Setting Up Microsoft Intune: A Step-by-Step Guide for SMBs
Learn how to configure Microsoft Intune for the first time with this comprehensive, step-by-step guide designed for small and medium-sized businesses. Secure and manage all your devices with ease.

This guide provides a comprehensive, step-by-step walkthrough for small and medium-sized businesses (SMBs) on how to configure Microsoft Intune for the first time. Intune, part of Microsoft Endpoint Manager, offers a unified platform for managing and securing your organization's devices and applications. By following these steps, you can establish a robust mobile device management (MDM) and mobile application management (MAM) solution, enhancing your cybersecurity posture and operational efficiency.
Key Takeaways
- Confirm licensing and admin roles before touching any Intune setting.
- Enrolment restrictions control which platforms and how many devices per user.
- Compliance policies judge device health; Conditional Access acts on the verdict.
- App protection secures company data on unenrolled personal devices.
- Autopilot gives new Windows devices a near zero-touch setup.
1. Prerequisites and Initial Setup
Before diving into Intune configuration, ensure you have the necessary prerequisites in place. This includes an active Microsoft 365 subscription that includes Intune (e.g., Microsoft 365 Business Premium, Enterprise Mobility + Security E3/E5).
If you're starting with a new tenant, make sure to activate Intune. For existing tenants, Intune is likely already active. Access the Microsoft Endpoint Manager admin centre by navigating to endpoint.microsoft.com.
Verify Licensing and Admin Roles
Ensure that your administrative account has the necessary Global Administrator or Intune Service Administrator roles assigned. Also, confirm that your users have appropriate Intune licences assigned to them. Without these licences, users will not be able to enrol their devices or access Intune-managed applications.
2. Configure Device Management Settings
The foundation of Intune lies in its device management capabilities. This involves setting up device enrolment restrictions and defining compliance policies.
A. Set Device Enrolment Restrictions
Device enrolment restrictions allow you to control which types of devices can enrol in Intune and how many devices a user can enrol. This is crucial for maintaining security and preventing unauthorized access.
- Navigate to Device Enrolment: In the Microsoft Endpoint Manager admin centre, go to
Devices > Enrol Devices > Enrolment restrictions. - Create New Restriction: Click
Create restrictionand choose betweenDevice type restrictionorDevice limit restriction. - Define Platforms: For device type restrictions, select the platforms you want to allow or block (e.g., iOS/iPadOS, Android, Windows, macOS). Configure operating system versions as needed.
- Assign to Groups: Assign these restrictions to specific user or device groups.
B. Create Device Compliance Policies
Compliance policies define the conditions a device must meet to be considered "compliant" with your organization's security standards. Non-compliant devices can be blocked from accessing corporate resources or flagged for remediation.
- Navigate to Compliance Policies: Go to
Devices > Compliance policies > Policies. - Create Policy: Click
Create Policyand select the platform (e.g., Windows 10 and later, Android Enterprise). - Configure Settings: Define settings such as requiring a password, encryption, minimum OS version, and Windows Defender settings.
- Actions for Non-compliance: Specify actions to take for non-compliant devices, such as sending email notifications or marking the device as non-compliant immediately.
- Assign Policy: Assign the policy to your user or device groups.
3. Set Up Application Management
Intune's application management (MAM) capabilities allow you to deploy, manage, and protect applications on both enrolled and unenrolled devices. This is particularly useful for bring-your-own-device (BYOD) scenarios.
A. Add and Deploy Applications
You can add various types of applications to Intune, including store apps, LOB (line-of-business) apps, and Microsoft 365 apps.
- Navigate to Apps: In the Microsoft Endpoint Manager admin centre, go to
Apps > All apps. - Add App: Click
Addand select the app type (e.g.,Microsoft 365 Apps for Windows 10 and later,Store app (for Android),iOS store app). - Configure App Details: Follow the wizard to configure app details, assignments, and installation settings.
- Assign to Groups: Assign the applications to user or device groups as
Required(automatic installation),Available for enrolled devices(user-initiated installation), orUninstall.
B. Implement App Protection Policies
App protection policies (APP) protect your organization's data within applications, even on devices not fully enrolled with Intune. This prevents data leakage and ensures corporate data remains secure.
- Navigate to App Protection Policies: Go to
Apps > App protection policies. - Create Policy: Click
Create policyand select the platform (e.g., iOS/iPadOS, Android). - Configure Data Protection Settings: Define settings like requiring a PIN for app access, blocking screenshots, preventing "save as" to personal locations, and encrypting corporate data.
- Conditional Access: Integrate with Conditional Access policies to further restrict access to applications based on device compliance and app protection status.
- Assign to Groups: Assign the policies to user groups that will be using the protected applications.

4. Onboard Windows Devices with Autopilot
Windows Autopilot streamlines the deployment of new Windows devices, providing a near-zero-touch experience for end-users. Devices can be shipped directly to users and automatically configured with the necessary policies, applications, and settings.
- Register Devices: Work with your hardware vendor to register new devices with Windows Autopilot. This involves providing device hardware hashes.
- Create Autopilot Deployment Profiles: In the Microsoft Endpoint Manager admin centre, go to
Devices > Windows > Windows Enrolment > Windows Autopilot Deployment Program > Deployment profiles. - Create Profile: Click
Create profile, selectWindows PC, and follow the wizard to configure OOBE (out-of-box experience) settings, user assignment, and more. - Assign Profle: Assign the Autopilot profile to your device groups.
- Status and Monitoring: Monitor the deployment status of your Autopilot devices under
Devices > Windows > Windows Enrolment > Windows Autopilot Deployment Program.
FAQ
Which licences include Intune?
Microsoft 365 Business Premium, E3, E5 and F3 include it, as do Enterprise Mobility + Security E3 and E5. It is also sold standalone. Users need a licence assigned individually before they can enrol a device.
Do users have to do anything to enrol?
On company Windows devices configured with Autopilot, no. The device configures itself when they sign in. Personal phones under app protection need the user to sign in to Outlook or Teams once, at which point the policy applies automatically.
Can Intune manage devices that are not domain joined?
Yes. Cloud-only devices joined to Microsoft Entra ID are the simplest case. Hybrid join exists for organizations still running on-premises Active Directory, at the cost of extra moving parts.
What is the difference between MDM and MAM?
MDM enrols and manages the whole device, which suits company hardware. MAM protects only the company applications and their data, which suits personal devices. Most SMBs use MDM on laptops and MAM on personal phones.
How long does an initial Intune setup take?
The configuration itself is a few days of work in a small tenant. The calendar is driven by enrolling existing devices, which means touching each machine, so plan a few weeks end to end for a fleet under 100 devices.
Configuring Microsoft Intune is a critical step towards modern device management and enhanced cybersecurity for SMBs. By following these steps and establishing robust device enrolment restrictions, compliance policies, application management, and Windows Autopilot, you can effectively secure and manage your organization's digital assets. Remember to regularly review and update your Intune policies to adapt to evolving security threats and business needs. Mirage Informatique is here to help you navigate the complexities of Intune and ensure your IT infrastructure is secure and efficient.
Related Articles

Essential Intune Configurations for Every SMB
Microsoft Intune offers a powerful suite of tools to manage and secure devices within your small or medium-sized business (SMB) efficiently.

What Microsoft Intune Does, and Whether You Need It
Intune manages devices and apps from the cloud. What it actually controls, what it does not, what it costs you already, and when a small business needs it.

Microsoft Viva in 2026: What Survived the Retirements
Viva Topics and Viva Goals are gone. Here is which Viva modules remain, what they cost, and which ones a small business should bother switching on.