Back to BlogMicrosoft 365 Tips

Microsoft Intune Setup Guide for Beginners: Step-by-Step for UK IT Teams 2026

13 September 2026 6 min read
Photo by Marek Levák on Unsplash

What is Microsoft Intune and why UK organisations need it now

Microsoft Intune is Microsoft's cloud-based device and application management service. It lets you control who accesses company data, manage devices (laptops, phones, tablets), enforce security policies, and deploy software all from a single dashboard. For UK organisations especially, where remote and hybrid work is now the norm, Intune has become non-negotiable.

The reason beginners struggle with Intune isn't that it's complicated. It's that most people jump straight into the Microsoft Intune admin centre without understanding the foundational concepts: tenant configuration, Azure AD sync, device enrolment methods, and conditional access policies. Get those wrong, and you'll spend weeks unpicking your own setup.

This guide walks you through the order things should actually happen in, not the order the interface presents them.

Step 1: Verify your Microsoft 365 tenant and licensing

Before you touch Intune, confirm:

  • You have an active Microsoft 365 for Business, Enterprise, or Education subscription (E3, E5, or equivalent)
  • Your Azure AD tenant is set up and synced with on-premises Active Directory if you have one
  • Intune is included in your licence (it's bundled into nearly all Microsoft 365 enterprise plans)
  • You have Global Administrator or Intune Administrator role assigned in Azure AD
  • To check this, sign in to the Azure portal (portal.azure.com) and navigate to Azure Active Directory. Look for your tenant details. If you're working in a larger organisation, your IT team should have already done this. If you're setting up Intune for the first time at your organisation, this step is critical. Skipping it means you'll hit permission errors later.

    Step 2: Access the Microsoft Intune admin centre

    Go to intune.microsoft.com and sign in with your Global Administrator or Intune Administrator account.

    The dashboard you land on is your command centre. The left sidebar contains everything you'll use:

  • Dashboard: Overview of device health, compliance, and alerts
  • Devices: Where you enrol and manage devices
  • Apps: Deploy applications to users and groups
  • Security: Configure conditional access and device compliance policies
  • Reports: Monitor adoption and device health
  • Spend five minutes just clicking around and reading labels. The interface won't change if you look. Familiarity with the layout will save you hours later.

    Step 3: Configure your enrolment settings (the most critical step)

    Enrolment is how devices join Intune's management. You need to decide which devices can enrol and under what conditions.

    Go to Devices > Enrolment and onboarding > Enrolment restrictions.

    Here, you'll see two types of restrictions:

    1. Device type restrictions (can iOS devices enrol? Can Android?)

    2. Device limit restrictions (how many devices can one user enrol?)

    For a UK business starting out, a sensible starting point is:

  • Allow Windows 10/11, macOS, iOS, and Android
  • Set device limit to 5 per user (most people have a work device, personal phone, tablet, plus one spare)
  • Mark "Personally owned" devices as allowed (BYOD, if your organisation supports it)
  • If you're in the NHS or a healthcare setting where BYOD isn't appropriate, disable personally owned devices entirely.

    Next, enable automatic enrolment for Windows devices (if you have Windows devices and Azure AD join):

    Go to Devices > Enrolment and onboarding > Automatic enrolment.

  • Set "MDM user scope" to "Some" or "All" (depending on your rollout plan)
  • If you choose "Some", create an Azure AD security group containing the users you want to enrol first (usually IT staff and a pilot group)
  • This is where most UK organisations stumble. They enable automatic enrolment for everyone at once, then panic when 500 devices suddenly enrol and fail because they haven't set up policies yet. Use a phased approach.

    Step 4: Create device compliance policies

    A compliance policy tells Intune what a device must do to stay "compliant". Non-compliant devices can be blocked from email or sensitive apps.

    Go to Devices > Compliance policies > Create policy.

    For Windows 10/11 devices, start with:

  • Require password (minimum 6 characters)
  • Require encryption (BitLocker enabled)
  • Block jailbroken or rooted devices
  • Require antivirus software (Windows Defender sufficient for most)
  • Set "Require app to be installed on managed devices" for Microsoft Authenticator
  • For iOS and Android:

  • Require password (minimum 6 characters, biometric optional)
  • Block jailbroken/rooted devices
  • Require OS updates within 30 days
  • Assign these policies to Azure AD groups (e.g., "All Users" or "Pilot Group" depending on your rollout phase). Don't assign to individual users. Groups scale.

    Step 5: Set up conditional access (optional for beginners but important)

    Conditional access enforces security rules based on conditions. For example: "If a user logs in from outside the UK, require multi-factor authentication."

    This lives in Azure AD > Conditional Access > New policy (not in Intune itself).

    For a beginner UK team, start with one policy:

  • Condition: "All users" or a specific group
  • Target: Microsoft 365 cloud apps
  • Requirement: Require multi-factor authentication
  • Action: Grant access (if MFA is completed)
  • This single policy closes most security gaps. Once you're comfortable, add more (device compliance checks, location-based rules, etc.).

    Step 6: Enrol your first device and test

    This is not optional. Many setups look correct in theory but fail in practice.

    Take a Windows device and enrol it manually:

    1. Go to Settings > Accounts > Access work or school > Connect

    2. Sign in with your corporate account

    3. Watch it enrol in Intune

    Go back to the admin centre and verify the device appears in Devices > All devices within 5 to 10 minutes.

    If it doesn't appear, check:

  • Azure AD join is enabled (not just domain join)
  • The user account has a valid Intune licence
  • The device meets your enrolment restrictions
  • Fix these before rolling out to staff.

    Real-world tip: Start small, expand systematically

    Many UK organisations try to "perfect" their Intune setup before enrolling anyone. This is backwards. Enrol 20 pilot users first. Let them live with the policies for two weeks. Gather feedback. Adjust policies. Then roll out to everyone.

    If you need structured, hands-on training in Intune setup from a trainer who's actually done this in the NHS, SmoothOps 365 runs a Microsoft 365 Administrator Programme (currently on the waitlist at smoothops365.com/courses, joining soon). It covers Intune, Azure AD, device management, and real troubleshooting. Grab a spot on the waitlist now if you're serious about this.

    Key takeaways

  • Intune sits inside Microsoft 365 but lives in the Azure ecosystem. Know your Azure AD structure first.
  • Enrolment, compliance policies, and conditional access are the three pillars. Do them in that order.
  • Test with a small pilot group before rolling out organisation-wide.
  • Device groups matter more than user settings. Build your Azure AD groups correctly early.
  • Frequently asked questions

    How long does a device take to enrol in Intune after I click connect?

    Most devices enrol within 5 to 10 minutes. Windows devices with automatic enrolment can take longer (up to 30 minutes) because Intune waits for the device to perform initial sync. If a device hasn't appeared after 30 minutes, check the device's event logs or sign out and in again.

    Can I enrol a device that's already joined to our on-premises domain?

    Yes, but the device must also be Azure AD joined or registered in Azure AD. Hybrid Azure AD join is the typical setup in UK organisations. Your device can be on-premises domain joined and Azure AD joined at the same time. Intune management works alongside traditional domain group policy.

    What happens to a device if it becomes non-compliant?

    By default, the device receives a notification but remains functional. You can configure policies to block email access or restrict access to sensitive apps. You cannot remotely wipe a device just because it's non-compliant unless you explicitly set that action in the policy.

    Do I need conditional access if I'm already using Intune compliance policies?

    Compliance policies manage the device itself. Conditional access manages the user's ability to access apps and data based on conditions (location, device state, sign-in risk). Use both. They work together, not as alternatives.

    Can I manage macOS and iOS devices with the same policies as Windows?

    No. Each platform has its own policy templates because their security models are different. You'll create separate policies for Windows, macOS, iOS, and Android. The principles are the same, but the configuration options differ.

    Ready to start your IT career?

    SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.