Microsoft Intune and Endpoint Management
Microsoft Intune helps organisations manage and secure company devices while protecting business data on personal devices.
There are two main challenges to consider.
The first is making sure company-owned devices meet your organisation’s security standards. For example, you may require devices to use encryption, have a secure PIN or password, and run an approved operating system.
The second challenge is protecting company data when employees use their own devices. Bring Your Own Device (BYOD) can provide greater flexibility, but businesses naturally have less control over personal devices.
Microsoft Intune provides different policies for addressing both scenarios.
Compliance Policies for Company-Owned Mobile Devices
For company-owned iOS, iPadOS and Android devices, we recommend using device compliance policies.
Compliance policies define the minimum security standards a device must meet before it is considered compliant.
For example, your organisation might require mobile devices to:
- use an appropriate PIN or password;
- have device encryption enabled;
- run a supported operating system; and
- not be jailbroken or rooted.
Devices enrolled in Microsoft Intune can then be assessed against these requirements.
This provides a clear view of which devices meet your security standards and which require attention.
Compliance policies can also be combined with Conditional Access so that devices which fail to meet the required standard can have their access restricted.
Device Configuration Policies
Compliance policies assess whether a device meets your requirements. Configuration policies can actively apply settings to managed devices.
For example, a configuration policy could automatically require a device to lock after a defined period of inactivity.
This allows organisations to apply security settings consistently rather than relying on individual users to configure their devices correctly.
The exact configuration will depend on your organisation’s security requirements, but Microsoft Intune provides a wide range of settings for managing mobile devices.
Protecting Company Data on Personal Devices
Personal devices present a different challenge.
Employees may need to access Outlook, Teams, Word, OneDrive and other Microsoft 365 services from their own mobile devices. However, the business may not want or need full control of the device.
This is where Microsoft Intune app protection policies can be useful.
App protection policies allow organisations to protect business information at application level without necessarily enrolling and managing the entire device.
For example, an organisation can restrict users from copying information from a managed Outlook or OneDrive account into a personal application.
It can also control where company documents can be saved.
This means the organisation retains control over its business data without taking unnecessary control of an employee’s personal device.
Controlling Data Between Applications
Intune app protection policies provide several options for controlling how company data is used.
For example, policies can restrict users from:
- saving business documents to personal storage locations;
- copying and pasting company information into unmanaged applications;
- backing up managed application data to personal cloud services; and
- transferring business data into applications that are not approved for company use.
These controls help reduce the risk of sensitive information being moved outside the organisation’s managed environment.
Protecting Access to Mobile Applications
Additional access requirements can also be applied to managed applications.
For example, an organisation can require users to enter a PIN or use biometric authentication before opening a managed application such as Outlook.
This can provide another layer of protection if the device itself is lost or stolen.
With BYOD, the important distinction is that the business controls the company information and managed applications rather than unnecessarily controlling the employee’s entire personal device.
Managing Windows Devices with Microsoft Intune
Microsoft Intune can also be used to manage and secure Windows devices.
As with mobile devices, we recommend establishing a clear compliance standard.
A Windows compliance policy might require devices to:
- run an approved version of Windows;
- meet defined operating system and security update requirements;
- use encryption;
- have appropriate antivirus and security protection enabled; and
- meet your organisation’s password and security requirements.
Intune can continually assess managed devices against these standards.
When combined with Conditional Access, organisations can also restrict access to company resources when a Windows device does not meet the required compliance level.
Managing BitLocker with Microsoft Intune
Microsoft Intune can do more than simply check whether a Windows device is encrypted.
Endpoint security policies can be used to configure and enforce BitLocker disk encryption across managed Windows devices.
This allows the organisation to define its required encryption settings centrally and apply them consistently.
The advantage of cloud-based device management is that policies can continue to apply even when devices are away from the traditional office network.
This is increasingly important for organisations with remote and hybrid workers.
Managing OneDrive on Windows Devices
Microsoft Intune can also be used to configure OneDrive settings across company devices.
For example, organisations may choose to prevent employees from syncing personal OneDrive accounts or content belonging to other organisations.
Policies can also be used to configure Known Folder Move.
This allows key Windows folders such as Desktop, Documents and Pictures to be redirected to the organisation’s OneDrive environment.
Doing this can help ensure important business files are stored within the company’s managed Microsoft 365 environment rather than only on an individual device.
Creating a Consistent Endpoint Security Standard
The objective of Microsoft Intune is not simply to apply more restrictions.
It is about creating a consistent security standard across the devices and applications that access your organisation’s information.
For company-owned devices, Intune provides the ability to assess compliance and enforce configuration settings.
For personal devices, app protection policies provide a way to protect company information while respecting the employee’s ownership of the device.
Combined with Conditional Access, these policies provide organisations with much greater control over how users, applications and devices access company data.