing the admin center. Despite this, Intune effectively synchronizes information to endpoints.

What is most valuable?

While conditional access isn't solely limited to Intune, we can also effectively implement and manage conditional access policies through Azure. However, Intune significantly simplifies application deployment, mobile application management, and policy enforcement, such as restricting user access to specific applications, thereby enhancing overall environment security. Furthermore, Intune automates numerous tasks previously requiring manual configuration by administrators, streamlining the process by creating simple policies for desired outcomes.

What needs improvement?

There are specific devices we can focus on. For example, due to GMS restrictions in China, we face limitations. However, BlackBerry UEM can enroll Android devices as Android Enterprise, though the exact method is unclear. We could explore whether Intune can replicate this functionality. Since GMS is unavailable in China, we currently rely on device administrator enrollment for managing Android devices there. This suggests potential opportunities to develop solutions or collaborate with Chinese partners to create new features within Intune for managing Android devices in the Chinese market.

For how long have I used the solution?

I have been using Microsoft Intune for three years.

What do I think about the stability of the solution?

While some specific tenants experience occasional outages and bugs, our monitoring team is actively tracking an upcoming issue affecting certain tenants in specific regions. Both the support and broader teams are diligently working to resolve this. Aside from this, Microsoft Intune is demonstrating overall stability.

What do I think about the scalability of the solution?

If an organization has the budget, they can easily scale Microsoft Intune.

How are customer service and support?

Microsoft's technical support for Microsoft Intune and the broader Microsoft environment consists of several tiers. Customers can choose between broad commercial support, Pro support, or Premier support, the latter including dedicated Customer Success Account Managers and Incident Managers to facilitate access to specialized engineers. Support engineers are categorized into levels one, two, and three. We collaborate weekly with global subject matter experts to address ongoing issues and cases. For complex or backend problems, we engage the product group using a specific request form. While Microsoft previously employed support staff primarily in the US and Canada, they now utilize vendors in India and the Philippines, offering varying levels of expertise. To enhance support quality, Microsoft should invest in training these engineers and consider opportunities for full-time employment, rather than incurring the costs of recruiting and training new staff.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?


How was the initial setup?

An organization migrating to the cloud typically requires an Azure subscription as a starting point. While our FastTrack Team offers full migration solutions, IT administrators can also independently move operations to the cloud by purchasing an Azure subscription, tenant, and licenses and configuring policies, privileges, and workloads. Existing on-premises infrastructure can be synced to the cloud using Azure AD Connect, enabling management within a hybrid or pure Azure AD environment. The ease of migration depends on the administrator's experience, and Microsoft support is available for those requiring assistance.

One to two solution architects are enough for the deployment.

Several factors influence the time required for deployment. For instance, with a user base of 100, deployment can be achieved within a week. However, environments with thousands of users and devices, especially on-premises setups, present greater challenges. Customers or administrators migrating to the cloud and adopting Intune often follow a phased approach. They typically start by deploying and testing a subset of policies to assess manageability and feasibility before proceeding with application deployment. As a result, the overall deployment timeline varies significantly across organizations and can extend to several weeks.

What's my experience with pricing, setup cost, and licensing?

Microsoft services are slightly more expensive than competitors but offer advantages and disadvantages. Even if they charge a premium, they aim to provide equal value.

Which other solutions did I evaluate?

I have experience with SOTI MobiControl, Jamf Pro, and AirWatch. SOTI MobiControl excels at managing specific devices, offering a list of compatible models upon request. Intune, however, struggles with printer management and Zebra device compatibility. Its network security features are limited due to ongoing development, and it lacks in-built policies for third-party applications, hindering compatibility and communication with external devices and manufacturers. While custom policies can be implemented, comprehensive built-in options would be beneficial.

What other advice do I have?

I would rate Microsoft Intune eight out of ten.

Intune requires no maintenance after initial deployment, but ongoing subscriptions are necessary for each user as individual licenses are needed monthly. Microsoft continually updates the service to support the latest operating systems and applications, so ensuring our environment is up-to-date is crucial for optimal performance.

Microsoft Intune is a good tool, and to simplify operations, I recommend a full cloud environment over a hybrid environment.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Microsoft Intune
May 2025
Learn what your peers think about Microsoft Intune. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Nicola Moresi - PeerSpot reviewer
Ceo at Moresi.Com SA BGP Network
Real User
Top 10
The compliance features are valuable because they allow immediate visibility into ongoing situations
Pros and Cons
  • "Intune's compliance features are valuable because they allow immediate visibility into ongoing situations."
  • "Microsoft Intune has helped us by improving our security posture, leading to fewer security problems, and helping us understand where we have issues."
  • "It would be interesting to integrate the server side of Intune. Some group policy updates we have on the Windows Server side and possibly some on the client side could also be included."
  • "It would be interesting to integrate the server side of Intune. Some group policy updates we have on the Windows Server side and possibly some on the client side could also be included."

What is our primary use case?

We use Intune for security or endpoint inside the company and especially for many customers we have.

How has it helped my organization?

Microsoft Intune has helped us by improving our security posture, leading to fewer security problems, and helping us understand where we have issues. 

What is most valuable?

Intune's compliance features are valuable because they allow for immediate visibility into ongoing situations. The solution is very easy to use. We haven't implemented Microsoft Copilot but will adopt it next year. It will be interesting to use natural language to interact with Intune.

What needs improvement?

It would be interesting to integrate the server side of Intune. Some group policy updates we have on the Windows Server side and possibly some on the client side could also be included.

For how long have I used the solution?

I have been using Microsoft Intune for about two years.

What do I think about the stability of the solution?

Microsoft Intune is very stable.

What do I think about the scalability of the solution?

The scalability of Microsoft Intune is good. We don't have large customers, so we haven't seen any issues with scalability.

How are customer service and support?

I rate Microsoft support nine out of 10. Customer service and technical support are good. The technical support from Microsoft and Infineon Technologies is also good. The quality and professionalism of the people are really good, although sometimes we need to escalate to get the right content and answers.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used a solution from an older competitor that is now defunct.

What about the implementation team?

We did not use an integrator, reseller, or consultant for the deployment because we are an integrator.

What was our ROI?

Our customers have seen a significant return on investment because they now understand and see where the problems are on the endpoints without needing to search the entire company.

What's my experience with pricing, setup cost, and licensing?

We know the pricing is good because customers are not complaining about it.

Which other solutions did I evaluate?

We directly switched to Microsoft Intune after receiving good feedback from customers.

What other advice do I have?

I would rate Intune eight out of 10. Some features could be added, but it is a rock-solid solution.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Mahmoud-Eldeep - PeerSpot reviewer
Technical Sales Professional (Microsoft Modern Workplace) at Alnafitha IT
Real User
Top 20
Enables us to deploy applications to devices remotely without touching or interacting with the end user
Pros and Cons
  • "Microsoft Intune is very stable due to its cloud-based infrastructure and its reliability in performance."
  • "Improvements are needed in Microsoft Intune's enterprise app management, including support for more applications in app patching, boot batching, and discovery. I also hope the cost of Remote Help will decrease because it's a much-needed Intune function. Our customers need that capability, or they will buy it from a third party at a premium."
  • "I also hope the cost of Remote Help will decrease because it's a much-needed Intune function."

What is our primary use case?

We use Microsoft Intune to manage our customers' end-user workstations. Specifically, we use it for mobile application management, managing personal phone devices for iOS and Android without enrollment, and configuring app VPN through the Intune tunnel server. We also manage Microsoft Teams for mobile application management and use it extensively for Windows devices.

How has it helped my organization?

Microsoft Intune has helped by making additional access based on corporate owned devices or managed devices, which prevents our IT admins from accessing specific organizational resources unless using these secure devices.

Intune enables us to deploy applications to devices remotely without touching or interacting with the end user. We can also configure some profiles, like Wi-Fi profiles, for specific branches without additional configuration from the end user. It's easy for end-users to adopt changes or merge branches. Also, you can predefine the applications so they automatically download when the user joins that branch.

What is most valuable?

Microsoft Intune offers features such as mobile application management and always-on VPN for Windows, which are valuable for managing customer devices and ensuring efficiency. It also aids in application deployment and configuration without requiring direct user interaction, simplifying the integration of new devices and systems.

We use endpoint analytics to analyze the user performance on their machines or  app crashes. We can also evaluate Windows startups to detect if there are some user problems or if it's their workstation performance. We can be more proactive about improving our user's work infrastructure. 

We use enterprise application management for app patching, but it needs to include more applications. Some important applications are not part of the enterprise app management, but we hope they will be added soon. We appreciate the automatic updates and discovery of installed applications and older devices. Automatic patching will help us keep the devices and applications up to date to detect newly discovered vulnerabilities. Copilot helps us generate reports about compliant devices and software installed on specific devices. We can also track the device's compliance state. 

What needs improvement?

Improvements are needed in Microsoft Intune's enterprise app management, including support for more applications in app patching, boot batching, and discovery. I also hope the cost of Remote Help will decrease because it's a much-needed Intune function. Our customers need that capability, or they will buy it from a third party at a premium. 

For how long have I used the solution?

We have used Microsoft Intune for around three years.

What do I think about the stability of the solution?

Microsoft Intune is very stable due to its cloud-based infrastructure and its reliability in performance.

What do I think about the scalability of the solution?

Microsoft Intune's cloud-based nature ensures it is highly scalable, supporting a large number of devices without performance issues.

How are customer service and support?

We do not often rely on Microsoft Support. Sometimes response times can be long, but generally, they are helpful in resolving issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Previously, we used solutions like ManageEngine and Endpoint Central. We switched to Microsoft Intune to better support enterprise customers needing fully managed devices like iPads for secure environments.

How was the initial setup?

The initial setup of Microsoft Intune was straightforward, thanks to its various enrollment methods.

What about the implementation team?

We are a consulting partner, providing implementation services for Microsoft Intune.

What was our ROI?

We've seen a return on investment through enhanced security, as Intune allows access to critical systems only through corporate-owned devices, integrating well with Microsoft’s ecosystem to protect company assets.

What's my experience with pricing, setup cost, and licensing?

The default capabilities of Microsoft Intune are reasonably priced, but the Intune suite and add-ons, such as batch management and remote help, are costly, leading customers to consider third-party options.

Which other solutions did I evaluate?

Before switching to Microsoft Intune, we considered ManagerEngine. Eventually, the decision focused on Intune specifically to meet enterprise requirements.

What other advice do I have?

I rate Microsoft Intune eight out of 10. I deduct a couple of points because key features like application patching and Remote Help need to be purchased separately. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: LSP Partner
Flag as inappropriate
PeerSpot user
reviewer2595288 - PeerSpot reviewer
Solutions Architect at a computer software company with 51-200 employees
Real User
Allows us to maintain a necessary security patch level
Pros and Cons
  • "The most valuable feature of Microsoft Intune is patching-related capabilities."
  • "The stability of Microsoft Intune is ten out of ten."
  • "A more incisive reporting tool with automated progress updates and graphical representation would be beneficial, as the current manual method lacks efficiency and visual clarity."
  • "A more incisive reporting tool with automated progress updates and graphical representation would be beneficial, as the current manual method lacks efficiency and visual clarity."

What is our primary use case?

We operate call centers and provide our agents with laptops that they use from their home environment or home offices. We use Microsoft Intune to manage those laptops remotely. This remote management accounts for 99 percent of our use cases.

How has it helped my organization?

Microsoft Intune has effectively managed our patching needs, resulting in very few system-wide issues. While a small number of laptops occasionally fail to receive updates, the vast majority are patched successfully without manual intervention.

Microsoft Intune has enabled us to effectively manage our laptops, which is crucial for our involvement in civilian federal projects. The platform allows us to maintain a necessary security patch level and address any bugs that may arise, ensuring our devices are always secure and functional. Implementing Intune provides a cost-effective solution that would otherwise be prohibitively expensive.

Our Intune users, the IT group and system administrators, are happy with the system and have not reported any complaints.

What is most valuable?

The most valuable feature of Microsoft Intune is patching-related capabilities. This is because patches are constantly being released, and it requires us to stay current with bug-related and security-related patches, which is critical for our day-to-day operations. Intune's support in this area is crucial for us to maintain our laptops at a certain security patch level.

What needs improvement?

A more incisive reporting tool with automated progress updates and graphical representation would be beneficial, as the current manual method lacks efficiency and visual clarity.

For how long have I used the solution?

I have been using the solution for about a year.

What do I think about the stability of the solution?

The stability of Microsoft Intune is ten out of ten. It has been very stable for us.

What do I think about the scalability of the solution?

The scalability of Microsoft Intune is ten out of ten. Although we are not the largest company, it has never presented any scalability issues for us.

How are customer service and support?

The customer service is above average. We have an Azure engineer on staff who handles troubleshooting. Although we have not had any major issues.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?


How was the initial setup?

The initial setup is straightforward. We manage everything in-house with just a few commands needed before deploying laptops, never having to reconsider our processes.

What about the implementation team?

We do everything ourselves without using a reseller or consultant.

What was our ROI?

We have never operated without Microsoft Intune, but it is apparent that it offers significant cost reductions. Operating without it would likely be prohibitively expensive, indicating a ninety-nine percent reduction in cost with Intune.

What's my experience with pricing, setup cost, and licensing?

The alternative to Intune, sending out replacements for every issue, is prohibitively expensive. In contrast, Intune's pricing is reasonable considering its benefits and the high costs it helps avoid.

Which other solutions did I evaluate?

We evaluated other options that are tool-specific. For instance, our call center platform from NICE's CXone, has built-in Copilot-like capabilities. Nevertheless, Copilot remains our primary focus as it covers our entire spectrum of needs.

What other advice do I have?

I rate Microsoft Intune nine out of ten.

We recently started using Copilot and find its support features very attractive. Our call center agents are internal customers who, like any customer, need occasional assistance with various issues. Copilot could benefit both IT and non-IT departments by providing faster service, self-guided troubleshooting, and access to relevant resources. For example, if an agent has an HR question, needs help with benefits, or experiences a technical issue like audio problems with their laptop, Copilot could guide them with self-service options or provide helpful files. This would empower our agents to resolve issues independently and efficiently. Our initial analysis suggests Copilot may have the potential to protect our environment, though our assessment is ongoing and we haven't begun implementation. Preliminary findings indicate it will be a valuable tool.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
CHRISTOS-PANAGIOTOU - PeerSpot reviewer
IT Manager at Profile Software
Real User
Top 10
Helps to improve our data governance, security, and central management
Pros and Cons
  • "The compliance and configuration policies in Microsoft Intune are the most valuable features, saving significant time compared to manual implementation."
  • "Although Intune is from the same provider, its integration with other Microsoft products, like Microsoft Defender or Microsoft Purview, could be improved."

What is our primary use case?

I used Microsoft Intune for compliance policies, configuration policies, and Intune enrollment.

We implemented Microsoft Intune to manage mobile devices in bulk and enforce management policies.

Intune was deployed in a hybrid environment. Devices were initially onboarded to Azure Active Directory and then enrolled in Intune. All devices originated from a local Active Directory.

How has it helped my organization?

Intune brought all of our endpoint and security management tools into one place. 

Having our endpoint and security management tools in one place saves time, and I have most of the information in one dashboard.

From an administrative and user standpoint, Intune offers a beneficial and secure user experience.

I have had a great experience with enterprise application management for app discovery, deployment, and automatic updating because it automates all the procedures.

Intune improved our data governance, security, central management, and policy application. I realized these benefits after two to three months of seeing how Intune works.

Intune effectively secures hybrid work environments and safeguards company data, especially on BYOD devices. Through Intune, we can monitor all devices accessing company data and manage them centrally, which is crucial.

Intune affected IT productivity in our organization by governing company data, securing global data, and saving time, all through central management.

It helped our organization save 50 percent of costs by integrating Office 365 and Intune into one license. We didn't have to use third-party software for mobile device management.

Intune helped consolidate vendors. This consolidation has dramatically improved our security posture.

The vendor consolidation helped reduce our licensing costs.

The integrated capabilities of Intune within the Microsoft 365 and Microsoft Security suites are essential for managing cloud and co-managed devices. They provide a comprehensive solution under a single license, eliminating the need to install agents from third-party vendors and saving significant time and effort.

What is most valuable?

The compliance and configuration policies in Microsoft Intune are the most valuable features, saving significant time compared to manual implementation. The security integration with Microsoft Defender is also valuable.

What needs improvement?

Although Intune is from the same provider, its integration with other Microsoft products, like Microsoft Defender or Microsoft Purview, could be improved. Regarding synchronization, there are occasional delays in updating a device's status. Integrating Microsoft products, such as Microsoft Purview, Microsoft Defender, and Entra, requires enhanced synchronization capabilities.

For how long have I used the solution?

I have been using Microsoft Intune for almost three years.

What do I think about the stability of the solution?

I would rate the stability of Microsoft Intune eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Microsoft Intune eight out of ten.

How was the initial setup?

Intune has too many capabilities. Deploying it is not straightforward, but it gets easier once you understand how it works.

For 200 devices, the deployment took us almost three months to complete.

What was our ROI?

In conjunction with Microsoft Defender, Intune has significantly reduced our spending on third-party endpoint security solutions. For instance, we previously used Check Point, but after implementing Intune and Defender, we discontinued using it, resulting in substantial cost savings.

What's my experience with pricing, setup cost, and licensing?

Our Office 365 Business Premium license, including Office 365 and Intune Management, offers excellent value.

What other advice do I have?

I would rate Microsoft Intune eight out of ten.

I would recommend Microsoft Intune to others.

Intune offers a wide array of capabilities, and even after extensive familiarity with the platform, it's difficult to fully grasp its potential. To effectively implement Intune, it's recommended to conduct thorough research, primarily through online resources, to understand specific requirements and capabilities in advance.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Aekantak Vashistha - PeerSpot reviewer
Cloud Engineer III at Insight
Real User
Top 10
Intune centralizes device, application, and policy management, enhancing IT efficiency and security, though some custom deployments require additional innovation.
Pros and Cons
  • "I like how Intune brings everything into one place. For example, you can set up conditional access to applications and devices inside Intune. I also like the segregation inside the Intune devices. You can segregate them by Windows, iOS, iPadOS, macOS, and Android. You can sort it by platform, so you don't need to go into the devices section."
  • "I rate Microsoft support four out of 10. Support is one area where Microsoft needs to improve a lot. I recently raised a ticket for a Microsoft Azure issue, and it took two and a half weeks for support to reply. They need to improve support across their entire catalog of products."

What is our primary use case?

You can use Intune to manage devices for any size project, from a small business to an enterprise-level project. You can manage hundreds of thousands of devices. Intune can manage on-prem and cloud services. We are working with large enterprises mostly.

How has it helped my organization?

Intune encompasses all devices, applications, and policies that can be deployed within an organization through a single portal. In the event of an outage, it simplifies the management and resolution of issues or policy adjustments. It allows for the management of security profiles, applications, and devices from one portal across any operating system platform.

Consolidating everything in one location enhances the efficiency and productivity of IT administrators. Since adopting Intune, our IT team's productivity has increased by 20 to 30 percent. Additionally, the integration of Copilot has further improved our efficiency by 5 to 10 percent.

However, there are exceptions. Certain applications cannot be deployed easily via Intune. Win32 deployment is necessary for these, which can be challenging as it demands extensive testing to release a custom package from Intune. More innovation is needed to deploy custom applications, which would greatly benefit us. For most enterprise scenarios, application deployment is relatively straightforward.

Hybrid environments call for innovation, particularly with hybrid enrollments using GPO. While most autopilot hybrid scenarios and co-management run smoothly, I have encountered issues with hybrid GPO enrollments due to their complexity.

Intune is a leading secure solution in the Indian market. It allows the creation of any conceivable security policy. With the addition of Purview and DLP modules and integration with Microsoft Defender for Endpoint, security has never been a concern, and our security posture is nearly impeccable.

Intune has also facilitated vendor consolidation. It is our primary recommendation for an MDM solution because it offers the productivity and features that would otherwise require integration of multiple solutions from other vendors. The industry is now transitioning from on-premises Intune to cloud-based management.

Intune enables the deployment of any security solution. Although it does not integrate, it allows for the deployment of a wide range of security measures.


What is most valuable?

I appreciate how Intune consolidates everything in one location. For instance, it allows the setup of conditional access for applications and devices directly within Intune. The segregation feature within Intune devices is also beneficial. Devices can be categorized by Windows, iOS, iPadOS, macOS, and Android, and sorted by platform, eliminating the need to navigate the devices section.

The app management feature has seen significant improvements. Initially, navigating the app section was quite challenging, but now, all my concerns have been addressed. It's possible to deploy or manage any application, with reports and app-protection policies accessible in the same section, which is quite convenient.

I would rate the user experience at nine out of 10. Having utilized various MDM solutions from Microsoft, Cisco, and VMware, I find Intune to be superior. We employ Microsoft Defender for Endpoint and DLP policies in Purview, along with multiple security policies such as baselines and BitLocker for encryption. This integration simplifies the administration of security features from other tools in one place.

The most sophisticated analytics we've utilized are group policy analytics. As a consultant, I often handle multiple migrations, primarily from on-premises to the cloud. Group policy analytics are particularly useful in these scenarios as we migrate on-premises policies. If Intune lacks support, we must either start anew or seek alternatives.

Copilot is beneficial as it supports various CSPs or policies. Despite extensive use, one cannot be fully versed in everything about Intune. Whenever there's confusion, Copilot is a valuable resource to clarify and ensure the feasibility of creations within Intune. Copilot assists in profile creation and assignment considerations.

My perspective on tools like Copilot is that they are artificial; the intelligence aspect is still emerging in the AI industry. Nevertheless, Copilot is a well-maintained and informed tool.


What needs improvement?

Microsoft currently restricts deployment to PowerShell or XML scripts, so it would be beneficial to support additional scripts such as command scripts, C languages, or TypeScript to enhance systematic compliance.

While the UI has been updated, it could be made more accessible. Navigating to a specific section in Intune requires multiple clicks through different areas before arriving at the intended destination, indicating the UI could benefit from further improvement.

The process of application discovery and deployment is relatively seamless. Nonetheless, there is room for enhancement in the reporting aspect. Intune still lacks comprehensive reports, and notably, its failure reporting does not succinctly communicate the full extent of an error.


For how long have I used the solution?

I have used Intune for more than six and a half years. 

What do I think about the stability of the solution?

I rate Intune 10 out of 10 for stability.

What do I think about the scalability of the solution?

With Linux and Chrome OS now supported, the scalability has reached 100 percent. Every device or endpoint operating on our OS can be enrolled in Intune. 

How are customer service and support?

I would rate Microsoft support as four out of ten. Support is an area where Microsoft could significantly improve. I had an issue with Microsoft Azure recently, and after raising a ticket, it took two and a half weeks to receive a response. There is a need for enhanced support across all their product offerings.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We have utilized Cisco Meraki, VMware Workspace ONE, and Jamf for managing Apple devices. However, Intune stands out among these options because it overcomes application deployment limitations that others have. While some support only Apple or Windows devices, Intune excels in compatibility, supporting Android as well. Moreover, Intune can implement more security policies than any other MDM solution available.

How was the initial setup?

Hybrid enrollment is typically complex, yet cloud autopilot simplifies the process considerably. It's possible for anyone to grasp cloud deployment within five to ten minutes. While the most intricate enrollments, involving thousands of devices, may take two to three weeks, a cloud-based deployment can be accomplished in approximately one week.

What about the implementation team?

This was completely in-house.

What's my experience with pricing, setup cost, and licensing?

Intune is considered moderately priced. It is available as part of a bundle with Microsoft 365 E3 or E5 licenses. While the E5 licenses are somewhat costly, Intune offers some more affordable solutions.

Which other solutions did I evaluate?

Yes, we evaluated Cisco Meraki and VMware workspace One.

What other advice do I have?

I give Microsoft Intune a rating of nine out of ten. Intune stands out as one of the top solutions in the market, and its capabilities are expanding with the integration of cloud PCs, Chrome OS, and Linux systems. For any large enterprise, I endorse both Intune and Defender.

The recent CrowdStrike outage, which is the largest in IT history, affected only systems without Microsoft Defender but with CrowdStrike. This incident underscores the importance for enterprises to transition towards deploying Intune and Defender for enhanced security.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
End User Computing Architect at a consultancy with 10,001+ employees
Real User
Top 20
Simplifies IT and security operations and enrolling endpoints is a breeze
Pros and Cons
  • "A valuable feature is user enrollment, where users can enroll their devices in their organizations themselves."
  • "The current Intune reporting functionality could benefit from some improvements."

What is our primary use case?

We use Intune to manage endpoints as a centralized enterprise solution. Instead of relying on Active Directory or an on-premise system, we directly manage employee devices using Microsoft Intune. Intune, a cloud-based SaaS product, simplifies endpoint management. From a user perspective, it's an improvement. Users no longer need to be on the office network. They can set up their devices anywhere with an internet connection, whether at home or another location.

Security is also enhanced. By using Intune as a mobile device management solution, we can implement security controls and restrictions on endpoints. Intune helps us achieve a balance between user experience and security.

How has it helped my organization?

Managing remote employee devices with Microsoft Intune is easy. Intune acts as a central platform for deploying controls, policies, and applications to our endpoints. It simplifies the delivery of these configurations to our remote workforce.

Intune simplifies our mobile application management. Once implemented across the organization, it will eliminate our reliance on on-premises solutions. Previously, managing endpoints required using our System Center Configuration Manager. Now, Microsoft offers a unified solution called Microsoft Endpoint Manager. Intune, a key component of this suite, allows for convenient device enrollment over the internet, streamlining endpoint organization.

Intune helps bring our endpoints and security management tools into one place.

Consolidating endpoints and security management tools simplifies IT and security operations. This unified approach offers a single solution or console for all tasks. Role-based access control ensures each administrator only sees and modifies what's relevant to their role. For example, the security team can access Intune solely for security-related functions, while the patch management team has its own set of permissions. This centralized management is significantly easier to handle than using multiple third-party tools. Intune provides a comprehensive solution where everyone can configure settings – security, endpoints, controls, etc. – within a single platform.

Intune offers endpoint visibility and IT control across various device platforms. It simplifies troubleshooting and device management compared to other solutions. Intune excels in providing a comprehensive solution. We can manage applications, security controls, and patching processes all within Intune. This eliminates the need to rely on three separate solutions. With Intune, everything is consolidated into a single platform, allowing for combined reporting and streamlined issue resolution.

Enrolling endpoints with Intune is a breeze! The overall user experience is excellent, easily a nine out of ten.

There are three critical features of Intune for maintaining our devices' security. Endpoint encryption ensures data on the device is scrambled even if it's lost or stolen. Intune supports BitLocker encryption for Windows devices and file-level encryption for Mac devices. Defender is a comprehensive security solution that helps protect devices from malware, viruses, and other threats. Compliance policies in Intune allow us to define security requirements for devices. These policies can enforce encryption, complex passwords, and other security settings. If a device doesn't meet the compliance policy, it can be restricted from accessing organizational resources. Intune can also send notifications to users or administrators when a device becomes non-compliant.

In the initial stages of migrating from our on-premises solution to Intune, we relied on device compliance policies. We configured these policies to require the latest antivirus signatures, specifically targeting developer devices. This ensured compliance and minimized the risk of non-compliance impacting their work. While compliance policies were initially used, we've since transitioned to Microsoft Defender, which now plays a major role in our device security strategy.

Intune's application deployment feature has significantly improved efficiency in our IT department. As one of its key functionalities, Intune allows deployment of a variety of applications with different extensions, such as .DXE or .MSI files. However, for applications requiring custom license scripts, batch files, or executables, Intune provides its own Windows app deployment toolkit. This toolkit facilitates the conversion of these files into a format compatible with the Intune app store and its update system.

The user interface is easy to navigate. Microsoft provides monthly updates that introduce new features. Previously, they provided pie chart visualizations for complaint and policy control status reports. These have been transitioned to standard chart formats. Overall, the UI continues to improve with each Microsoft update.

Company-owned devices are subject to a different set of policies. These policies may be very strict, restricting certain functionalities, or they may prioritize security above all else. On the other hand, for BYOD programs, we provide users with certain privileges for their mobile devices and laptops. We create a secure, isolated environment in a sandbox to manage the devices within that environment. Security is a major consideration for both BYOD and company-owned devices.

Intune has increased our IT productivity for patching and security by around 15 percent.

Microsoft Intune helps our organization reduce the risk of security breaches by eight percent by deploying zero-day patches in conjunction with Defender and Sentinel.

Intune has helped us consolidate vendors with the driver deployment and onboarding.

We manage configurations for Microsoft 365, co-managed devices, Azure, Defender security controls, and DLP controls within Intune. This centralized platform allows us to configure roughly 80 percent of these services and controls in a single location.

What is most valuable?

A valuable feature is user enrollment, where users can enroll their devices in their organizations themselves. This streamlines the process and saves IT time.

Another key benefit is zero-day productivity. During enrollment, the user has access to the applications and settings the organization needs them to have, making them ready to work immediately. Intune essentially pre-configures the device based on the user and organization during enrollment.

Finally, Intune offers easy patch management for various endpoints, including Windows 10, 11, and Macs. Deploying upgrades and monthly patches is significantly simpler compared to other solutions, both from Microsoft and third-party vendors.

What needs improvement?

The current Intune reporting functionality could benefit from some improvements. Specifically, a report that tracks patch deployment status would be valuable. Ideally, I'd like a report that provides device-level details on applications and controls deployed. However, it seems like other organizations might be more interested in control-centric reports, showing details like what control was deployed, the number of devices affected, and other relevant device data. Overall, reporting is the area where we're encountering the most challenges with Intune.

For how long have I used the solution?

I've been using Microsoft Intune as a comprehensive solution for the past six years. While I had some experience with it before 2019, it was limited to mobile device management. Since 2019, I've been managing the full Intune suite as an administrator, overseeing Windows endpoints, Mac endpoints, Android and iOS.

What do I think about the stability of the solution?

I would rate the stability of Microsoft Intune eight out of ten.

What do I think about the scalability of the solution?

Microsoft Intune excels in scalability, earning it a nine out of ten rating. It empowers organizations to migrate to the cloud and manage all their endpoints seamlessly. This includes a wide range of platforms like Windows, macOS, mobile devices, and even Linux. Intune simplifies endpoint management by offering a centralized solution for all these platforms.

How are customer service and support?

The response time and technical knowledge of the support team is not what it used to be.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used an on-premises solution, Microsoft Endpoint Manager, to manage our devices. The pandemic necessitated a shift to the cloud.

How was the initial setup?

The initial deployment of Intune can be complex because it is linked to Microsoft Entra, which itself is a complex product. This complexity depends on the desired outcome. Intune's deployment complexity hinges on whether users will enroll their devices themselves or if the IT team will enroll them and grant access. A proper pre-assessment is crucial to determine if Intune's complexity aligns with our desired outcome.

Our deployment took two months to complete because of the internal security approvals we required.

Three administrators were required for the deployment.

What's my experience with pricing, setup cost, and licensing?

The price for Intune is fair.

What other advice do I have?

I would rate Microsoft Intune eight out of ten. There are some improvements concerning the reports and there are other design-related concerns that we are looking at in Intune.

We don't have the tunnel option because we primarily work in a restricted computer environment. Our organization uses Microsoft Intune to manage applications within a dedicated sandbox environment. We perform frequent updates to ensure everything is current.

During the initial onboarding process, we encountered some challenges, and multiple teams were involved in resolving them. For example, users from India might experience issues like broken URLs or restricted access due to their ISPs. Similarly, in China, certain URLs might be blocked by some internet service providers. To address these issues, we initially involved additional administrators from each region on the administrative side. However, we've since transitioned to a centralized management structure with a core team of five to six members overseeing the entire organization.

We maintain a separate development Intune environment for User Acceptance Testing specific to the Asia Pacific region. Since our production environment is also located in Asia Pacific, we essentially have two Intune instances: one for development and one for production. We also have around 290,000 devices.

We have a team of five Intune administrators. The only maintenance required for Intune is the updates.

I recommend Microsoft Intune.

Based on the number of users and devices you're enrolling, I recommend having separate UAT and production Intune environments for larger deployments. For simpler environments, a single Intune license is sufficient to manage your devices and integrate with your Enterprise and Microsoft 365 solutions.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free Microsoft Intune Report and get advice and tips from experienced pros sharing their opinions.