1
00:00:00,000 --> 00:00:01,880
What happens when a company hands you a laptop

2
00:00:01,880 --> 00:00:03,000
and says go to work?

3
00:00:03,000 --> 00:00:05,960
You power it on, sign in, and start doing your job.

4
00:00:05,960 --> 00:00:07,680
But behind that simple moment, there's

5
00:00:07,680 --> 00:00:09,440
a whole process running in the background.

6
00:00:09,440 --> 00:00:11,120
Something has to install the right apps,

7
00:00:11,120 --> 00:00:13,440
enforce the security settings, and make sure your device is

8
00:00:13,440 --> 00:00:15,320
safe to use with company data.

9
00:00:15,320 --> 00:00:17,560
15 years ago, that process looked very different.

10
00:00:17,560 --> 00:00:19,640
I'd had to physically touch every single device.

11
00:00:19,640 --> 00:00:21,920
They'd unbox a laptop, install the operating system,

12
00:00:21,920 --> 00:00:24,360
configure every setting by hand, load all the applications,

13
00:00:24,360 --> 00:00:26,280
test everything, and then hand it to you.

14
00:00:26,280 --> 00:00:28,480
If something needed to change later on the security update

15
00:00:28,480 --> 00:00:31,000
in your app, somebody had to push that change manually

16
00:00:31,000 --> 00:00:32,600
or through complex on-premise servers.

17
00:00:32,600 --> 00:00:34,040
Intune changes all of that.

18
00:00:34,040 --> 00:00:36,880
It's a cloud service that does the entire job remotely.

19
00:00:36,880 --> 00:00:39,040
Without IT ever needing to see your device,

20
00:00:39,040 --> 00:00:41,120
think of it as a digital bouncer and butler

21
00:00:41,120 --> 00:00:42,320
for your work devices.

22
00:00:42,320 --> 00:00:44,800
It decides what's allowed in, what stays out,

23
00:00:44,800 --> 00:00:46,920
and makes sure everything runs smoothly.

24
00:00:46,920 --> 00:00:48,120
All from the cloud.

25
00:00:48,120 --> 00:00:50,040
What exactly is Microsoft Intune?

26
00:00:50,040 --> 00:00:51,280
Here's the simplest definition.

27
00:00:51,280 --> 00:00:53,800
Microsoft Intune is a cloud-based service

28
00:00:53,800 --> 00:00:56,800
that manages devices, phones, laptops, tablets,

29
00:00:56,800 --> 00:00:58,400
from one central dashboard.

30
00:00:58,400 --> 00:01:00,640
It's part of Microsoft's endpoint manager family,

31
00:01:00,640 --> 00:01:02,320
but most people just call it Intune.

32
00:01:02,320 --> 00:01:04,040
Now let's clear up a common confusion.

33
00:01:04,040 --> 00:01:06,480
Intune is not a VPN, not antivirus software,

34
00:01:06,480 --> 00:01:07,960
and not a remote desktop tool.

35
00:01:07,960 --> 00:01:09,680
It's a device management platform.

36
00:01:09,680 --> 00:01:12,440
That means its job is to control what happens on a device,

37
00:01:12,440 --> 00:01:15,200
enforce rules, and keep an eye on device health.

38
00:01:15,200 --> 00:01:18,000
Not to connect you to a network or scan for viruses,

39
00:01:18,000 --> 00:01:20,960
though it does work alongside tools that do those things.

40
00:01:20,960 --> 00:01:22,280
Intune has three core jobs.

41
00:01:22,280 --> 00:01:23,920
It enforces security settings,

42
00:01:23,920 --> 00:01:25,240
things like password requirements,

43
00:01:25,240 --> 00:01:26,760
encryption and camera restrictions.

44
00:01:26,760 --> 00:01:29,200
It deploys apps, so when you need outlook or teams,

45
00:01:29,200 --> 00:01:30,680
they just appear on your device.

46
00:01:30,680 --> 00:01:32,080
And it tracks device health.

47
00:01:32,080 --> 00:01:34,000
It knows whether your device is up to date,

48
00:01:34,000 --> 00:01:36,360
whether it's encrypted, and whether it's been compromised.

49
00:01:36,360 --> 00:01:38,440
And it does all of this across pretty much every platform

50
00:01:38,440 --> 00:01:39,240
you can think of.

51
00:01:39,240 --> 00:01:42,680
Windows, Mac OS, iOS, Android, even some Linux devices.

52
00:01:42,680 --> 00:01:44,520
So whether you're using a corporate laptop,

53
00:01:44,520 --> 00:01:46,880
a personal phone for work, or a shared tablet

54
00:01:46,880 --> 00:01:49,000
on a factory floor, Intune can manage it.

55
00:01:49,000 --> 00:01:50,560
But Intune didn't appear out of nowhere.

56
00:01:50,560 --> 00:01:52,280
It solved a very specific problem

57
00:01:52,280 --> 00:01:54,800
that used to drive IT teams crazy.

58
00:01:54,800 --> 00:01:56,840
The old way versus the Intune way.

59
00:01:56,840 --> 00:01:57,440
Picture this.

60
00:01:57,440 --> 00:02:00,680
It's 15 years ago, and a new employee joins the company.

61
00:02:00,680 --> 00:02:03,200
Someone in the IT department grabs a laptop from a shelf,

62
00:02:03,200 --> 00:02:05,240
unboxes it, installs the operating system

63
00:02:05,240 --> 00:02:08,360
from a USB drive, configures every setting manually,

64
00:02:08,360 --> 00:02:11,080
loads all the required applications, runs tests,

65
00:02:11,080 --> 00:02:13,400
and then finally hands it to the new hire.

66
00:02:13,400 --> 00:02:15,240
That process could take hours per device,

67
00:02:15,240 --> 00:02:17,920
and for a company onboarding 50 people, that's days of work.

68
00:02:17,920 --> 00:02:19,800
Updates were just as painful because IT

69
00:02:19,800 --> 00:02:21,840
had to push group policies from on-premise servers

70
00:02:21,840 --> 00:02:23,360
sitting in a server room somewhere.

71
00:02:23,360 --> 00:02:25,080
Devices would only check for those updates

72
00:02:25,080 --> 00:02:27,080
when they were connected to the corporate network.

73
00:02:27,080 --> 00:02:29,560
So if you were working from home, or from a coffee shop,

74
00:02:29,560 --> 00:02:31,560
or from an airport lounge, your device

75
00:02:31,560 --> 00:02:35,160
might go weeks without receiving critical security updates.

76
00:02:35,160 --> 00:02:38,000
And mobile devices, they were basically a blind spot.

77
00:02:38,000 --> 00:02:39,520
It had no real way to manage phones.

78
00:02:39,520 --> 00:02:41,480
If an employee used their personal phone

79
00:02:41,480 --> 00:02:43,800
to check work email, which everybody did,

80
00:02:43,800 --> 00:02:45,760
there was no way to enforce a passcode,

81
00:02:45,760 --> 00:02:48,280
no way to wipe corporate data if the phone was lost,

82
00:02:48,280 --> 00:02:51,000
and no way to know if the device was even secure.

83
00:02:51,000 --> 00:02:52,880
Intune turned this entire model around.

84
00:02:52,880 --> 00:02:55,840
It lives in the cloud, which means it's always connected.

85
00:02:55,840 --> 00:02:58,680
Devices check in from anywhere, your home office,

86
00:02:58,680 --> 00:03:01,240
a hotel lobby, a client site, and Intune

87
00:03:01,240 --> 00:03:03,320
can push updates, enforce policies,

88
00:03:03,320 --> 00:03:04,960
and check compliance in real time.

89
00:03:04,960 --> 00:03:06,840
It sets the policies once, and every device

90
00:03:06,840 --> 00:03:08,200
follows them automatically.

91
00:03:08,200 --> 00:03:11,200
No manual setup, and no waiting for the next network connection.

92
00:03:11,200 --> 00:03:13,120
So how does Intune actually pull this off?

93
00:03:13,120 --> 00:03:14,840
Let's look under the hood at the three core building

94
00:03:14,840 --> 00:03:16,400
blocks that make it work.

95
00:03:16,400 --> 00:03:18,320
The three core building blocks.

96
00:03:18,320 --> 00:03:20,160
Let's start with device enrollment.

97
00:03:20,160 --> 00:03:22,760
This is how a device gets claimed by your company,

98
00:03:22,760 --> 00:03:25,120
and the method depends on who owns it.

99
00:03:25,120 --> 00:03:27,440
For company-owned devices, Windows Autopilot

100
00:03:27,440 --> 00:03:28,640
is the gold standard.

101
00:03:28,640 --> 00:03:31,280
Imagine a laptop shipped directly from Dell or Lenovo

102
00:03:31,280 --> 00:03:32,120
to a new employee.

103
00:03:32,120 --> 00:03:35,000
They power it on, connect to Wi-Fi, and enter their work email.

104
00:03:35,000 --> 00:03:35,760
That's it.

105
00:03:35,760 --> 00:03:37,640
Behind the scenes, Intune recognizes

106
00:03:37,640 --> 00:03:39,960
the device's unique hardware hash, applies the right

107
00:03:39,960 --> 00:03:42,280
configuration, installs the required apps,

108
00:03:42,280 --> 00:03:44,080
and joins it to the company's directory.

109
00:03:44,080 --> 00:03:45,760
No IT person ever touched that laptop.

110
00:03:45,760 --> 00:03:48,440
For iPhones and Macs, Intune integrates with Apple Business

111
00:03:48,440 --> 00:03:49,160
Manager.

112
00:03:49,160 --> 00:03:52,000
When a company buys devices through an authorized reseller,

113
00:03:52,000 --> 00:03:54,640
those devices are automatically linked to the organization.

114
00:03:54,640 --> 00:03:57,040
The first time someone turns on their new iPhone,

115
00:03:57,040 --> 00:04:00,080
it walks them through the setup and enrolls into Intune

116
00:04:00,080 --> 00:04:02,520
before they even see the home screen.

117
00:04:02,520 --> 00:04:05,200
For personal devices, what people call BYOD

118
00:04:05,200 --> 00:04:08,200
or bring your own device, Intune uses something called

119
00:04:08,200 --> 00:04:11,360
a work profile on Android and user enrollment on iOS.

120
00:04:11,360 --> 00:04:13,320
Instead of taking over the whole phone,

121
00:04:13,320 --> 00:04:16,440
it creates a separate encrypted space just for work, apps,

122
00:04:16,440 --> 00:04:17,200
and data.

123
00:04:17,200 --> 00:04:19,000
Your personal photos, messages, and apps

124
00:04:19,000 --> 00:04:20,560
stay completely private.

125
00:04:20,560 --> 00:04:23,120
Once the device is enrolled, Intune pushes down

126
00:04:23,120 --> 00:04:24,200
configuration policies.

127
00:04:24,200 --> 00:04:26,520
Think of these as the house rules for your work device.

128
00:04:26,520 --> 00:04:28,240
They define things like password requirements.

129
00:04:28,240 --> 00:04:29,960
Must be six characters, must include a number,

130
00:04:29,960 --> 00:04:31,320
must change every 90 days.

131
00:04:31,320 --> 00:04:32,160
They enforce encryption.

132
00:04:32,160 --> 00:04:34,640
So if your laptop gets stolen, nobody can read the files.

133
00:04:34,640 --> 00:04:36,680
They can block the camera, disable Bluetooth,

134
00:04:36,680 --> 00:04:38,880
or restrict which apps are allowed to run.

135
00:04:38,880 --> 00:04:41,600
These policies are set once by IT and applied automatically

136
00:04:41,600 --> 00:04:43,080
to every enrolled device.

137
00:04:43,080 --> 00:04:45,000
Then there are compliance policies, which

138
00:04:45,000 --> 00:04:47,360
are the health checks that run constantly behind the scenes,

139
00:04:47,360 --> 00:04:50,200
is the device up to date with the latest security patches,

140
00:04:50,200 --> 00:04:51,440
is encryption still enabled?

141
00:04:51,440 --> 00:04:53,240
Has the device been jailbroken or rooted?

142
00:04:53,240 --> 00:04:56,000
Intune checks all of this on a regular basis, typically

143
00:04:56,000 --> 00:04:57,280
every eight hours.

144
00:04:57,280 --> 00:04:59,560
If a device falls out of compliance, say the user

145
00:04:59,560 --> 00:05:01,960
disabled encryption or skipped a critical update,

146
00:05:01,960 --> 00:05:03,240
Intune can take action.

147
00:05:03,240 --> 00:05:06,640
It might send a notification asking the user to fix the problem,

148
00:05:06,640 --> 00:05:08,720
block access to company email and files

149
00:05:08,720 --> 00:05:11,600
until the issue is resolved, or in extreme cases,

150
00:05:11,600 --> 00:05:13,520
wipe the device remotely.

151
00:05:13,520 --> 00:05:15,840
But managing the device itself is only half the story

152
00:05:15,840 --> 00:05:18,120
of what about the apps and data on it?

153
00:05:18,120 --> 00:05:21,080
Mobile Application Management, the BYOD Superpower.

154
00:05:21,080 --> 00:05:23,000
This is where Intune really shines.

155
00:05:23,000 --> 00:05:25,160
A lot of companies let employees use personal phones

156
00:05:25,160 --> 00:05:25,640
for work.

157
00:05:25,640 --> 00:05:27,960
It saves money, people prefer using their own devices,

158
00:05:27,960 --> 00:05:29,160
and it's more convenient.

159
00:05:29,160 --> 00:05:30,360
But there's attention there.

160
00:05:30,360 --> 00:05:33,280
Full device management on a personal phone feels invasive.

161
00:05:33,280 --> 00:05:35,360
Nobody wants their employer controlling their photos,

162
00:05:35,360 --> 00:05:37,080
their messages, their personal apps.

163
00:05:37,080 --> 00:05:38,480
Intune's answer to this is something

164
00:05:38,480 --> 00:05:41,920
called Mobile Application Management, or MAM for short.

165
00:05:41,920 --> 00:05:43,760
Instead of managing the whole device,

166
00:05:43,760 --> 00:05:46,200
Intune manages only the work apps.

167
00:05:46,200 --> 00:05:47,200
Here's how it works.

168
00:05:47,200 --> 00:05:49,720
You install Outlook, Teams, and OneDrive

169
00:05:49,720 --> 00:05:51,480
on your personal phone like normal.

170
00:05:51,480 --> 00:05:53,160
But when you sign in with your work account,

171
00:05:53,160 --> 00:05:54,920
those apps get a corporate wrapper.

172
00:05:54,920 --> 00:05:57,280
That wrapper controls what you can do with work data

173
00:05:57,280 --> 00:05:58,360
inside those apps.

174
00:05:58,360 --> 00:05:59,560
Let me give you a real example.

175
00:05:59,560 --> 00:06:02,160
You can read a work email in Outlook on your personal phone.

176
00:06:02,160 --> 00:06:04,000
That's fine, but you cannot copy that email

177
00:06:04,000 --> 00:06:05,680
and paste it into a personal notes app.

178
00:06:05,680 --> 00:06:08,480
You cannot save a work document to your personal cloud storage.

179
00:06:08,480 --> 00:06:10,200
You cannot forward a confidential message

180
00:06:10,200 --> 00:06:11,600
to your personal email address.

181
00:06:11,600 --> 00:06:14,280
The corporate wrapper enforces those rules at the app level,

182
00:06:14,280 --> 00:06:15,520
not the device level.

183
00:06:15,520 --> 00:06:16,600
And here's the best part.

184
00:06:16,600 --> 00:06:19,640
If you leave the company, or if your phone is lost or stolen,

185
00:06:19,640 --> 00:06:22,480
IT can wipe the corporate data from those apps remotely.

186
00:06:22,480 --> 00:06:25,280
They don't touch your personal photos, your text messages,

187
00:06:25,280 --> 00:06:27,680
your contacts, or any of your personal apps.

188
00:06:27,680 --> 00:06:30,760
They just remove the work data from Outlook, Teams, and OneDrive.

189
00:06:30,760 --> 00:06:32,520
Your phone goes back to being your phone.

190
00:06:32,520 --> 00:06:34,760
This is what makes BYOD actually workable.

191
00:06:34,760 --> 00:06:36,720
Employees get to use their own devices.

192
00:06:36,720 --> 00:06:38,520
Employers get to protect their data.

193
00:06:38,520 --> 00:06:40,800
Nobody has to choose between privacy and security.

194
00:06:40,800 --> 00:06:42,360
This brings us to the security layer

195
00:06:42,360 --> 00:06:44,360
that ties everything together.

196
00:06:44,360 --> 00:06:46,400
Identity and conditional access.

197
00:06:46,400 --> 00:06:47,400
The gatekeeper.

198
00:06:47,400 --> 00:06:48,800
Intune doesn't work alone.

199
00:06:48,800 --> 00:06:52,280
It sits on top of another Microsoft service called EntraID.

200
00:06:52,280 --> 00:06:55,480
You might know it by its old name, Azure Active Directory.

201
00:06:55,480 --> 00:06:57,880
Think of EntraID as the identity system.

202
00:06:57,880 --> 00:06:58,960
It knows who you are.

203
00:06:58,960 --> 00:07:00,720
It knows whether you're allowed to sign in.

204
00:07:00,720 --> 00:07:02,160
It handles authentication.

205
00:07:02,160 --> 00:07:05,080
The part where you type your password and get a code on your phone.

206
00:07:05,080 --> 00:07:08,200
What Intune does is add device information to that picture.

207
00:07:08,200 --> 00:07:09,840
Intune tells EntraID.

208
00:07:09,840 --> 00:07:11,520
This device is healthy and compliant.

209
00:07:11,520 --> 00:07:13,760
Or this device has a problem.

210
00:07:13,760 --> 00:07:15,480
That signal, device health,

211
00:07:15,480 --> 00:07:17,360
becomes part of the access decision.

212
00:07:17,360 --> 00:07:19,240
This is where conditional access comes in.

213
00:07:19,240 --> 00:07:22,480
Conditional access policies combine both signals into one rule.

214
00:07:22,480 --> 00:07:23,400
Is this the right person?

215
00:07:23,400 --> 00:07:24,600
Are they on a healthy device?

216
00:07:24,600 --> 00:07:26,720
Are they connecting from a trusted location?

217
00:07:26,720 --> 00:07:29,480
The policy checks all three before granting access.

218
00:07:29,480 --> 00:07:30,920
Here's what that looks like in practice.

219
00:07:30,920 --> 00:07:32,080
You're sitting in a coffee shop,

220
00:07:32,080 --> 00:07:34,360
trying to check your email on your work laptop.

221
00:07:34,360 --> 00:07:35,840
You type your password correctly.

222
00:07:35,840 --> 00:07:37,200
You pass the MFA check.

223
00:07:37,200 --> 00:07:38,120
But behind the scenes,

224
00:07:38,120 --> 00:07:40,240
Entune reports that your device hasn't installed

225
00:07:40,240 --> 00:07:41,960
the latest security update.

226
00:07:41,960 --> 00:07:43,280
It's out of compliance.

227
00:07:43,280 --> 00:07:44,880
Conditional access sees that signal

228
00:07:44,880 --> 00:07:45,720
and blocks access.

229
00:07:45,720 --> 00:07:48,760
You can't get to your email until you install that update.

230
00:07:48,760 --> 00:07:50,760
The password was correct, the person was you.

231
00:07:50,760 --> 00:07:53,280
But the device wasn't healthy, so access was denied.

232
00:07:53,280 --> 00:07:55,920
This is the foundation of something called zero trust.

233
00:07:55,920 --> 00:07:57,720
It's a security model that says,

234
00:07:57,720 --> 00:07:59,560
"Never trust, always verify.

235
00:07:59,560 --> 00:08:00,760
"Don't assume something is safe

236
00:08:00,760 --> 00:08:02,360
"just because it's on the corporate network.

237
00:08:02,360 --> 00:08:03,840
"Don't assume a user is legitimate

238
00:08:03,840 --> 00:08:05,440
"just because they know the password.

239
00:08:05,440 --> 00:08:07,000
"Check everything every time.

240
00:08:07,000 --> 00:08:08,920
"Intune is the tool that makes device verification

241
00:08:08,920 --> 00:08:10,840
"possible in a zero trust world."

242
00:08:10,840 --> 00:08:12,800
Now let's talk about the practical stuff.

243
00:08:12,800 --> 00:08:14,880
What does Entune actually look like for the people

244
00:08:14,880 --> 00:08:16,320
who use it every day?

245
00:08:16,320 --> 00:08:18,760
The admin experience versus the user experience.

246
00:08:18,760 --> 00:08:21,400
For IT admins, Entune looks like a single dashboard

247
00:08:21,400 --> 00:08:23,320
where every enrolled device shows up

248
00:08:23,320 --> 00:08:24,800
with its compliance status,

249
00:08:24,800 --> 00:08:28,080
last check-in time, operating system, and primary user.

250
00:08:28,080 --> 00:08:30,360
At a glance, they can see which devices are healthy

251
00:08:30,360 --> 00:08:31,680
and which ones have problems.

252
00:08:31,680 --> 00:08:34,360
From that dashboard, admins can take remote actions.

253
00:08:34,360 --> 00:08:36,520
If a laptop gets lost, they can wipe it remotely,

254
00:08:36,520 --> 00:08:38,040
all data gone, just like that.

255
00:08:38,040 --> 00:08:39,800
If an employee forgets their pin,

256
00:08:39,800 --> 00:08:43,040
they can reset it without making them bring the device to IT.

257
00:08:43,040 --> 00:08:44,720
Critical security update, they can push it

258
00:08:44,720 --> 00:08:46,240
to every device with a few clicks.

259
00:08:46,240 --> 00:08:47,720
The reporting is just as powerful.

260
00:08:47,720 --> 00:08:50,360
Admins can see exactly which devices are out of compliance

261
00:08:50,360 --> 00:08:52,960
and why, filter by platform, user or policy,

262
00:08:52,960 --> 00:08:55,520
and export reports for audits, all in one place.

263
00:08:55,520 --> 00:08:57,360
For end users, that's you.

264
00:08:57,360 --> 00:08:58,640
Entune is nearly invisible.

265
00:08:58,640 --> 00:09:00,200
Most of the time, you never know it's there

266
00:09:00,200 --> 00:09:01,760
and that's exactly the goal.

267
00:09:01,760 --> 00:09:03,440
You might use the company portal app once

268
00:09:03,440 --> 00:09:05,400
to install Work Apps, see a notification

269
00:09:05,400 --> 00:09:06,840
about a password update,

270
00:09:06,840 --> 00:09:09,440
or notice your work laptop forces you to use a pin

271
00:09:09,440 --> 00:09:10,920
before booting.

272
00:09:10,920 --> 00:09:12,640
But the vast majority of Intune's work

273
00:09:12,640 --> 00:09:14,840
happens silently in the background.

274
00:09:14,840 --> 00:09:17,520
Pushing configuration changes, updating apps, checking

275
00:09:17,520 --> 00:09:20,240
compliance, and reporting back to the admin dashboard,

276
00:09:20,240 --> 00:09:22,880
all automatically, without any input from you.

277
00:09:22,880 --> 00:09:25,720
The best Intune deployment is the one users never think about.

278
00:09:25,720 --> 00:09:28,280
They just know their devices work, their apps are there,

279
00:09:28,280 --> 00:09:30,320
and their data is safe with everything else happening

280
00:09:30,320 --> 00:09:33,280
behind the scenes, Intune versus the alternatives.

281
00:09:33,280 --> 00:09:34,560
Now, Intune is powerful,

282
00:09:34,560 --> 00:09:36,920
but it's not the only device management platform out there.

283
00:09:36,920 --> 00:09:39,120
Let's look at how it compares to the main alternatives.

284
00:09:39,120 --> 00:09:40,200
The big one is Jamf Pro,

285
00:09:40,200 --> 00:09:42,360
the gold standard for Apple-only environments.

286
00:09:42,360 --> 00:09:44,560
If your company only uses Macs and iPhones,

287
00:09:44,560 --> 00:09:46,320
Jamf gives you much deeper control.

288
00:09:46,320 --> 00:09:49,240
You can run shell scripts, build complex automation workflows,

289
00:09:49,240 --> 00:09:51,760
and patch third-party Mac apps automatically.

290
00:09:51,760 --> 00:09:54,080
It's built by Apple Specialist for Apple Specialist,

291
00:09:54,080 --> 00:09:55,800
but it only manages Apple devices.

292
00:09:55,800 --> 00:09:57,400
So if you have a single Windows laptop

293
00:09:57,400 --> 00:09:59,080
in your fleet, Jamf can't help you,

294
00:09:59,080 --> 00:10:00,880
then there's VMware Workspace 1,

295
00:10:00,880 --> 00:10:02,520
a strong cross-platform competitor

296
00:10:02,520 --> 00:10:06,040
that manages Windows, Mac, iOS, and Android just like Intune.

297
00:10:06,040 --> 00:10:07,600
But it's more complex to set up.

298
00:10:07,600 --> 00:10:09,080
It tends to be more expensive

299
00:10:09,080 --> 00:10:11,560
and requires dedicated expertise to run well.

300
00:10:11,560 --> 00:10:13,920
Intune's advantage comes down to integration.

301
00:10:13,920 --> 00:10:16,480
It's built into the Microsoft 365 ecosystem,

302
00:10:16,480 --> 00:10:18,880
talking directly to Android for identity,

303
00:10:18,880 --> 00:10:21,920
defendable security, and office apps for data protection.

304
00:10:21,920 --> 00:10:23,640
Everything is designed to work together

305
00:10:23,640 --> 00:10:25,280
because Microsoft built it all.

306
00:10:25,280 --> 00:10:28,200
For organizations already using Microsoft 365,

307
00:10:28,200 --> 00:10:31,000
which is most, Intune is the natural choice.

308
00:10:31,000 --> 00:10:32,520
You don't need to buy a separate tool,

309
00:10:32,520 --> 00:10:33,800
learn a separate interface,

310
00:10:33,800 --> 00:10:35,200
or manage a separate integration.

311
00:10:35,200 --> 00:10:36,240
It's already there.

312
00:10:36,240 --> 00:10:38,360
Included in your E3 or E5 license.

313
00:10:38,360 --> 00:10:40,920
That said, many large enterprises use both.

314
00:10:40,920 --> 00:10:42,360
Jamf for their Apple devices,

315
00:10:42,360 --> 00:10:45,360
giving Mac admins deep control, and Intune for everything else.

316
00:10:45,360 --> 00:10:46,720
The two platforms integrate

317
00:10:46,720 --> 00:10:49,280
so Jamf can send compliance signals to Intune,

318
00:10:49,280 --> 00:10:51,320
which feeds them into conditional access.

319
00:10:51,320 --> 00:10:54,720
It's more complex, but it gives you the best of both worlds.

320
00:10:54,720 --> 00:10:55,880
What's coming next?

321
00:10:55,880 --> 00:10:57,320
Intune keeps getting better

322
00:10:57,320 --> 00:10:59,760
and the biggest shift arrives in July, 2026,

323
00:10:59,760 --> 00:11:01,760
when several Intune Suite capabilities

324
00:11:01,760 --> 00:11:06,080
move into the standard Microsoft 365, E3 and E5 licenses.

325
00:11:06,080 --> 00:11:08,720
Features that used to cost extra are now included.

326
00:11:08,720 --> 00:11:11,400
Remote help lets it take over screen for troubleshooting.

327
00:11:11,400 --> 00:11:13,360
Advanced analytics gives deeper insights

328
00:11:13,360 --> 00:11:14,840
into device performance.

329
00:11:14,840 --> 00:11:16,800
CloudPKi handles certificate management

330
00:11:16,800 --> 00:11:18,600
without running your own infrastructure.

331
00:11:18,600 --> 00:11:19,520
These were all add-ons,

332
00:11:19,520 --> 00:11:21,400
but now they're part of the base license.

333
00:11:21,400 --> 00:11:22,960
E5 subscribers get even more.

334
00:11:22,960 --> 00:11:24,760
Endpoint privilege management allows users

335
00:11:24,760 --> 00:11:26,240
to temporarily elevate permissions

336
00:11:26,240 --> 00:11:27,760
to install software or change settings

337
00:11:27,760 --> 00:11:29,920
without granting full admin rights.

338
00:11:29,920 --> 00:11:32,840
It's a smart middle ground between security and usability,

339
00:11:32,840 --> 00:11:34,520
and the security co-pilot integration

340
00:11:34,520 --> 00:11:36,680
brings AI assisted troubleshooting

341
00:11:36,680 --> 00:11:39,920
and policy recommendations directly into the Intune console.

342
00:11:39,920 --> 00:11:41,160
The direction here is clear.

343
00:11:41,160 --> 00:11:43,200
Intune is shifting from a standalone product

344
00:11:43,200 --> 00:11:46,360
to a built-in management layer inside Microsoft 365.

345
00:11:46,360 --> 00:11:47,800
It's not something you bolt on later.

346
00:11:47,800 --> 00:11:49,320
It's part of the foundation from the start,

347
00:11:49,320 --> 00:11:50,840
and here's the bottom line.

348
00:11:50,840 --> 00:11:54,320
Microsoft Intune is a cloud service that manages devices,

349
00:11:54,320 --> 00:11:58,560
enforces security, deploys apps, and protects corporate data,

350
00:11:58,560 --> 00:12:01,240
or without IT ever touching a single device.

351
00:12:01,240 --> 00:12:04,160
But the key isn't just device management, it's trust.

352
00:12:04,160 --> 00:12:07,280
Intune tells the rest of Microsoft 365

353
00:12:07,280 --> 00:12:09,600
this device is safe, let it through.

354
00:12:09,600 --> 00:12:11,120
That simple signal of device health

355
00:12:11,120 --> 00:12:12,800
powers conditional access, zero trust,

356
00:12:12,800 --> 00:12:14,280
and modern cloud security.

357
00:12:14,280 --> 00:12:16,320
If you use a work laptop or phone,

358
00:12:16,320 --> 00:12:18,800
Intune is probably running behind the scenes right now,

359
00:12:18,800 --> 00:12:21,200
keeping things secure without you ever noticing.

360
00:12:21,200 --> 00:12:22,280
That's the point.

361
00:12:22,280 --> 00:12:24,080
Subscribe on your favorite podcast platform

362
00:12:24,080 --> 00:12:26,360
and share this with someone starting their journey.

363
00:12:26,360 --> 00:12:28,080
Coming up next, Microsoft Defender,

364
00:12:28,080 --> 00:12:30,920
the security shield you didn't know you had.

