1.Check your Microsoft 365 subscription
Before setting up Intune, ensure that your Office 365 subscription includes Intune. Intune is available in the following subscriptions:
- Microsoft 365 Business Premium
- Microsoft 365 Enterprise E3 and E5
- Enterprise Mobility + Security (EMS) E3 and E5
- Microsoft Intune standalone subscription
You can check and add Intune licenses through the Microsoft 365 Admin Center.
2. Assign Intune licenses to users
Each user needs a Microsoft Intune license. You can assign them via the Microsoft 365 Admin Center:
- Go to the Microsoft 365 Admin Center at https://admin.microsoft.com.
- On the left sidebar, click Users > Active Users.
- Select a user, then click Licenses and Apps.
- Under Licenses, toggle the switch for Microsoft Intune and click Save changes.
Repeat this process for every user that you want to manage with Intune.
3. Sign into Microsoft Endpoint Manager admin center
The Endpoint Manager admin center is where you manage Intune:
- Go to the Microsoft Endpoint Manager Admin Center at https://endpoint.microsoft.com.
- Sign in using your admin credentials.
4. Set up MDM (Mobile Device Management) Authority
To manage mobile devices via Intune, you need to configure your MDM authority. For most organizations, Intune is used as the MDM authority.
- In the Endpoint Manager admin center, click Devices > Enroll devices.
- Under MDM authority, select Microsoft Intune.
If you’re using a combination of Intune and other MDM solutions, you might configure a co-management option.
5. Configure device enrollment options
Next, configure how devices will be enrolled in Intune:
- In the Endpoint Manager admin center, go to Devices > Enroll devices.
- Under Windows Enrollment, configure Automatic Enrollment for Windows 10/11 devices.
- You can also configure other enrollment types like Apple Enrollment for iOS/macOS and Android Enrollment.
6. Create and assign policies
After configuring enrollment, you’ll want to create policies to manage devices and ensure security.
- Compliance policies: Set up rules to ensure devices comply with your organization’s standards. For example, you can ensure devices have a passcode or that they are encrypted.
- In the Endpoint Manager admin center, go to Devices > Compliance policies and click Create policy.
- Choose the platform (e.g., Windows, iOS) and configure your compliance settings.
- Configuration profiles: These profiles allow you to manage settings like Wi-Fi, VPN, and email configurations.
- Go to Devices > Configuration profiles and click Create profile.
- Select the platform and the type of profile, then configure the necessary settings.
- App protection policies: These protect company data within apps. You can control how users access and share information.
- Go to Apps > App protection policies and create policies for different platforms.
7. Enroll devices into Intune
Users can enroll their devices manually or automatically, depending on your configuration.
- Windows devices:
- On a Windows 10/11 device, go to Settings > Accounts > Access work or school.
- Click Connect and follow the prompts to sign in with your Office 365 account. This enrolls the device into Intune.
- iOS/Android devices:
- Install the Company Portal app from the App Store or Google Play Store.
- Sign in using your Office 365 account and follow the instructions to enroll the device.
8. Monitor and manage devices
Once devices are enrolled, you can monitor and manage them from the Endpoint Manager admin center:
- Go to Devices to view enrolled devices, check compliance status, and take actions like wiping data or resetting passwords.