lead

What Is Microsoft Intune? Mobile Device Management for Small Businesses

September 29, 2026

Your company data doesn’t stay in the office any more. It lives on laptops at kitchen tables, phones on trains and tablets left in cars. Mobile device management is how you keep control of it, and for most businesses on Microsoft 365, the tool that does the job is Microsoft Intune.

This guide explains what Intune is, what mobile device management actually does, and the settings worth switching on first.

What is Microsoft Intune?

Microsoft Intune is Microsoft’s cloud service for managing and securing the devices your team uses for work. It covers Windows laptops, Macs, iPhones, iPads and Android devices from one admin centre.

It’s part of the Microsoft 365 family and is included in Microsoft 365 Business Premium. If your business already has that licence, you may be paying for Intune without using it. It’s one of the things we look for when reviewing the Microsoft 365 licences businesses pay for but never use.

What mobile device management does

Mobile device management lets you set rules for company devices and check they’re being followed, without touching each device by hand. In practice, you can:

  • Require a PIN, password or fingerprint on every device.
  • Encrypt laptops, so a lost machine doesn’t mean lost data.
  • Push security updates and see which devices have fallen behind.
  • Install and remove work apps centrally.
  • Lock or wipe a device that’s lost, stolen or leaving with a member of staff.
  • Block devices that don’t meet your rules from reaching company email and files.

The last one matters most. Combined with conditional access in Microsoft 365, Intune can stop an out-of-date or unmanaged device from opening company data at all.

Company laptops and personal phones

Plenty of businesses let staff read work email on their own phones. That’s reasonable, but it’s also where control tends to slip.

Intune handles personal phones with app protection policies. Instead of managing the whole phone, it protects the work apps, such as Outlook, Teams and OneDrive. You can stop company data being copied into personal apps and remove it when someone leaves, without touching their photos or messages.

For company-owned laptops, full device management is the better fit. The business owns the hardware, so it should be able to control it.

Why it matters for security and Cyber Essentials

Much of the everyday risk in a small business sits on its devices: missed updates, weak sign-in, unencrypted drives and old accounts on old phones. Device management turns each of those from an assumption into a setting you can check.

It also helps with evidence. Cyber Essentials asks about secure configuration, security updates, malware protection and who has access to what. When your devices are managed, the settings and reports that answer those questions are in one place. Insurers ask similar questions at renewal, and so do larger customers in their supplier questionnaires.

What to set up first

  1. Enrol every company device. You’ll have an accurate list of what exists, and you can’t manage what you can’t see.
  2. Turn on encryption for Windows and Mac laptops, using BitLocker and FileVault.
  3. Set update rules so security updates install within a set window.
  4. Require a PIN or password, with the screen locking automatically.
  5. Add app protection for work data on personal phones.
  6. Link device compliance to conditional access, so a device that falls out of line loses access until it’s fixed.
  7. Agree a leaver process. Remove access and company data on the day someone leaves.

Roll changes out gradually, starting with a small group. A setting that surprises your whole team on a Monday morning creates support calls, not security.

New starters get working faster too

Device management isn’t only about restrictions. With Windows Autopilot and Intune, a new laptop can go straight to a new starter. When they first sign in, it sets itself up with the right apps and settings.

That makes every new starter’s setup the same, and the leaver process becomes the same steps in reverse.

Do you need Intune?

If your team uses laptops and phones for work, and especially if those devices ever leave the office, some form of mobile device management is worth having. For businesses already on Microsoft 365 Business Premium, Intune is usually the natural choice, because it’s already licensed and works with the rest of Microsoft 365.

If you’re on a different Microsoft 365 plan, Intune can be added. The right licence depends on what else you need, so it’s worth checking before you buy anything new.

Frequently asked questions

What is Intune used for?

Intune is used to manage and secure the laptops, phones and tablets your team uses for work. It enforces settings such as encryption and passcodes, keeps devices updated, installs apps and can remove company data from a lost device.

Is Intune included in Microsoft 365?

Intune is included in Microsoft 365 Business Premium and some enterprise plans. Business Basic and Business Standard don’t include it, although it can be licensed separately.

Can Intune wipe a personal phone?

With app protection policies, Intune removes only the company data held in work apps and leaves personal data alone. A full wipe is normally kept for company-owned devices.

Does Intune work with Macs and iPhones?

Yes. Intune manages Windows, macOS, iOS, iPadOS and Android devices from the same admin centre.

Not sure how your devices are managed today?

Microsoft 365 and endpoint security are part of the managed IT services we provide to businesses across Surrey, Hampshire and Berkshire. We’ll look at how your devices, sign-in and backups are set up and explain what’s worth changing first.

Talk to us about your IT, or start with our Microsoft 365 security checklist.

Talk to us about your IT

If this raises questions about your own systems or security, we'll talk them through with you.