⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7
Every work laptop, phone and tablet set up the same way, kept up to date, and recoverable on the day one goes missing. Your organisation decides the rules once, and each device follows them.
Intune is the part of Microsoft 365 that does this, and many organisations already pay for it without using it. I design the policies, pilot them on a few devices, and hand over a setup your own people can run.
In most small organisations every laptop was set up by hand, by whoever was available that week. Each one is slightly different. Nobody can say with confidence which are encrypted, which have missed six months of updates, or what is on the one that was left in a taxi.
Those are questions that cyber insurance questionnaires, auditors and larger customers commonly ask, and "I think so" is a hard answer to stand behind. Mobile device management replaces the guess with a record: the rules you set, the devices they apply to, and whether each device meets them today.
A policy is a setting your organisation decides once and Intune applies to every device in a group. These are the ones most organisations need on a Windows laptop. Each is there for a reason you could explain to your board.
So a lost laptop is an inconvenience and not a data breach.
So updates happen, and happen at a sensible time.
So a new or rebuilt laptop is ready to work on, not a day of setup.
So the device and the account are one decision, not two.
The point is that the organisation can see and manage its own devices. It is not surveillance of the people using them, and the design says where the line is.
Which devices exist, who uses them, when they last checked in and whether they meet your rules. Most organisations have never had this list.
A policy is written once and applied to a group. The twentieth laptop is configured exactly like the first, whoever unboxes it.
Locate the recovery key, lock the device, or wipe it. Who may do which is agreed, written down and tested before it is needed.
When somebody leaves, the device can be wiped and reissued, and work data removed from a personal phone without touching the rest of it.
A laptop the organisation owns can be fully managed. A phone a staff member owns is a different matter, and it should be.
For personal phones, Intune can protect the work data inside the work applications without enrolling the device at all. Work mail and files stay in those applications and can be removed from them, and everything else on the phone is left alone. Whether personal devices are in scope is decided with you at the start.
A tablet passed between field staff, or a kiosk at the front desk, is set up as a dedicated device: a managed home screen showing only the approved applications, with personal accounts, file transfer and unapproved installs blocked.
Staff still sign in to the work application as themselves. There is no shared Microsoft 365 password.
On a shared device, a device policy alone does not guarantee that every application clears the last person's data. Sign-out is tested in each application, with a second person, before the device goes into the field.
A rule that blocks devices which fail your checks is measured before it is enforced. Devices are assessed first and the results read, so nobody is locked out on the morning the rule is switched on. That rule is Conditional Access, and it is introduced deliberately, as its own step.
An illustrative example, not a client. The values below are the kind a small organisation typically agrees to, taken from the sample work record I use to show how completed work is written up. Yours are decided with you.
Enrol
A device joins Intune when its user signs in with a work account.
Configure
Security settings, applications and updates arrive by policy.
Check
The device is assessed against your rules and reported on.
Support and recover
Recovery keys, remote lock and wipe, and a clean reissue.
| Policy | Example setting | Why it is there |
|---|---|---|
| Disk encryption | BitLocker on, recovery keys confirmed in Entra ID | Protects files if a laptop is lost or stolen |
| Antivirus | Defender real-time and cloud protection, daily quick scan | One consistent protection setup |
| Screen lock | Unattended sessions lock after 10 minutes | An open laptop is not an open session |
| Windows updates | Quality updates deferred 7 days, agreed restart times | Updates keep moving with fewer interruptions |
| Microsoft 365 apps | Word, Excel, PowerPoint and Outlook deployed | A laptop is ready to work on |
| OneDrive | Silent sign-in, Files On-Demand, known folders backed up | Files follow the person, not the laptop |
| Compliance | Encryption, antivirus and Windows version assessed | Measured first, with no new access block |
In the example the policies go to a pilot group of laptops first, and each setting is confirmed on the device as well as in Intune before anything wider is enrolled.
What devices you have, who owns them, how they are set up now, and what your Microsoft 365 plan already includes.
Company laptops, shared devices, personal phones: which are in scope, which policies apply to each, and who may lock or wipe a device.
You receive a written programme of work with estimated hours before you commit to it.
Policies are built and applied to a small pilot group first, then checked on the devices themselves, not just in the console.
Finding a recovery key, wiping a device and enrolling it again are all tested during the pilot, while nothing depends on them.
You get a written work record and instructions for enrolling the rest, so your own administrator or IT provider can carry on.
A completed work record: each policy that was applied, the setting, the business reason for it, what was tested and the result. It is written for the person who has to explain it to a board or an insurer, not only for the person who has to maintain it.
If you want a wider look at the tenant first, the Microsoft 365 Health Check is $599 GST inclusive, fixed. It does not include setting up Intune, and you do not need one before a device project.
The setup is project work, scoped and quoted after discovery. There is no ongoing management agreement to sign.
Hamilton365 is Jamie Hamilton. I have worked in enterprise IT for more than 25 years, including a decade running identity and messaging for an environment of more than 200,000 users. The person who scopes the work is the person who builds it and hands it over.
Device management depends on identity being right first, which is why the two are designed together. My Microsoft certifications are listed with links to their public Credly records on the Microsoft 365 support page, and the identity side of the work is described on the Entra identity management page.
Device management is one part of a secure Microsoft 365 setup. These cover the parts around it.
The other half of the same question: who somebody is, what they may reach, and what happens when they join, move or leave.
Where device management sits among the other things worth configuring, in the order that buys the most safety.
What to do with a departing person's account, mail and files, including the phone that still has work mail on it.
How to find out what your plan already includes before paying for anything new.
The wider review that often finds inconsistent device management in the first place.
Tenant work beyond devices: Conditional Access, Exchange Online, migrations and governance.
Tell me roughly what devices you have and what is going wrong. I reply personally, usually the same day.
Prefer to talk it through? Call 0403 401 250 or email [email protected]