Setting Up Microsoft Intune: A Step-by-Step Guide for SMBs
Learn how to configure Microsoft Intune for the first time with this comprehensive, step-by-step guide designed for small and medium-sized businesses. Secure and manage all your devices with ease.

This guide provides a comprehensive, step-by-step walkthrough for small and medium-sized businesses (SMBs) on how to configure Microsoft Intune for the first time. Intune, part of Microsoft Endpoint Manager, offers a unified platform for managing and securing your organization's devices and applications. By following these steps, you can establish a robust mobile device management (MDM) and mobile application management (MAM) solution, enhancing your cybersecurity posture and operational efficiency.
1. Prerequisites and Initial Setup
Before diving into Intune configuration, ensure you have the necessary prerequisites in place. This includes an active Microsoft 365 subscription that includes Intune (e.g., Microsoft 365 Business Premium, Enterprise Mobility + Security E3/E5).
If you're starting with a new tenant, make sure to activate Intune. For existing tenants, Intune is likely already active. Access the Microsoft Endpoint Manager admin centre by navigating to endpoint.microsoft.com.
Verify Licensing and Admin Roles
Ensure that your administrative account has the necessary Global Administrator or Intune Service Administrator roles assigned. Also, confirm that your users have appropriate Intune licences assigned to them. Without these licences, users will not be able to enrol their devices or access Intune-managed applications.
2. Configure Device Management Settings
The foundation of Intune lies in its device management capabilities. This involves setting up device enrolment restrictions and defining compliance policies.
A. Set Device Enrolment Restrictions
Device enrolment restrictions allow you to control which types of devices can enrol in Intune and how many devices a user can enrol. This is crucial for maintaining security and preventing unauthorized access.
- Navigate to Device Enrolment: In the Microsoft Endpoint Manager admin centre, go to
Devices > Enrol Devices > Enrolment restrictions. - Create New Restriction: Click
Create restrictionand choose betweenDevice type restrictionorDevice limit restriction. - Define Platforms: For device type restrictions, select the platforms you want to allow or block (e.g., iOS/iPadOS, Android, Windows, macOS). Configure operating system versions as needed.
- Assign to Groups: Assign these restrictions to specific user or device groups.
B. Create Device Compliance Policies
Compliance policies define the conditions a device must meet to be considered "compliant" with your organization's security standards. Non-compliant devices can be blocked from accessing corporate resources or flagged for remediation.
- Navigate to Compliance Policies: Go to
Devices > Compliance policies > Policies. - Create Policy: Click
Create Policyand select the platform (e.g., Windows 10 and later, Android Enterprise). - Configure Settings: Define settings such as requiring a password, encryption, minimum OS version, and Windows Defender settings.
- Actions for Non-compliance: Specify actions to take for non-compliant devices, such as sending email notifications or marking the device as non-compliant immediately.
- Assign Policy: Assign the policy to your user or device groups.

3. Set Up Application Management
Intune's application management (MAM) capabilities allow you to deploy, manage, and protect applications on both enrolled and unenrolled devices. This is particularly useful for bring-your-own-device (BYOD) scenarios.
A. Add and Deploy Applications
You can add various types of applications to Intune, including store apps, LOB (line-of-business) apps, and Microsoft 365 apps.
- Navigate to Apps: In the Microsoft Endpoint Manager admin centre, go to
Apps > All apps. - Add App: Click
Addand select the app type (e.g.,Microsoft 365 Apps for Windows 10 and later,Store app (for Android),iOS store app). - Configure App Details: Follow the wizard to configure app details, assignments, and installation settings.
- Assign to Groups: Assign the applications to user or device groups as
Required(automatic installation),Available for enrolled devices(user-initiated installation), orUninstall.
B. Implement App Protection Policies
App protection policies (APP) protect your organization's data within applications, even on devices not fully enrolled with Intune. This prevents data leakage and ensures corporate data remains secure.
- Navigate to App Protection Policies: Go to
Apps > App protection policies. - Create Policy: Click
Create policyand select the platform (e.g., iOS/iPadOS, Android). - Configure Data Protection Settings: Define settings like requiring a PIN for app access, blocking screenshots, preventing "save as" to personal locations, and encrypting corporate data.
- Conditional Access: Integrate with Conditional Access policies to further restrict access to applications based on device compliance and app protection status.
- Assign to Groups: Assign the policies to user groups that will be using the protected applications.

4. Onboard Windows Devices with Autopilot
Windows Autopilot streamlines the deployment of new Windows devices, providing a near-zero-touch experience for end-users. Devices can be shipped directly to users and automatically configured with the necessary policies, applications, and settings.
- Register Devices: Work with your hardware vendor to register new devices with Windows Autopilot. This involves providing device hardware hashes.
- Create Autopilot Deployment Profiles: In the Microsoft Endpoint Manager admin centre, go to
Devices > Windows > Windows Enrolment > Windows Autopilot Deployment Program > Deployment profiles. - Create Profile: Click
Create profile, selectWindows PC, and follow the wizard to configure OOBE (out-of-box experience) settings, user assignment, and more. - Assign Profle: Assign the Autopilot profile to your device groups.
- Status and Monitoring: Monitor the deployment status of your Autopilot devices under
Devices > Windows > Windows Enrolment > Windows Autopilot Deployment Program.

Conclusion
Configuring Microsoft Intune is a critical step towards modern device management and enhanced cybersecurity for SMBs. By following these steps and establishing robust device enrolment restrictions, compliance policies, application management, and Windows Autopilot, you can effectively secure and manage your organization's digital assets. Remember to regularly review and update your Intune policies to adapt to evolving security threats and business needs. Mirage Informatique is here to help you navigate the complexities of Intune and ensure your IT infrastructure is secure and efficient.
Related Articles

Essential Intune Configurations for Every SMB
Microsoft Intune offers a powerful suite of tools to manage and secure devices within your small or medium-sized business (SMB) efficiently.

How to Configure BitLocker on Intune for SMBs: A Step-by-Step Guide
BitLocker drive encryption is an essential security feature for any business.

Microsoft Secure AI Productivity: April 2026 Shift
Discover what Microsoft's April 2026 Secure AI Productivity specialization change means for Quebec partners and their clients. Get expert guidance now.