Microsoft's endpoint management service, run from the cloud, covering both MDM and MAM. Conditional Access grant controls can depend on its compliance policies for devices and protection policies for apps.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Intune in context, with comparison tables and the common traps.
Terms in this definition
- MDM
Mobile device management: a service such as Microsoft Intune controlling the settings, security and apps of enrolled devices. Intune can push Defender configuration this way using Policy CSP and OMA-URI.
- MAM
Short for mobile application management. Rather than enrolling a phone or laptop, Intune applies app protection policies to the work apps and their data, which suits personally owned BYOD devices.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Grant controls
The part of a Conditional Access policy that either blocks access or demands conditions such as MFA, a compliant device or an approved client app. Several can be combined, requiring all of them or just one.
Related terms
- Android Management API
The interface Google recommends for Android Enterprise; on devices, the Android Device Policy app enforces it. Intune runs corporate-owned devices on it already, and is migrating BYOD work profile devices too, replacing Company Portal there with the Microsoft Intune app.
- AOSP
Intune's option for company-owned headsets (AR and VR) and other Android hardware lacking Google Mobile Services, with or without an associated user. Rather than going through Android Enterprise, it uses the Authenticator and Microsoft Intune apps.
- Device staging
A way of enrolling Android Enterprise devices in which a vendor or admin completes the provisioning using a staging token. Until a person signs in to the Microsoft Intune app, it remains userless, with Staging_ at the start of its name.
- Microsoft Endpoint Manager
Name formerly used for Microsoft's family of device-management products, which are now brought together as Microsoft Intune.