Module 10 and the capstone of StartCloud's Microsoft 365 Security Essentials learning pathway, in five short units with a knowledge check: why an unmanaged laptop undermines every other control, the four jobs Intune does (enrolment, compliance policies, updates and settings, remote wipe), exactly what an employer can and cannot see on an enrolled device, app protection policies as the lighter option for personal phones, and a four-step rollout that avoids a staff revolt.
Managing Company Devices with Intune
The last gap in the pathway
Have a look at what you have built across this pathway. Sign-in needs a second factor. Admin accounts are separated and protected. Mail is filtered and your domain cannot be spoofed. Sharing is controlled, access is shaped by risk, sensitive data carries its own protection, and there is a real backup behind all of it.
Now picture the laptop it all runs on. Six months behind on updates, no disk encryption, a local account with no passcode, and a browser signed into everything. Every control you have built assumes the device is trustworthy, and until now nothing in the pathway has actually checked.
You cannot tell whether it is encrypted, patched or even still in the building. If it goes missing you have no way to wipe it, and nobody knows what was on the desktop. When someone leaves, you are relying on them to hand it back and on nothing having been copied off it.
Encrypted, patched, and required to prove it before it gets near company data. Lost on the train, and you wipe it from your phone before dinner. The laptop stops being the weak link and starts being another control, which is exactly what Conditional Access back in Module 6 was waiting for.
Module 6 let you say "only allow access from a compliant device." That sentence is doing nothing at all until something is deciding what compliant means and checking it. Intune is that something, and switching it on quietly upgrades several earlier modules at once.
Intune is Microsoft's device management service, and it is included in Microsoft 365 Business Premium and most enterprise plans, which means a lot of businesses are already paying for it and not using it. It does four jobs worth understanding.
Enrolment: the device introduces itself
A device gets registered to your organisation, and from then on it has an identity you can check policy against. New machines can enrol themselves the first time they are switched on, so a laptop can be posted straight to a new starter and arrive set up. Windows, macOS, iOS, iPadOS, Android and Linux are all supported.
- New devices configure themselves out of the box
- No more building each laptop by hand
- Devices already managed by another MDM may need a factory reset first
Compliance policies: the device proves it is healthy
You define what healthy means. Disk encryption on, screen lock set, operating system above a minimum version, no jailbreak. Devices report their state, and anything that drifts out of line gets flagged. Pair it with Conditional Access and a non-compliant device simply cannot reach company data until it is fixed.
- Encryption, passcode and OS version enforced, not hoped for
- Drift shows up in a report instead of a breach
- Access is blocked automatically, without anyone chasing
Updates and settings, without the nagging
Patching is the least glamorous control in security and one of the most effective, and it is exactly the sort of thing that never happens if it relies on people clicking a reminder. Intune schedules updates, sets a deadline, and reports on what is actually installed rather than what was requested.
- Update deadlines that apply whether or not anyone clicks
- Wi-Fi, VPN and printer settings pushed once, centrally
- Apps installed and updated without touching each machine
Remote wipe: the lost laptop becomes a shrug
A managed, encrypted device left in a taxi is an inconvenience and a hardware cost. The same device unmanaged is a data breach you may have to report. This one capability changes the entire character of the phone call that starts with "I think I have left my laptop somewhere."
- Wipe company data, or the whole device, from anywhere
- Retire a device cleanly when someone leaves
- Encryption means the data is unreadable even before the wipe lands
This module is about the decisions. If you want the deeper walkthrough of how Intune is set up and what the licensing looks like, we have written that up separately.
Read the Microsoft Intune deep diveHere is where rollouts usually go wrong, and it is never a technical problem. Somebody hears "the company is putting management software on my phone" and reasonably concludes that the boss will be reading their texts. Nobody says it out loud, they just quietly refuse to enrol, and the project stalls.
The cure is straightforward: tell people exactly what you can and cannot see, before you ask them for anything. Microsoft publishes the list, so you are not asking anyone to take your word for it.
- Calling and web browsing history
- Email and text messages
- Contacts
- Calendar
- Passwords
- Photos, including the camera roll
- The contents of documents you created
- Device owner
- Device name
- Serial number
- Model, such as Google Pixel
- Manufacturer
- Operating system and version
- Device IMEI
It is an inventory list, not a surveillance list. Worth reading out at the team meeting, word for word, and then pointing people at Microsoft's own page so they can check you.
App protection policies protect the company data inside apps like Outlook and Teams without managing the device at all. The phone is never enrolled. You are not managing their phone, you are managing your data that happens to be sitting on it. When they leave, you remove the company data and their photos, messages and personal apps are never touched. For staff who use their own phone for work mail, this is usually the right answer and the easiest one to agree to.
Company-owned laptops and phones get fully enrolled and managed, because you own them and you are responsible for what is on them. Personal devices get app protection policies instead. Two approaches, two different sets of expectations, and nobody feels their private phone has been quietly annexed.
Device management has a reputation problem, and it was earned honestly. Plenty of people have experienced a heavy-handed rollout that broke printing, locked them out mid-deadline, or arrived with no warning at all.
None of that is inherent to the tooling. It comes from switching things on for everyone at once and finding out what breaks in production. Four steps avoid essentially all of it.
- 1
Tell people before anything appears on their screen
An unexplained prompt demanding they enrol their phone is how you generate a week of suspicious hallway conversations. A short, plain email a few days ahead covering what is changing, why, what you can see and what you cannot, costs you ten minutes and saves the whole rollout.
- 2
Start with IT and one friendly team
Enrol yourselves first, then a small group who will tell you honestly when something is annoying. You will find the surprises here, and finding them with five people is infinitely better than finding them with fifty.
- 3
Report first, enforce second
Run compliance policies in report-only mode to begin with. You get a clear picture of how many devices are unencrypted or behind on updates without locking anyone out on a Tuesday morning. Fix what the report shows, then turn on enforcement.
- 4
New devices first, existing devices gradually
Every new laptop from today gets enrolled during setup, which costs nothing extra because you are configuring it anyway. Existing machines get brought in at a natural moment: a rebuild, an upgrade, a quiet week. The fleet converts itself over a few months without a single disruptive weekend.
Not "we need to manage your device." Try "if you lose this laptop, we can wipe it in two minutes and you will not have to tell forty clients that their information is on a train." People are entirely reasonable about security when the benefit is theirs too, and the lost-laptop story is one everyone can picture.
And that is the pathway. Ten modules ago this was a business with passwords and hope. You now have a second factor on sign-in, protected admin accounts, filtered mail, a domain that cannot be spoofed, controlled sharing, access shaped by risk, data that carries its own protection, a real backup, a clean starter and leaver process, and devices that prove they are healthy before they get near any of it.
That is a genuinely well-secured small business. Not a theoretical one, and not an expensive one. Mostly it is a series of sensible decisions made once and then left switched on. Nice work getting to the end of it.
- learn.microsoft.com: What information can my organization see when I enroll my device?
- learn.microsoft.com: Managing and securing your devices in Microsoft Intune
- learn.microsoft.com: App protection policies overview
- learn.microsoft.com: Privacy and personal data in Intune
Details were current at the time of writing (August 2026). Microsoft updates Intune regularly, so check the links above for the current capability and platform support.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. You already have Conditional Access set up. Why does device management still matter?
2. A staff member worries that enrolling their phone lets you read their text messages. What is the honest answer?
3. Someone uses their own personal phone for work email. What is usually the right approach?
4. What is the safest way to introduce compliance policies to an existing fleet?
5. What is the strongest way to explain device management to staff?