← Back to Blog
    TutorialMicrosoft 365April 8, 20265 min readBy Mirage Informatique

    Setting Up Microsoft Intune: A Step-by-Step Guide for SMBs

    Learn how to configure Microsoft Intune for the first time with this comprehensive, step-by-step guide designed for small and medium-sized businesses. Secure and manage all your devices with ease.

    Share
    Setting Up Microsoft Intune: A Step-by-Step Guide for SMBs

    This guide provides a comprehensive, step-by-step walkthrough for small and medium-sized businesses (SMBs) on how to configure Microsoft Intune for the first time. Intune, part of Microsoft Endpoint Manager, offers a unified platform for managing and securing your organization's devices and applications. By following these steps, you can establish a robust mobile device management (MDM) and mobile application management (MAM) solution, enhancing your cybersecurity posture and operational efficiency.

    1. Prerequisites and Initial Setup

    Before diving into Intune configuration, ensure you have the necessary prerequisites in place. This includes an active Microsoft 365 subscription that includes Intune (e.g., Microsoft 365 Business Premium, Enterprise Mobility + Security E3/E5).

    If you're starting with a new tenant, make sure to activate Intune. For existing tenants, Intune is likely already active. Access the Microsoft Endpoint Manager admin centre by navigating to endpoint.microsoft.com.

    Verify Licensing and Admin Roles

    Ensure that your administrative account has the necessary Global Administrator or Intune Service Administrator roles assigned. Also, confirm that your users have appropriate Intune licences assigned to them. Without these licences, users will not be able to enrol their devices or access Intune-managed applications.

    2. Configure Device Management Settings

    The foundation of Intune lies in its device management capabilities. This involves setting up device enrolment restrictions and defining compliance policies.

    A. Set Device Enrolment Restrictions

    Device enrolment restrictions allow you to control which types of devices can enrol in Intune and how many devices a user can enrol. This is crucial for maintaining security and preventing unauthorized access.

    1. Navigate to Device Enrolment: In the Microsoft Endpoint Manager admin centre, go to Devices > Enrol Devices > Enrolment restrictions.
    2. Create New Restriction: Click Create restriction and choose between Device type restriction or Device limit restriction.
    3. Define Platforms: For device type restrictions, select the platforms you want to allow or block (e.g., iOS/iPadOS, Android, Windows, macOS). Configure operating system versions as needed.
    4. Assign to Groups: Assign these restrictions to specific user or device groups.

    B. Create Device Compliance Policies

    Compliance policies define the conditions a device must meet to be considered "compliant" with your organization's security standards. Non-compliant devices can be blocked from accessing corporate resources or flagged for remediation.

    1. Navigate to Compliance Policies: Go to Devices > Compliance policies > Policies.
    2. Create Policy: Click Create Policy and select the platform (e.g., Windows 10 and later, Android Enterprise).
    3. Configure Settings: Define settings such as requiring a password, encryption, minimum OS version, and Windows Defender settings.
    4. Actions for Non-compliance: Specify actions to take for non-compliant devices, such as sending email notifications or marking the device as non-compliant immediately.
    5. Assign Policy: Assign the policy to your user or device groups.
    IT professional monitoring server room with blue LED lights
    IT professional monitoring server room with blue LED lights

    3. Set Up Application Management

    Intune's application management (MAM) capabilities allow you to deploy, manage, and protect applications on both enrolled and unenrolled devices. This is particularly useful for bring-your-own-device (BYOD) scenarios.

    A. Add and Deploy Applications

    You can add various types of applications to Intune, including store apps, LOB (line-of-business) apps, and Microsoft 365 apps.

    1. Navigate to Apps: In the Microsoft Endpoint Manager admin centre, go to Apps > All apps.
    2. Add App: Click Add and select the app type (e.g., Microsoft 365 Apps for Windows 10 and later, Store app (for Android), iOS store app).
    3. Configure App Details: Follow the wizard to configure app details, assignments, and installation settings.
    4. Assign to Groups: Assign the applications to user or device groups as Required (automatic installation), Available for enrolled devices (user-initiated installation), or Uninstall.

    B. Implement App Protection Policies

    App protection policies (APP) protect your organization's data within applications, even on devices not fully enrolled with Intune. This prevents data leakage and ensures corporate data remains secure.

    1. Navigate to App Protection Policies: Go to Apps > App protection policies.
    2. Create Policy: Click Create policy and select the platform (e.g., iOS/iPadOS, Android).
    3. Configure Data Protection Settings: Define settings like requiring a PIN for app access, blocking screenshots, preventing "save as" to personal locations, and encrypting corporate data.
    4. Conditional Access: Integrate with Conditional Access policies to further restrict access to applications based on device compliance and app protection status.
    5. Assign to Groups: Assign the policies to user groups that will be using the protected applications.
    Team reviewing cybersecurity dashboard on large screen
    Team reviewing cybersecurity dashboard on large screen

    4. Onboard Windows Devices with Autopilot

    Windows Autopilot streamlines the deployment of new Windows devices, providing a near-zero-touch experience for end-users. Devices can be shipped directly to users and automatically configured with the necessary policies, applications, and settings.

    1. Register Devices: Work with your hardware vendor to register new devices with Windows Autopilot. This involves providing device hardware hashes.
    2. Create Autopilot Deployment Profiles: In the Microsoft Endpoint Manager admin centre, go to Devices > Windows > Windows Enrolment > Windows Autopilot Deployment Program > Deployment profiles.
    3. Create Profile: Click Create profile, select Windows PC, and follow the wizard to configure OOBE (out-of-box experience) settings, user assignment, and more.
    4. Assign Profle: Assign the Autopilot profile to your device groups.
    5. Status and Monitoring: Monitor the deployment status of your Autopilot devices under Devices > Windows > Windows Enrolment > Windows Autopilot Deployment Program.
    User setting up new laptop in an office environment
    User setting up new laptop in an office environment

    Conclusion

    Configuring Microsoft Intune is a critical step towards modern device management and enhanced cybersecurity for SMBs. By following these steps and establishing robust device enrolment restrictions, compliance policies, application management, and Windows Autopilot, you can effectively secure and manage your organization's digital assets. Remember to regularly review and update your Intune policies to adapt to evolving security threats and business needs. Mirage Informatique is here to help you navigate the complexities of Intune and ensure your IT infrastructure is secure and efficient.

    Share

    Related Articles