Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Microsoft Intune Plan 1 Review: Device Management Without a Server Room

10 min read Updated October 5, 2026 Microsoft Product Reviews

Fix it now

Intune Plan 1 is the base device management service: it enrols Windows, Mac, iOS, Android and Linux machines, applies configuration and compliance policy, deploys software and reports state back to a console you reach from anywhere. The product is capable and usually already in your subscription. The gap is the configuration work between owning it and getting value from it.

  1. Buy it if staff work outside the office and you need control of machines that rarely touch a corporate network.
  2. Buy it if you want a new laptop to configure itself out of the box without an engineer touching it.
  3. Buy it if you want device compliance to gate access to company data, which needs Microsoft Entra ID P1 alongside it for the Conditional Access half.
  4. Buy it if you manage phones and want company data separated from personal data on a device you do not own.
  5. Skip buying it standalone until you have checked what you hold. Microsoft names Microsoft 365 E3, E5 and E7 as the usual routes, and Microsoft 365 Business Premium carries it for smaller organisations.
  6. Buy the device-only subscription for kiosks, shared tablets, meeting-room hardware and single-use devices, rather than inventing a user account for each one.

Remote Help and Advanced Analytics are Intune Plan 2, not add-ons and not Plan 1. The Intune Suite is additive to Plan 1 and includes Plan 2. Read which of the three a quote is for.

If that settles it you can stop here. If you want the enrolment prerequisites and the certificate that quietly expires every year, read on.

Why it happens

Enrolment is the foundation and each platform has its own route: Windows Autopilot for machines shipped straight to the user, Apple Automated Device Enrolment through Apple Business Manager, Android Enterprise through managed Google Play, and manual or bulk enrolment for the rest. Once a device is enrolled you apply configuration profiles for settings, compliance policies defining what a healthy device looks like, endpoint security policies covering antivirus, firewall, disk encryption and attack surface rules, and update rings that stage Windows updates across groups instead of all at once.

Application delivery covers Microsoft Store applications, line-of-business packages and Win32 software wrapped into the packaging format Intune uses. App protection policies are the underrated part, because they apply to the application rather than the device: a personal phone can hold corporate mail with copy and paste restricted and a wipe that removes only company data. That is what lets you support personal devices without demanding to manage them, and it is often the fastest route to a real security improvement.

Compliance is where Intune stops being an inventory tool. A compliance policy marks a device healthy or not, and a Conditional Access policy in Microsoft Entra ID refuses company data to devices that are not. Encryption on, firewall on, operating system current, not jailbroken: fail any of those and the mailbox stops syncing. That link between the two products is the reason they are sold together, and it needs Entra ID P1 to work. Buying Intune with no plan for the identity half produces a very good inventory and no enforcement.

The plan structure is worth stating carefully because it moved. Intune Plan 1 is the base service. Intune Plan 2 is additive to Plan 1 and brings advanced endpoint management, including Remote Help and Advanced Analytics. The Intune Suite is additive to Plan 1, includes Plan 2, and unifies the advanced management and security capabilities. Older comparisons put Remote Help in an add-on column, which is no longer how Microsoft describes it, so check the plan rather than the feature list on a renewal.

What the product does not do is decide policy for you. Intune applies your intentions precisely and has no opinion about what those intentions should be. Budget real time for deciding your update cadence, your encryption standard, your password rules and what happens to a non-compliant device, because those decisions are the project. The tooling is the easy half, and the organisations that fail to get value from Intune almost never fail because of the licence.

The moment that convinces people is a new starter opening a sealed laptop, signing in with their work account, and finding the machine configured, encrypted, joined and carrying its applications without anybody having touched it. The second is a lost phone stripped of company data from a browser in three minutes. The third is quieter: a compliance report showing which machines are behind on updates, which is a question most organisations previously could not answer at all.

Full reference

The three plans

Plan What it is Notable contents
Microsoft Intune Plan 1 The base service Enrolment, configuration, compliance, app deployment, endpoint security policy, update rings, app protection policies
Microsoft Intune Plan 2 Additive to Plan 1 Advanced endpoint management, including Remote Help and Advanced Analytics
Microsoft Intune Suite Additive to Plan 1, includes Plan 2 The unified advanced management and security set
Device-only subscription Separate For devices not affiliated with a user: kiosks, dedicated devices, phone-room devices, IoT and other single-use hardware

The setup nobody warns you about

  1. Set automatic enrolment for Windows in Microsoft Entra ID. Without it users must enrol manually, and most will not.
  2. Create an Apple MDM push certificate for iOS, iPadOS and macOS management, using an organisational Apple account rather than an individual’s.
  3. Connect Apple Business Manager and a volume purchasing token if you deploy Apple devices or paid App Store applications.
  4. Bind Android Enterprise to managed Google Play before enrolling any Android device.
  5. Register Windows hardware for Autopilot, either through your supplier or by collecting hardware identifiers from existing machines.
  6. Package your Win32 applications, define detection rules for each, and test installs on a clean machine before deploying widely.
  7. Build a pilot ring and then a broad ring, and never deploy a new configuration profile to everyone at once.

The Apple certificate, stated precisely

Fact Detail
Validity 365 days
Renewal Annually, with the same Apple account that created it
If it expires There is a 30-day grace period in which to renew
Best practice Use a company email address as the Apple ID and a mailbox monitored by more than one person
What it enables Enrolment through the Company Portal app and Apple bulk methods such as Apple Business Manager, Apple School Manager and Apple Configurator

Record the Apple account and the renewal date somewhere that survives staff turnover. The certificate can only be renewed with the account that created it, and a personal Apple ID belonging to somebody who has left is the single most avoidable device management emergency in this product.

Where each requirement sits

Need Where it lives
Enrolment, configuration, compliance, app deployment Intune Plan 1
Windows Autopilot and update rings Intune Plan 1
App protection policies for unmanaged personal devices Intune Plan 1
Compliance-gated access to company data Intune Plan 1 plus Microsoft Entra ID P1 for Conditional Access
Remote Help and Advanced Analytics Intune Plan 2, or the Intune Suite
Kiosks, shared tablets and meeting-room hardware The device-only subscription

What a realistic deployment looks like

  • Enrolling the first device takes an afternoon. Reaching a state where policy is agreed, applications are packaged and a new laptop configures itself unattended is measured in weeks. Plan the second figure.
  • Decide the policy questions before touching the console: update cadence, encryption standard, password rules, and what actually happens to a non-compliant device.
  • Co-management with Configuration Manager is a supported path, with each workload assigned to one of the two, and is the normal route for an existing Configuration Manager estate.
  • Basic mobile device management is included with Microsoft 365 subscriptions and covers mail policy and remote wipe on phones. It does not do Windows configuration, application deployment or compliance-based access.
  • The measure of success is a laptop that configures itself and a compliance report you trust. Both are achievable on Plan 1 alone, before you consider Plan 2 or the Suite.

When a licence is the actual fix

Microsoft Intune Plan 1 is the right licence for any organisation whose machines have stopped living behind a firewall, which by now is most of them. It replaces the parts of Group Policy that assumed a domain-joined device on your own network, and it is the only practical way to manage phones and tablets alongside laptops from one console. Check your existing subscriptions first: Microsoft names Microsoft 365 E3, E5 and E7 as the usual routes and Microsoft 365 Business Premium carries it for smaller organisations, so a standalone purchase only makes sense if your users are on plans that do not. Arco can supply Intune per user or per device, work out which of your devices need which, and tell you whether Business Premium is cheaper than adding Intune and Entra ID P1 separately to what you already run. If somebody has quoted you Remote Help as an add-on, ask us to check the plan, because Microsoft lists it under Intune Plan 2.

Questions people ask about this

Do we need Microsoft Entra ID P1 as well?

For automatic Windows enrolment and for Conditional Access based on device compliance, yes. Compliance policy on its own only marks a device healthy or unhealthy; it is Conditional Access that acts on that verdict, and Conditional Access requires Entra ID P1. Both products are included together in Business Premium and in the enterprise suites, which is why those bundles are usually the sensible route.

What is the difference between Plan 1, Plan 2 and the Intune Suite?

Plan 1 is the base service. Plan 2 is additive to Plan 1 and brings advanced endpoint management including Remote Help and Advanced Analytics. The Intune Suite is additive to Plan 1, includes Plan 2, and unifies the advanced management and security capabilities. Older comparisons treat Remote Help as an add-on, which is not how Microsoft describes it now.

What happens if the Apple push certificate expires?

There is a 30-day grace period in which to renew it, and the renewal must use the same Apple account that created it. Beyond that you are re-enrolling devices by hand. The certificate is valid for 365 days, so put the date and the account in a place that survives whoever set it up leaving.

Can Intune manage machines that stay on-premises?

Yes, and it can run alongside Configuration Manager in co-management, where each workload is assigned to one of the two. That is the normal path for organisations with an existing Configuration Manager estate rather than a reason to choose between them.

Is there a free way to manage devices?

Basic mobile device management is included with Microsoft 365 subscriptions and covers mail policy and remote wipe on phones. It does not do Windows configuration, application deployment or compliance-based access, so it is a starting point rather than an answer.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Microsoft 365 Personal Review 2026: One User, Copilot and Cloud Storage Review Windows 11 Pro for Workstations Review: Who Needs ReFS and SMB Direct? Review SQL Server 2025 CAL Review: When Server Plus CAL Beats Core Licensing Review Windows Server 2025 Essentials Review: Small-Business Server, No CALs
โ† Back to Knowledge Base