1
00:00:00,000 --> 00:00:02,560
Today's topic is one that almost everyone has heard of,

2
00:00:02,560 --> 00:00:03,880
but most people get wrong.

3
00:00:03,880 --> 00:00:05,800
I'm talking about SCCM and Intune.

4
00:00:05,800 --> 00:00:07,440
You've probably heard both names thrown around,

5
00:00:07,440 --> 00:00:08,960
and it's easy to assume they're basically

6
00:00:08,960 --> 00:00:10,640
the same tool with different names,

7
00:00:10,640 --> 00:00:13,320
two Microsoft products that both manage devices, right?

8
00:00:13,320 --> 00:00:14,720
Well, not exactly, actually,

9
00:00:14,720 --> 00:00:16,320
they're two very different tools

10
00:00:16,320 --> 00:00:18,160
with different strengths, different philosophies

11
00:00:18,160 --> 00:00:20,200
and different infrastructure requirements.

12
00:00:20,200 --> 00:00:22,200
And picking the wrong one means you could waste time

13
00:00:22,200 --> 00:00:24,440
and money on infrastructure you don't need

14
00:00:24,440 --> 00:00:26,480
or miss the control you actually want.

15
00:00:26,480 --> 00:00:27,480
By the end of this episode,

16
00:00:27,480 --> 00:00:29,680
you'll understand what each tool actually does,

17
00:00:29,680 --> 00:00:31,400
how they compare side by side

18
00:00:31,400 --> 00:00:33,640
and which one makes sense for your organization.

19
00:00:33,640 --> 00:00:35,880
So grab your coffee and let's dive in.

20
00:00:35,880 --> 00:00:38,600
The core problem, managing devices at scale.

21
00:00:38,600 --> 00:00:41,560
Let's start with the problem, both tools are trying to solve.

22
00:00:41,560 --> 00:00:43,240
If you only have five computers in your office,

23
00:00:43,240 --> 00:00:44,200
you don't need either one.

24
00:00:44,200 --> 00:00:46,560
You can walk over and install software, run updates

25
00:00:46,560 --> 00:00:48,720
and fix things yourself and that works fine.

26
00:00:48,720 --> 00:00:51,880
But what happens with 500 computers or 5,000 or 50,000?

27
00:00:51,880 --> 00:00:53,760
The manual approach stops working very quickly.

28
00:00:53,760 --> 00:00:55,800
You can't have IT staff walking to every desk

29
00:00:55,800 --> 00:00:57,280
to install a security patch

30
00:00:57,280 --> 00:00:59,040
and you can't check each machine one by one

31
00:00:59,040 --> 00:01:00,120
for the right antivirus.

32
00:01:00,120 --> 00:01:01,400
It just doesn't scale.

33
00:01:01,400 --> 00:01:04,640
20 years ago, this was a huge problem for large organizations.

34
00:01:04,640 --> 00:01:06,720
IT teams had to physically visit machines,

35
00:01:06,720 --> 00:01:10,080
install software from CDs and run updates one at a time.

36
00:01:10,080 --> 00:01:12,160
That was slow, expensive and error prone.

37
00:01:12,160 --> 00:01:14,920
Microsoft looked at this problem and built two solutions,

38
00:01:14,920 --> 00:01:16,720
one for the old world where everything lived

39
00:01:16,720 --> 00:01:18,960
in your own building on your own servers

40
00:01:18,960 --> 00:01:22,240
and one for the new world, where devices are everywhere,

41
00:01:22,240 --> 00:01:25,400
users work remotely and the cloud handles the heavy lifting

42
00:01:25,400 --> 00:01:27,760
the first is SCCM and the second is in tune.

43
00:01:27,760 --> 00:01:30,480
They solve the same core problem, but in completely different ways.

44
00:01:30,480 --> 00:01:32,160
So before we compare them head to head,

45
00:01:32,160 --> 00:01:35,240
we need to understand what each one actually is.

46
00:01:35,240 --> 00:01:37,680
What is SCCM, the on-premises powerhouse?

47
00:01:37,680 --> 00:01:41,000
SCCM stands for System Center Configuration Manager.

48
00:01:41,000 --> 00:01:42,200
Though you might also hear it called

49
00:01:42,200 --> 00:01:45,520
Microsoft Endpoint Configuration Manager or MECM for short.

50
00:01:45,520 --> 00:01:48,480
That's the new name, but most people still call it SCCM.

51
00:01:48,480 --> 00:01:49,920
Here's the simplest definition.

52
00:01:49,920 --> 00:01:53,240
SCCM is an on-premises tool that you run on your own servers

53
00:01:53,240 --> 00:01:55,280
inside your own building on your own network.

54
00:01:55,280 --> 00:01:57,720
It's software you install and maintain yourself

55
00:01:57,720 --> 00:01:59,560
and it's been the go-to for large enterprises

56
00:01:59,560 --> 00:02:00,880
for over two decades.

57
00:02:00,880 --> 00:02:03,960
SCCM works using what's called an agent-based model.

58
00:02:03,960 --> 00:02:05,640
A small piece of software gets installed

59
00:02:05,640 --> 00:02:07,520
on every device you want to manage

60
00:02:07,520 --> 00:02:11,400
and that agent reports back to the SCCM server receives commands

61
00:02:11,400 --> 00:02:12,640
and carries out tasks.

62
00:02:12,640 --> 00:02:15,760
It's like having a tiny IT assistant living on each computer,

63
00:02:15,760 --> 00:02:16,920
waiting for instructions.

64
00:02:16,920 --> 00:02:18,800
So what can SCCM actually do?

65
00:02:18,800 --> 00:02:19,800
A lot.

66
00:02:19,800 --> 00:02:21,720
First, operating system deployment.

67
00:02:21,720 --> 00:02:24,440
You can push out windows to hundreds of new machines at once,

68
00:02:24,440 --> 00:02:27,440
saving days of manual effort, then software distribution.

69
00:02:27,440 --> 00:02:29,440
Install applications like Office or Chrome

70
00:02:29,440 --> 00:02:32,600
across your entire organization from one central console.

71
00:02:32,600 --> 00:02:34,000
It also handles patch management

72
00:02:34,000 --> 00:02:35,920
so you can roll out security updates

73
00:02:35,920 --> 00:02:37,760
on a schedule during maintenance windows

74
00:02:37,760 --> 00:02:40,200
with full control over timing and targeting.

75
00:02:40,200 --> 00:02:41,840
Compliance reporting shows which machines

76
00:02:41,840 --> 00:02:44,000
meet your security standards and which don't.

77
00:02:44,000 --> 00:02:45,680
An inventory gives you a complete picture

78
00:02:45,680 --> 00:02:48,160
of hardware and software across your environment.

79
00:02:48,160 --> 00:02:49,960
Large enterprises have relied on this tool

80
00:02:49,960 --> 00:02:51,040
for more than 20 years.

81
00:02:51,040 --> 00:02:53,160
It's mature, powerful, and gives IT teams

82
00:02:53,160 --> 00:02:55,600
deep granular control over Windows devices.

83
00:02:55,600 --> 00:02:57,240
Need to deploy a complex application

84
00:02:57,240 --> 00:02:59,200
with dependencies and custom scripts?

85
00:02:59,200 --> 00:03:00,680
SCCM can handle it.

86
00:03:00,680 --> 00:03:02,320
Need to image a hundred new laptops

87
00:03:02,320 --> 00:03:04,240
with a custom operating system build?

88
00:03:04,240 --> 00:03:04,920
That too.

89
00:03:04,920 --> 00:03:05,760
But here's the thing.

90
00:03:05,760 --> 00:03:08,160
SCCM requires serious infrastructure.

91
00:03:08,160 --> 00:03:11,320
You need domain controllers, SQL servers, site servers,

92
00:03:11,320 --> 00:03:12,880
distribution points, management points,

93
00:03:12,880 --> 00:03:14,320
and people who know how to set it all up

94
00:03:14,320 --> 00:03:16,480
and keep it running is not something you just turn on

95
00:03:16,480 --> 00:03:17,560
and forget about.

96
00:03:17,560 --> 00:03:19,240
And that's where it sibling comes in.

97
00:03:19,240 --> 00:03:22,120
A tool from Microsoft that takes a completely different approach.

98
00:03:22,120 --> 00:03:25,040
One that doesn't need any of that infrastructure at all.

99
00:03:25,040 --> 00:03:25,880
What is Intune?

100
00:03:25,880 --> 00:03:27,600
The Cloud Native Modern Tool.

101
00:03:27,600 --> 00:03:29,680
Now let's talk about the other option, Intune.

102
00:03:29,680 --> 00:03:31,120
Here's the simplest definition.

103
00:03:31,120 --> 00:03:32,480
It's a cloud-based service.

104
00:03:32,480 --> 00:03:33,520
No service to buy.

105
00:03:33,520 --> 00:03:34,960
No infrastructure to maintain.

106
00:03:34,960 --> 00:03:36,600
No SQL databases to manage.

107
00:03:36,600 --> 00:03:39,120
Everything runs inside Microsoft's Azure Data Centers.

108
00:03:39,120 --> 00:03:41,840
You sign in through a web browser, configure your policies,

109
00:03:41,840 --> 00:03:42,640
and you're done.

110
00:03:42,640 --> 00:03:44,600
Instead of the agent-based model, Intune

111
00:03:44,600 --> 00:03:46,000
uses a profile-based model.

112
00:03:46,000 --> 00:03:47,880
Devices enroll directly with the service

113
00:03:47,880 --> 00:03:50,720
over the internet, receive policies and configurations,

114
00:03:50,720 --> 00:03:53,280
and check in periodically to report their status.

115
00:03:53,280 --> 00:03:54,920
No agent software to install.

116
00:03:54,920 --> 00:03:56,760
No management points to configure.

117
00:03:56,760 --> 00:03:58,840
The device talks directly to the cloud.

118
00:03:58,840 --> 00:04:00,280
That's a big difference in scope.

119
00:04:00,280 --> 00:04:02,360
SCCM is primarily a Windows tool.

120
00:04:02,360 --> 00:04:03,840
It can manage some other platforms,

121
00:04:03,840 --> 00:04:05,480
but it's hard and soul is Windows.

122
00:04:05,480 --> 00:04:08,120
Intune, on the other hand, supports Windows, Mac OS, iOS,

123
00:04:08,120 --> 00:04:08,960
and Android.

124
00:04:08,960 --> 00:04:10,920
So if you have a mixed environment with iPhones

125
00:04:10,920 --> 00:04:13,200
for executives, Android tablets for field workers,

126
00:04:13,200 --> 00:04:14,720
and MacBooks for the design team,

127
00:04:14,720 --> 00:04:17,400
Intune can manage all of them from the same console.

128
00:04:17,400 --> 00:04:18,960
So what can Intune actually do?

129
00:04:18,960 --> 00:04:20,760
It handles device enrollment, uses

130
00:04:20,760 --> 00:04:23,640
can join their own devices, or IT can pre-configure them.

131
00:04:23,640 --> 00:04:26,360
It handles application deployment to Windows, Mac, iOS,

132
00:04:26,360 --> 00:04:27,240
and Android.

133
00:04:27,240 --> 00:04:29,400
Conditional access policies require devices

134
00:04:29,400 --> 00:04:32,520
to be compliant before they can access company data.

135
00:04:32,520 --> 00:04:35,280
Compliance policies define what a healthy device looks like

136
00:04:35,280 --> 00:04:36,600
and generate reports.

137
00:04:36,600 --> 00:04:38,680
And Windows update rings, let patches roll out

138
00:04:38,680 --> 00:04:41,920
in a controlled way, without needing WS/US or on-premises

139
00:04:41,920 --> 00:04:42,800
infrastructure.

140
00:04:42,800 --> 00:04:45,800
This is the direction Microsoft is investing in for the future.

141
00:04:45,800 --> 00:04:48,000
Almost every new feature in endpoint management

142
00:04:48,000 --> 00:04:49,680
is being built for Intune first.

143
00:04:49,680 --> 00:04:52,080
The cloud native approach is where development resources are

144
00:04:52,080 --> 00:04:52,400
going.

145
00:04:52,400 --> 00:04:55,240
So we've got two tools that both manage devices, one runs

146
00:04:55,240 --> 00:04:57,360
on your servers with agents, the other runs in the cloud

147
00:04:57,360 --> 00:04:58,360
with profiles.

148
00:04:58,360 --> 00:05:00,160
They're fundamentally different under the hood,

149
00:05:00,160 --> 00:05:02,560
and we're going to dig into what that actually means.

150
00:05:02,560 --> 00:05:05,120
On-premises versus cloud, the big difference.

151
00:05:05,120 --> 00:05:07,440
Actually, the big difference between SCCM and Intune

152
00:05:07,440 --> 00:05:08,680
comes down to just one thing--

153
00:05:08,680 --> 00:05:09,480
infrastructure.

154
00:05:09,480 --> 00:05:10,800
SCCM needs a lot of it.

155
00:05:10,800 --> 00:05:13,040
You need domain controllers for authentication,

156
00:05:13,040 --> 00:05:15,800
SQL servers to host the site database, site servers

157
00:05:15,800 --> 00:05:18,320
to run the core management role, distribution points

158
00:05:18,320 --> 00:05:20,400
to host content that devices download,

159
00:05:20,400 --> 00:05:23,000
and management points for client communication.

160
00:05:23,000 --> 00:05:24,960
Each of these is a separate server--

161
00:05:24,960 --> 00:05:27,720
or multiple servers, or running Windows server,

162
00:05:27,720 --> 00:05:31,000
consuming licenses requiring patches, needing backups.

163
00:05:31,000 --> 00:05:33,840
Intune needs one thing, an internet connection.

164
00:05:33,840 --> 00:05:34,360
That's it.

165
00:05:34,360 --> 00:05:37,000
No servers, no SQL databases, no distribution points,

166
00:05:37,000 --> 00:05:38,120
no management points.

167
00:05:38,120 --> 00:05:40,720
The infrastructure is Microsoft's problem, not yours.

168
00:05:40,720 --> 00:05:43,640
This difference shows up in every part of how these tools work.

169
00:05:43,640 --> 00:05:45,200
Take deployment methods.

170
00:05:45,200 --> 00:05:47,440
In SCCM, deploying a new operating system

171
00:05:47,440 --> 00:05:49,800
to a computer typically involves PXC boot.

172
00:05:49,800 --> 00:05:51,320
The device boots from the network,

173
00:05:51,320 --> 00:05:52,800
connects to a distribution point,

174
00:05:52,800 --> 00:05:55,320
and runs a task sequence that partitions the drive,

175
00:05:55,320 --> 00:05:58,560
installs Windows, applies settings, and installs applications.

176
00:05:58,560 --> 00:06:00,280
It's powerful, but it requires the device

177
00:06:00,280 --> 00:06:02,040
to be on the corporate network connected

178
00:06:02,040 --> 00:06:03,200
to the right infrastructure.

179
00:06:03,200 --> 00:06:04,960
Intune takes a completely different approach

180
00:06:04,960 --> 00:06:06,440
with Windows autopilot.

181
00:06:06,440 --> 00:06:08,360
A new laptop arrives from the manufacturer,

182
00:06:08,360 --> 00:06:10,240
already registered in your tenant.

183
00:06:10,240 --> 00:06:12,600
The user turns it on, connects to Wi-Fi,

184
00:06:12,600 --> 00:06:14,840
and signs in with their work credentials.

185
00:06:14,840 --> 00:06:17,600
From there, Windows configures itself automatically,

186
00:06:17,600 --> 00:06:20,600
applications install from the cloud, and policies apply.

187
00:06:20,600 --> 00:06:22,960
The device is ready to use in minutes, no imaging,

188
00:06:22,960 --> 00:06:25,880
no PXC boot, and no IT staff needed.

189
00:06:25,880 --> 00:06:27,920
Update management follows the same pattern.

190
00:06:27,920 --> 00:06:32,360
SCCM integrates with WSUS, Windows Server Update Services,

191
00:06:32,360 --> 00:06:34,280
to download and approve patches.

192
00:06:34,280 --> 00:06:35,520
You configure maintenance Windows,

193
00:06:35,520 --> 00:06:37,520
create deployment packages, target collections,

194
00:06:37,520 --> 00:06:38,560
and monitor compliance.

195
00:06:38,560 --> 00:06:41,920
It gives you deep control, but there are a lot of moving parts.

196
00:06:41,920 --> 00:06:44,320
Intune uses Windows Update for business.

197
00:06:44,320 --> 00:06:46,600
You create update rings, groups of devices

198
00:06:46,600 --> 00:06:48,600
with the same update settings, and decide

199
00:06:48,600 --> 00:06:51,360
how fast updates roll out when deadlines happen,

200
00:06:51,360 --> 00:06:53,440
and what features to defer.

201
00:06:53,440 --> 00:06:55,920
Devices check directly with Microsoft's update servers,

202
00:06:55,920 --> 00:06:58,520
no WSUS, no distribution points, no maintenance

203
00:06:58,520 --> 00:07:00,800
windows to configure, and security integration

204
00:07:00,800 --> 00:07:02,320
follows the same split.

205
00:07:02,320 --> 00:07:04,640
Intune connects natively with Azure Active Directory

206
00:07:04,640 --> 00:07:06,000
and conditional access.

207
00:07:06,000 --> 00:07:07,720
The device reports its compliance status.

208
00:07:07,720 --> 00:07:09,800
If it's not compliant, missing an update,

209
00:07:09,800 --> 00:07:11,960
no encryption, outdated antivirus,

210
00:07:11,960 --> 00:07:14,520
conditional access can block it from accessing email teams

211
00:07:14,520 --> 00:07:15,680
or SharePoint.

212
00:07:15,680 --> 00:07:17,560
It happens automatically in real time,

213
00:07:17,560 --> 00:07:20,000
without any on-premises infrastructure.

214
00:07:20,000 --> 00:07:22,080
SCCM has its own compliance engine.

215
00:07:22,080 --> 00:07:25,400
It can evaluate policies, generate reports, and remediate issues,

216
00:07:25,400 --> 00:07:27,280
but it doesn't integrate as seamlessly

217
00:07:27,280 --> 00:07:29,520
with cloud identity and access controls.

218
00:07:29,520 --> 00:07:32,160
You can make it work, but it takes more effort and more pieces.

219
00:07:32,160 --> 00:07:33,680
These differences aren't abstract.

220
00:07:33,680 --> 00:07:36,280
They matter depending on what you're actually trying to do.

221
00:07:36,280 --> 00:07:38,320
If your workforce is in one building,

222
00:07:38,320 --> 00:07:41,160
on the corporate network, with standardized Windows Desktops,

223
00:07:41,160 --> 00:07:43,680
SCCM's depth might be exactly what you need.

224
00:07:43,680 --> 00:07:46,080
But if your workforce is spread across the country,

225
00:07:46,080 --> 00:07:48,120
working from home on a mix of devices,

226
00:07:48,120 --> 00:07:50,320
Intune's cloud native approach starts to look

227
00:07:50,320 --> 00:07:51,960
a lot more practical.

228
00:07:51,960 --> 00:07:54,880
What each tool does best feature comparison.

229
00:07:54,880 --> 00:07:56,800
So let's put them side by side on the tasks

230
00:07:56,800 --> 00:07:58,120
I teams do every day.

231
00:07:58,120 --> 00:08:00,200
This is where the differences really show up.

232
00:08:00,200 --> 00:08:01,880
Start with application deployment.

233
00:08:01,880 --> 00:08:03,600
In SCCM, you have full control.

234
00:08:03,600 --> 00:08:06,120
You can create complex deployments with dependencies.

235
00:08:06,120 --> 00:08:08,600
Install this, then that, then check for a registry key

236
00:08:08,600 --> 00:08:09,680
before proceeding.

237
00:08:09,680 --> 00:08:12,040
You can schedule deployments for specific times,

238
00:08:12,040 --> 00:08:15,120
target specific collections, and configure superceedings

239
00:08:15,120 --> 00:08:17,840
so old versions get replaced automatically.

240
00:08:17,840 --> 00:08:19,880
If you need to deploy a line of business application

241
00:08:19,880 --> 00:08:23,880
with custom scripts and multiple MSI files, SCCM handles it,

242
00:08:23,880 --> 00:08:25,640
Intune can deploy applications too.

243
00:08:25,640 --> 00:08:29,240
Win32 apps, Microsoft Store Apps, line of business apps.

244
00:08:29,240 --> 00:08:29,920
But it's simpler.

245
00:08:29,920 --> 00:08:32,080
You upload the installer, configure detection rules,

246
00:08:32,080 --> 00:08:33,400
and assign it to a group.

247
00:08:33,400 --> 00:08:35,200
It works well for most common scenarios.

248
00:08:35,200 --> 00:08:39,440
But if you need deep orchestration and sequencing, SCCM still wins.

249
00:08:39,440 --> 00:08:42,640
Now OS deployment, this is where SCCM really shines.

250
00:08:42,640 --> 00:08:45,160
Task sequences let you do bare metal deployments.

251
00:08:45,160 --> 00:08:47,520
A blank hard drive becomes a fully configured Windows machine

252
00:08:47,520 --> 00:08:49,960
with applications, settings, and security policies.

253
00:08:49,960 --> 00:08:53,280
You can do in place upgrades from Windows 10 to Windows 11

254
00:08:53,280 --> 00:08:55,280
and customize every step of the process.

255
00:08:55,280 --> 00:08:58,200
Intune takes a different approach with Windows autopilot.

256
00:08:58,200 --> 00:09:00,240
The device arrives, the user signs in,

257
00:09:00,240 --> 00:09:01,400
and the cloud does the rest.

258
00:09:01,400 --> 00:09:04,200
It's faster, simpler, and works great for modern hardware.

259
00:09:04,200 --> 00:09:06,360
But if you need to re-image existing machines,

260
00:09:06,360 --> 00:09:08,120
handle complex upgrade scenarios

261
00:09:08,120 --> 00:09:11,480
or deploy custom Windows images, SCCM's task sequences

262
00:09:11,480 --> 00:09:12,640
are still the gold standard.

263
00:09:12,640 --> 00:09:14,320
Compliance in reporting is another area

264
00:09:14,320 --> 00:09:15,800
where the tools diverge.

265
00:09:15,800 --> 00:09:18,280
SCCM has SQL Server Reporting Services,

266
00:09:18,280 --> 00:09:20,640
so you can build custom reports on almost anything,

267
00:09:20,640 --> 00:09:22,360
which machines have a specific software,

268
00:09:22,360 --> 00:09:24,040
which are missing a critical update,

269
00:09:24,040 --> 00:09:26,840
what hardware configurations exist across your fleet.

270
00:09:26,840 --> 00:09:28,400
The reporting is deep and customizable,

271
00:09:28,400 --> 00:09:29,600
but it takes work to set up.

272
00:09:29,600 --> 00:09:31,240
Intune has cloud-based dashboards

273
00:09:31,240 --> 00:09:33,000
that are much easier to use.

274
00:09:33,000 --> 00:09:35,160
You can see compliance status at a glance,

275
00:09:35,160 --> 00:09:38,040
drill into specific devices and export reports.

276
00:09:38,040 --> 00:09:40,040
It's less customizable than SCCM,

277
00:09:40,040 --> 00:09:42,120
but for most organizations, it's enough.

278
00:09:42,120 --> 00:09:44,400
Mobile Device Management is Intune's territory.

279
00:09:44,400 --> 00:09:46,880
SCCM doesn't manage phones or tablets, period.

280
00:09:46,880 --> 00:09:51,080
If you have iPhones, Android devices, or iPads in your organization,

281
00:09:51,080 --> 00:09:52,760
Intune is the tool you need.

282
00:09:52,760 --> 00:09:55,520
It handles enrollment, app deployment, compliance policies,

283
00:09:55,520 --> 00:09:57,520
and remote wipe for mobile devices.

284
00:09:57,520 --> 00:09:59,160
SCCM simply can't do that.

285
00:09:59,160 --> 00:10:00,880
And Server Management goes the other way.

286
00:10:00,880 --> 00:10:04,000
SCCM handles servers, patching, monitoring, inventory,

287
00:10:04,000 --> 00:10:05,080
software deployment.

288
00:10:05,080 --> 00:10:06,200
It's built for it.

289
00:10:06,200 --> 00:10:08,560
Intune has some server support through Azure Arc,

290
00:10:08,560 --> 00:10:09,600
but it's limited.

291
00:10:09,600 --> 00:10:11,600
If you're managing Windows Server infrastructure,

292
00:10:11,600 --> 00:10:13,280
SCCM is still the right tool.

293
00:10:13,280 --> 00:10:14,800
So you can see the pattern.

294
00:10:14,800 --> 00:10:16,560
SCCM gives you depth and control

295
00:10:16,560 --> 00:10:18,720
for complex Windows and server scenarios.

296
00:10:18,720 --> 00:10:21,120
Intune gives you simplicity and cross-platform support

297
00:10:21,120 --> 00:10:22,360
for modern endpoints.

298
00:10:22,360 --> 00:10:24,040
But what if you need both?

299
00:10:24,040 --> 00:10:26,320
Co-management, running both at once.

300
00:10:26,320 --> 00:10:27,560
That's where Co-management comes in.

301
00:10:27,560 --> 00:10:28,920
It's Microsoft's supported model,

302
00:10:28,920 --> 00:10:31,240
where a single device runs under both SCCM

303
00:10:31,240 --> 00:10:34,480
and Intune at the same time, not either or, but both.

304
00:10:34,480 --> 00:10:35,720
Let's break down how this works.

305
00:10:35,720 --> 00:10:38,520
You enable Co-management on your SCCM managed devices.

306
00:10:38,520 --> 00:10:40,480
They enroll in Intune and now both tools

307
00:10:40,480 --> 00:10:41,840
manage them simultaneously.

308
00:10:41,840 --> 00:10:43,800
But you decide which tool handles which task.

309
00:10:43,800 --> 00:10:45,720
Microsoft calls these workloads sliders,

310
00:10:45,720 --> 00:10:48,080
think of them like a control panel with switches.

311
00:10:48,080 --> 00:10:50,680
For each category of management, compliance policies,

312
00:10:50,680 --> 00:10:52,520
device configuration, Windows updates,

313
00:10:52,520 --> 00:10:54,720
endpoint protection, application deployment,

314
00:10:54,720 --> 00:10:57,640
you slide the switch to either SCCM or Intune.

315
00:10:57,640 --> 00:10:59,840
That tool becomes the authority for that workload

316
00:10:59,840 --> 00:11:01,120
and the other tool steps back.

317
00:11:01,120 --> 00:11:03,040
For example, you could keep application deployment

318
00:11:03,040 --> 00:11:05,440
in SCCM because your complex deployments

319
00:11:05,440 --> 00:11:08,080
still need the depth but slide compliance policies

320
00:11:08,080 --> 00:11:11,080
to Intune for cloud-native conditional access integration.

321
00:11:11,080 --> 00:11:12,920
You could keep Windows updates in SCCM

322
00:11:12,920 --> 00:11:14,720
with your existing maintenance windows

323
00:11:14,720 --> 00:11:16,680
but slide endpoint protection to Intune

324
00:11:16,680 --> 00:11:19,000
so Defender policies live in the cloud.

325
00:11:19,000 --> 00:11:21,400
You decide workload by workload at your own pace.

326
00:11:21,400 --> 00:11:23,400
There's also a feature called tenant attach

327
00:11:23,400 --> 00:11:26,160
which surfaces your SCCM managed devices

328
00:11:26,160 --> 00:11:27,800
inside the Intune console.

329
00:11:27,800 --> 00:11:29,640
So even if you're not ready to move workloads,

330
00:11:29,640 --> 00:11:31,680
you can see all your devices in one place,

331
00:11:31,680 --> 00:11:34,800
run reports, take actions, and get that unified view

332
00:11:34,800 --> 00:11:36,960
without changing how anything works.

333
00:11:36,960 --> 00:11:39,960
This makes co-management a gradual migration path.

334
00:11:39,960 --> 00:11:42,720
Most organizations use it for 12 to 18 months,

335
00:11:42,720 --> 00:11:44,880
starting with the easy workloads like compliance

336
00:11:44,880 --> 00:11:46,920
and endpoint protection, then moving updates,

337
00:11:46,920 --> 00:11:49,720
then applications step-by-step workload by workload

338
00:11:49,720 --> 00:11:51,520
until Intune handles most of the load

339
00:11:51,520 --> 00:11:53,760
and SCCM only does what it does best.

340
00:11:53,760 --> 00:11:56,360
And here's the thing that surprises a lot of people licensing.

341
00:11:56,360 --> 00:11:59,120
If you have Microsoft 365 e3 or e5,

342
00:11:59,120 --> 00:12:01,800
you usually already have rights to both SCCM and Intune

343
00:12:01,800 --> 00:12:03,440
so running both doesn't cost extra.

344
00:12:03,440 --> 00:12:05,080
The licensing is already covered.

345
00:12:05,080 --> 00:12:07,440
There's no financial reason not to use co-management

346
00:12:07,440 --> 00:12:09,160
if it makes sense for your environment.

347
00:12:09,160 --> 00:12:11,560
Co-management is the bridge letting you keep what works

348
00:12:11,560 --> 00:12:13,080
while moving towards what's next,

349
00:12:13,080 --> 00:12:16,680
but where you start depends entirely on your organization.

350
00:12:16,680 --> 00:12:19,320
Decision framework, which one should you use?

351
00:12:19,320 --> 00:12:22,120
So you've seen how both tools work, how they compare,

352
00:12:22,120 --> 00:12:24,240
and how co-management bridges the gap.

353
00:12:24,240 --> 00:12:27,000
The question now is simple, which one should you actually use?

354
00:12:27,000 --> 00:12:28,240
Let's break it down by scenario.

355
00:12:28,240 --> 00:12:31,840
Use SCCM if you have a large on-premises environment.

356
00:12:31,840 --> 00:12:34,080
If your organization has hundreds or thousands

357
00:12:34,080 --> 00:12:37,600
of Windows desktop's in offices connected to a corporate network

358
00:12:37,600 --> 00:12:40,280
with IT staff managing everything locally.

359
00:12:40,280 --> 00:12:42,880
If you need task sequences for OS deployment,

360
00:12:42,880 --> 00:12:45,080
imaging new machines, upgrading operating systems,

361
00:12:45,080 --> 00:12:46,560
handling complex build processes,

362
00:12:46,560 --> 00:12:49,200
or if you manage servers, patching, monitoring, inventory,

363
00:12:49,200 --> 00:12:50,680
if you require deep custom reporting

364
00:12:50,680 --> 00:12:52,800
that pulls data from SQL databases

365
00:12:52,800 --> 00:12:54,600
and generates detailed compliance audits,

366
00:12:54,600 --> 00:12:57,000
SCCM is built for these scenarios.

367
00:12:57,000 --> 00:13:00,120
It's mature, proven, and gives you the control you need.

368
00:13:00,120 --> 00:13:03,200
On the other hand, use Intune if you're cloud-first.

369
00:13:03,200 --> 00:13:06,320
If your organization has already moved most of its infrastructure

370
00:13:06,320 --> 00:13:08,520
to the cloud or you're planning to.

371
00:13:08,520 --> 00:13:10,520
If you have a remote workforce working from home,

372
00:13:10,520 --> 00:13:13,360
coffee shops anywhere, if you need to manage mobile devices

373
00:13:13,360 --> 00:13:15,920
like iPhones, Android phones, iPads,

374
00:13:15,920 --> 00:13:19,200
if you're a smaller organization without dedicated IT infrastructure

375
00:13:19,200 --> 00:13:21,080
or the budget for on-premises servers.

376
00:13:21,080 --> 00:13:23,800
Intune gives you everything you need without the overhead.

377
00:13:23,800 --> 00:13:26,240
And for large enterprises migrating to the cloud,

378
00:13:26,240 --> 00:13:27,760
co-management is the bridge.

379
00:13:27,760 --> 00:13:30,640
If you have existing SCCM infrastructure and expertise

380
00:13:30,640 --> 00:13:33,480
but know the future is cloud-based, use co-management.

381
00:13:33,480 --> 00:13:36,000
If you need the depth of SCCM for some workloads

382
00:13:36,000 --> 00:13:38,840
like complex app deployments or server management,

383
00:13:38,840 --> 00:13:41,200
but want cloud flexibility for compliance policies

384
00:13:41,200 --> 00:13:44,440
or mobile device management, co-management lets you have both.

385
00:13:44,440 --> 00:13:46,440
Shifting workloads at your own pace.

386
00:13:46,440 --> 00:13:47,760
Here's a reality check.

387
00:13:47,760 --> 00:13:50,000
Intune can handle roughly 80 to 85%

388
00:13:50,000 --> 00:13:51,720
of typical device management scenarios.

389
00:13:51,720 --> 00:13:52,560
That's a lot.

390
00:13:52,560 --> 00:13:54,560
And for most organizations, Intune alone is enough,

391
00:13:54,560 --> 00:13:57,120
but that 15 to 20% gap matters if you need it.

392
00:13:57,120 --> 00:13:59,680
If you're in that gap, needing task sequences,

393
00:13:59,680 --> 00:14:02,360
complex app dependencies, deep server management,

394
00:14:02,360 --> 00:14:05,160
then SCCM or co-management is the right call.

395
00:14:05,160 --> 00:14:07,480
A real example helps bring this to life.

396
00:14:07,480 --> 00:14:08,760
Real-world example.

397
00:14:08,760 --> 00:14:10,160
A company's migration.

398
00:14:10,160 --> 00:14:13,320
Picture a mid-sized company with 2,000 Windows desktops

399
00:14:13,320 --> 00:14:14,920
and 500 mobile devices.

400
00:14:14,920 --> 00:14:16,840
They started with SCCM for everything

401
00:14:16,840 --> 00:14:18,360
and for years it worked well.

402
00:14:18,360 --> 00:14:20,440
The IT team knew that tool inside and out,

403
00:14:20,440 --> 00:14:22,800
deployments were controlled, patching was predictable,

404
00:14:22,800 --> 00:14:23,760
and life was good.

405
00:14:23,760 --> 00:14:25,360
But then remote work happened.

406
00:14:25,360 --> 00:14:27,080
Suddenly half the workforce was at home

407
00:14:27,080 --> 00:14:29,520
and those on-premises patching cycles stopped working.

408
00:14:29,520 --> 00:14:30,920
Devices that never left the office

409
00:14:30,920 --> 00:14:32,720
were now scattered across the city.

410
00:14:32,720 --> 00:14:34,640
VPN connections were slow,

411
00:14:34,640 --> 00:14:36,160
and maintenance windows didn't apply

412
00:14:36,160 --> 00:14:37,960
when machines were turned off at night.

413
00:14:37,960 --> 00:14:39,400
The old model was breaking.

414
00:14:39,400 --> 00:14:41,240
They didn't rip out SCCM overnight.

415
00:14:41,240 --> 00:14:44,160
Instead, they spent 14 months implementing co-management.

416
00:14:44,160 --> 00:14:47,160
First, they moved mobile device management to Intune,

417
00:14:47,160 --> 00:14:49,320
all 500 iPhones and Android devices

418
00:14:49,320 --> 00:14:50,720
now managed from the cloud.

419
00:14:50,720 --> 00:14:52,480
Next came compliance policies.

420
00:14:52,480 --> 00:14:54,200
Devices had to meet security standards

421
00:14:54,200 --> 00:14:57,520
before accessing company data enforced through conditional access.

422
00:14:57,520 --> 00:14:59,280
Then they moved Windows updates.

423
00:14:59,280 --> 00:15:01,080
Update rings replaced maintenance windows

424
00:15:01,080 --> 00:15:03,760
and devices checked directly with Microsoft servers

425
00:15:03,760 --> 00:15:06,680
instead of the on-premises WSUs infrastructure.

426
00:15:06,680 --> 00:15:09,440
But they kept task sequences in SCCM for situations

427
00:15:09,440 --> 00:15:11,240
like deploying a custom operating system

428
00:15:11,240 --> 00:15:12,960
image to a lab full of machines.

429
00:15:12,960 --> 00:15:15,200
They also kept complex app deployments there.

430
00:15:15,200 --> 00:15:16,600
The line of business applications

431
00:15:16,600 --> 00:15:18,920
with custom scripts and multiple dependencies,

432
00:15:18,920 --> 00:15:20,720
those stayed where the depth was.

433
00:15:20,720 --> 00:15:21,680
By the time they finished,

434
00:15:21,680 --> 00:15:24,520
server infrastructure costs were down by 60%.

435
00:15:24,520 --> 00:15:26,200
They decommissioned distribution points,

436
00:15:26,200 --> 00:15:28,120
management points and SQL servers.

437
00:15:28,120 --> 00:15:30,520
The remote worker experience improved dramatically.

438
00:15:30,520 --> 00:15:33,400
Devices got updates and policies without needing a VPN

439
00:15:33,400 --> 00:15:34,720
and they still had deep control

440
00:15:34,720 --> 00:15:36,960
for the legacy applications that required it.

441
00:15:36,960 --> 00:15:38,960
That's the pattern more organizations are following.

442
00:15:38,960 --> 00:15:40,240
Not a sudden switch,

443
00:15:40,240 --> 00:15:42,640
but a gradual workload by workload migration.

444
00:15:42,640 --> 00:15:43,920
Co-management is the bridge

445
00:15:43,920 --> 00:15:46,040
and the destination is a modern cloud-connected

446
00:15:46,040 --> 00:15:47,920
endpoint management strategy.

447
00:15:47,920 --> 00:15:49,360
So here's what you need to remember.

448
00:15:49,360 --> 00:15:52,680
SCCM and Intune solve the same problem in very different ways

449
00:15:52,680 --> 00:15:55,360
on premises depth versus cloud simplicity.

450
00:15:55,360 --> 00:15:58,000
Agent-based control versus profile-based flexibility.

451
00:15:58,000 --> 00:15:59,600
One is a 20-year veteran.

452
00:15:59,600 --> 00:16:01,680
The other is the future Microsoft is building.

453
00:16:01,680 --> 00:16:03,560
Intune is the direction things are heading,

454
00:16:03,560 --> 00:16:05,240
but SCCM is in dead.

455
00:16:05,240 --> 00:16:08,000
It's still the right tool for complex Windows environments,

456
00:16:08,000 --> 00:16:09,760
server management and organizations

457
00:16:09,760 --> 00:16:11,160
that need deep control.

458
00:16:11,160 --> 00:16:12,920
And Co-management gives you both,

459
00:16:12,920 --> 00:16:16,200
a gradual path from one to the other at your own pace.

460
00:16:16,200 --> 00:16:17,280
Here's your homework.

461
00:16:17,280 --> 00:16:18,560
Look at your current environment

462
00:16:18,560 --> 00:16:21,760
and identify one workload you could move to Intune this month.

463
00:16:21,760 --> 00:16:23,160
Start with something simple.

464
00:16:23,160 --> 00:16:25,680
Compliance policies may be a mobile device management.

465
00:16:25,680 --> 00:16:26,520
Try it.

466
00:16:26,520 --> 00:16:27,360
See how it feels.

467
00:16:27,360 --> 00:16:28,800
You don't have to move everything at once.

468
00:16:28,800 --> 00:16:30,800
If this episode helped you understand the difference

469
00:16:30,800 --> 00:16:33,520
between SCCM and Intune, please subscribe to the channel.

470
00:16:33,520 --> 00:16:35,720
We break down Microsoft's endpoint management options

471
00:16:35,720 --> 00:16:38,280
in plain English, one knowledge nugget at a time.

