What Is Microsoft Intune – and Why Does your SMB Need It?
Intune is included in your Microsoft 365 license. But having access to a tool and having it properly configured are two very different things.
Intune is included in your Microsoft 365 license. But having access to a tool and having it properly configured are two very different things.
THE REALITY
If your business runs on Microsoft 365 Business Premium, Microsoft Intune is included. That part is true — and we’re not going to pretend otherwise. But here’s what most small businesses find out the hard way: having a tool in your subscription and having that tool configured, deployed, and actively managed are completely different things.
By default, Intune in a new M365 tenant does very little. There are no device policies. No conditional access rules. No enrollment requirements. Nothing is protected until someone sets it up correctly — and for most SMBs, that setup never happens. The licenses sit there, the capability goes unused, and your devices operate with zero centralized oversight.
That’s the gap SBT fills. Intune management isn’t a fee for something you didn’t already have — it’s the work of making sure what you have actually works: proper configuration, active monitoring, policy enforcement, and someone who owns it on your behalf every single day.
"A misconfigured Intune tenant is almost as risky as no configuration at all. Default settings aren't enough, and without proper deployment, your team will work around the tools regardless of what you've paid for."
WHAT IS IT?
Microsoft Intune is a cloud-based endpoint management platform. In practice, it’s the tool that lets your IT team see, manage, and secure every device that touches your company data — Windows laptops, Macs, iPhones, Androids, tablets — from a single dashboard. Company-owned or personal. In the office or remote.
It operates in two main modes depending on who owns the device:
Full management of the device: push software, enforce encryption, configure settings, require PINs, and remotely wipe the entire device if it's lost or stolen. Best for laptops and phones your company issues.
Protects company data inside specific apps without managing the whole phone. An employee's personal photos, texts, and apps are completely off-limits. Only the work data is containerized and controlled. A lost personal phone with MAM in place means a wipe of company data only — nothing personal is touched.
Intune integrates with Microsoft Entra ID to block non-compliant devices from accessing company email or SharePoint automatically — no IT intervention required. Wrong OS version, no PIN, not enrolled? Access denied, no exceptions.
The setup problem is real. Intune has hundreds of configuration options, policy settings, and security baselines. We've onboarded clients who had M365 Business Premium for years with Intune enabled in name only — no enrollment, no policies, no protection. The capability existed. The protection didn't.
WHY IT MATTERS
Unmanaged devices are consistently one of the top entry points for SMB breaches. Here’s what the data actually looks like:
Forrester’s 2024 Total Economic Impact study on Intune found that organizations with a properly deployed, actively managed Intune environment saw 80% faster new-device onboarding, a 25% drop in help desk tickets related to endpoint issues, and a meaningful reduction in breach risk from lost or stolen devices. Those aren’t theoretical gains — they’re the direct result of configuration and management done right.
THE BYOD PROBLEM
The scenario is more common than most SMB owners realize: a 20-person company with no formal BYOD policy. Employees check work email on personal iPhones. A few people remote into SharePoint from home laptops that haven’t been patched in six months. Someone’s Android phone — with access to company files — gets left in a rideshare.
Without Intune properly configured, there is nothing your IT team can do. No remote wipe. No way to verify that device was encrypted. No audit trail. The data is effectively gone — or in the wrong hands.
With Intune MAM policies deployed and monitored correctly, that scenario ends differently. Work data is containerized inside managed apps. If the device goes missing, you wipe the company container only. The employee’s personal content is untouched.
The key word is "deployed correctly." MAM policies don't enforce themselves. Someone has to build the policy, enroll the apps, test the configuration, and monitor compliance on an ongoing basis. That's the managed service — not the Intune license itself.
THE FULL PICTURE
Here’s what a fully deployed and managed Intune environment gives you — compared to what you’d be looking at building the same protection from separate tools:
| Capability | Standalone Alternative | With Managed Intune |
|---|---|---|
| Mobile Device Management | $8–$12/device/mo (separate MDM tool) | ✓ Included & Configured |
| App protection for BYOD (MAM) | Requires additional MDM licensing | ✓ Deployed with policies |
| Conditional access enforcement | Requires Azure AD P1 (~$6/user/mo) | ✓ Actively enforced |
| Remote wipe (selective or full) | Standalone MDM platform needed | ✓ Ready to execute |
| Autopilot device provisioning | Enterprise-tier; complex setup | ✓ Configured for your workflow |
| Compliance monitoring & reporting | Manual or separate tool | ✓ Ongoing via Datto RMM + Intune |
| Security baseline hardening | Manual configuration required | ✓ Applied and maintained |
The managed service cost covers the expertise, time, and accountability behind every one of those rows — not the license itself. If you have Business Premium and think Intune is already protecting you because it shows up in your portal, this is the conversation worth having with your IT partner.
HOW WE DO IT
When SBT manages Intune as part of your Total IT partnership, here’s what that work entails — from day one through ongoing operations:
We start by reviewing your M365 tenant configuration from scratch. Intune policies are built from the ground up against Microsoft's security baselines — not left on defaults. Everything is hardened before a single device enrolls.
Company-owned devices go into full MDM. Personal devices get MAM-only enrollment — no employee has to hand over their personal phone. We configure the right policy for each device type and ownership model your team actually uses.
We configure Entra ID conditional access rules that match how your business operates — blocking non-compliant devices from email and SharePoint, enforcing MFA, and applying access rules by role or location where relevant.
New Windows devices can ship directly to employees and self-configure through Autopilot — arriving pre-loaded with required apps, policies, and security settings. No IT time at the desk required.
Once deployed, we monitor device compliance through Datto RMM and the Intune console. Devices that fall out of policy get flagged and remediated. Updates get pushed. You get reporting your leadership can actually act on.
Most businesses with Business Premium have never had Intune properly configured. We'll take a look — at no cost — and tell you exactly where you stand.
Claim Your Free IT Health Check →










This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.
AcceptLearn moreWe may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.
Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.
These cookies are strictly necessary to provide you with services available through our website and to use some of its features.
Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.
We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.
We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.
We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.
Google Webfont Settings:
Google Map Settings:
Google reCaptcha Settings:
Vimeo and Youtube video embeds:
