Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
Also called Microsoft Endpoint Manager.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Intune in context, with comparison tables and the common traps.
Terms in this definition
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- Account protection
Covers Windows LAPS, local user group membership, Credential Guard and Windows Hello for Business in a single Intune endpoint security policy type for Windows. Since July 2024 it has replaced the Identity protection template.
- Administrative Templates
ADMX-based Group Policy settings. Intune lists the built-in ones among the settings catalog's entries; ADMX files that you bring yourself show up as Imported Administrative templates.
- ADML
The language file paired with an ADMX template, carrying the text that users see. For each ADMX imported into Intune, a single en-us ADML file is accepted.
- ADMX
Group Policy settings are defined in these XML files. The settings catalog in Intune already has many settings that depend on them, and you may import up to 20 of your own or third-party ones, at most 1 MB each and in en-us only, along with matching ADML files.
- Advanced Analytics
Adds device query, device scopes, a device timeline, anomaly detection, resource performance and battery health on top of endpoint analytics. It comes with the Intune Suite and with Intune Plan 2.
- ANC
Tells Windows 365 which Azure subscription, virtual network and subnet to place Cloud PCs in (plus, where they're hybrid joined, which AD OU and domain). Provisioning policies use it, Intune checks its health at intervals of one to six hours, and you can have 50 per tenant.
- Android Enterprise
How Google lets organisations manage Android devices that run Google Mobile Services. After a Managed Google Play account is connected, Intune handles four scenarios: fully managed, dedicated, corporate-owned work profile and personally owned work profile.
- Android Management API
The interface Google recommends for Android Enterprise; on devices, the Android Device Policy app enforces it. Intune runs corporate-owned devices on it already, and is migrating BYOD work profile devices too, replacing Company Portal there with the Microsoft Intune app.