Microsoft Intune is Microsoft's cloud-based device and application management service. It lets you control who accesses company data, manage devices (laptops, phones, tablets), enforce security policies, and deploy software all from a single dashboard. For UK organisations especially, where remote and hybrid work is now the norm, Intune has become non-negotiable.
The reason beginners struggle with Intune isn't that it's complicated. It's that most people jump straight into the Microsoft Intune admin centre without understanding the foundational concepts: tenant configuration, Azure AD sync, device enrolment methods, and conditional access policies. Get those wrong, and you'll spend weeks unpicking your own setup.
This guide walks you through the order things should actually happen in, not the order the interface presents them.
Before you touch Intune, confirm:
To check this, sign in to the Azure portal (portal.azure.com) and navigate to Azure Active Directory. Look for your tenant details. If you're working in a larger organisation, your IT team should have already done this. If you're setting up Intune for the first time at your organisation, this step is critical. Skipping it means you'll hit permission errors later.
Go to intune.microsoft.com and sign in with your Global Administrator or Intune Administrator account.
The dashboard you land on is your command centre. The left sidebar contains everything you'll use:
Spend five minutes just clicking around and reading labels. The interface won't change if you look. Familiarity with the layout will save you hours later.
Enrolment is how devices join Intune's management. You need to decide which devices can enrol and under what conditions.
Go to Devices > Enrolment and onboarding > Enrolment restrictions.
Here, you'll see two types of restrictions:
1. Device type restrictions (can iOS devices enrol? Can Android?)
2. Device limit restrictions (how many devices can one user enrol?)
For a UK business starting out, a sensible starting point is:
If you're in the NHS or a healthcare setting where BYOD isn't appropriate, disable personally owned devices entirely.
Next, enable automatic enrolment for Windows devices (if you have Windows devices and Azure AD join):
Go to Devices > Enrolment and onboarding > Automatic enrolment.
This is where most UK organisations stumble. They enable automatic enrolment for everyone at once, then panic when 500 devices suddenly enrol and fail because they haven't set up policies yet. Use a phased approach.
A compliance policy tells Intune what a device must do to stay "compliant". Non-compliant devices can be blocked from email or sensitive apps.
Go to Devices > Compliance policies > Create policy.
For Windows 10/11 devices, start with:
For iOS and Android:
Assign these policies to Azure AD groups (e.g., "All Users" or "Pilot Group" depending on your rollout phase). Don't assign to individual users. Groups scale.
Conditional access enforces security rules based on conditions. For example: "If a user logs in from outside the UK, require multi-factor authentication."
This lives in Azure AD > Conditional Access > New policy (not in Intune itself).
For a beginner UK team, start with one policy:
This single policy closes most security gaps. Once you're comfortable, add more (device compliance checks, location-based rules, etc.).
This is not optional. Many setups look correct in theory but fail in practice.
Take a Windows device and enrol it manually:
1. Go to Settings > Accounts > Access work or school > Connect
2. Sign in with your corporate account
3. Watch it enrol in Intune
Go back to the admin centre and verify the device appears in Devices > All devices within 5 to 10 minutes.
If it doesn't appear, check:
Fix these before rolling out to staff.
Many UK organisations try to "perfect" their Intune setup before enrolling anyone. This is backwards. Enrol 20 pilot users first. Let them live with the policies for two weeks. Gather feedback. Adjust policies. Then roll out to everyone.
If you need structured, hands-on training in Intune setup from a trainer who's actually done this in the NHS, SmoothOps 365 runs a Microsoft 365 Administrator Programme (currently on the waitlist at smoothops365.com/courses, joining soon). It covers Intune, Azure AD, device management, and real troubleshooting. Grab a spot on the waitlist now if you're serious about this.
Most devices enrol within 5 to 10 minutes. Windows devices with automatic enrolment can take longer (up to 30 minutes) because Intune waits for the device to perform initial sync. If a device hasn't appeared after 30 minutes, check the device's event logs or sign out and in again.
Yes, but the device must also be Azure AD joined or registered in Azure AD. Hybrid Azure AD join is the typical setup in UK organisations. Your device can be on-premises domain joined and Azure AD joined at the same time. Intune management works alongside traditional domain group policy.
By default, the device receives a notification but remains functional. You can configure policies to block email access or restrict access to sensitive apps. You cannot remotely wipe a device just because it's non-compliant unless you explicitly set that action in the policy.
Compliance policies manage the device itself. Conditional access manages the user's ability to access apps and data based on conditions (location, device state, sign-in risk). Use both. They work together, not as alternatives.
No. Each platform has its own policy templates because their security models are different. You'll create separate policies for Windows, macOS, iOS, and Android. The principles are the same, but the configuration options differ.
SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.