⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Brisbane based · remote Australia-wide

Microsoft Intune device management

Every work laptop, phone and tablet set up the same way, kept up to date, and recoverable on the day one goes missing. Your organisation decides the rules once, and each device follows them.

Intune is the part of Microsoft 365 that does this, and many organisations already pay for it without using it. I design the policies, pilot them on a few devices, and hand over a setup your own people can run.

Why it matters

In most small organisations every laptop was set up by hand, by whoever was available that week. Each one is slightly different. Nobody can say with confidence which are encrypted, which have missed six months of updates, or what is on the one that was left in a taxi.

Those are questions that cyber insurance questionnaires, auditors and larger customers commonly ask, and "I think so" is a hard answer to stand behind. Mobile device management replaces the guess with a record: the rules you set, the devices they apply to, and whether each device meets them today.

The policies, and what each one is for

A policy is a setting your organisation decides once and Intune applies to every device in a group. These are the ones most organisations need on a Windows laptop. Each is there for a reason you could explain to your board.

Protect the device

So a lost laptop is an inconvenience and not a data breach.

Disk encryption
BitLocker switched on, with the recovery key stored in Microsoft Entra ID where an administrator can find it. The files cannot be read by whoever picks the laptop up.
Antivirus
Microsoft Defender configured the same way on every device, with real-time and cloud protection on and regular scans.
Firewall
Windows Firewall on for every kind of network, including the cafe and the hotel.
Screen lock
An unattended session locks itself after a set time, so an open laptop is not an open account.

Keep it current

So updates happen, and happen at a sensible time.

Windows updates
Updates are installed centrally after a short deferral, with agreed restart times. They keep moving without restarting somebody in the middle of their day.
An approved version
A minimum Windows version is set, so a device that has fallen behind shows up on a report and is not discovered by accident.

Give people their tools

So a new or rebuilt laptop is ready to work on, not a day of setup.

Microsoft 365 apps
Word, Excel, PowerPoint and Outlook installed automatically and activated with the person's own work licence.
OneDrive
Signed in without prompting, with Desktop, Documents and Pictures backed up. A replaced laptop gets its files back by signing in.
Browser and Wi-Fi
A consistent browser starting point and the office wireless network already configured, so nobody is handed a password on a sticky note.

Tie it to the person

So the device and the account are one decision, not two.

Work account sign-in
Staff sign in to the laptop with their own work account, under your multi-factor authentication policy.
Windows Hello
A PIN or biometric sign-in backed by the work identity. Quicker for staff, with no password typed at the laptop.

Appropriate control, and no more than that

The point is that the organisation can see and manage its own devices. It is not surveillance of the people using them, and the design says where the line is.

One view of every device

Which devices exist, who uses them, when they last checked in and whether they meet your rules. Most organisations have never had this list.

The same setup every time

A policy is written once and applied to a group. The twentieth laptop is configured exactly like the first, whoever unboxes it.

A lost device has a procedure

Locate the recovery key, lock the device, or wipe it. Who may do which is agreed, written down and tested before it is needed.

Leavers take nothing with them

When somebody leaves, the device can be wiped and reissued, and work data removed from a personal phone without touching the rest of it.

Company devices and personal devices

A laptop the organisation owns can be fully managed. A phone a staff member owns is a different matter, and it should be.

For personal phones, Intune can protect the work data inside the work applications without enrolling the device at all. Work mail and files stay in those applications and can be removed from them, and everything else on the phone is left alone. Whether personal devices are in scope is decided with you at the start.

Shared and field devices

A tablet passed between field staff, or a kiosk at the front desk, is set up as a dedicated device: a managed home screen showing only the approved applications, with personal accounts, file transfer and unapproved installs blocked.

Staff still sign in to the work application as themselves. There is no shared Microsoft 365 password.

Two things that are tested, not assumed

On a shared device, a device policy alone does not guarantee that every application clears the last person's data. Sign-out is tested in each application, with a second person, before the device goes into the field.

A rule that blocks devices which fail your checks is measured before it is enforced. Devices are assessed first and the results read, so nobody is locked out on the morning the rule is switched on. That rule is Conditional Access, and it is introduced deliberately, as its own step.

What a finished setup looks like

An illustrative example, not a client. The values below are the kind a small organisation typically agrees to, taken from the sample work record I use to show how completed work is written up. Yours are decided with you.

  1. Enrol

    A device joins Intune when its user signs in with a work account.

  2. Configure

    Security settings, applications and updates arrive by policy.

  3. Check

    The device is assessed against your rules and reported on.

  4. Support and recover

    Recovery keys, remote lock and wipe, and a clean reissue.

The life of a managed device, from first sign-in to reissue.
Example Windows laptop policies, the setting applied and the reason for it
PolicyExample settingWhy it is there
Disk encryptionBitLocker on, recovery keys confirmed in Entra IDProtects files if a laptop is lost or stolen
AntivirusDefender real-time and cloud protection, daily quick scanOne consistent protection setup
Screen lockUnattended sessions lock after 10 minutesAn open laptop is not an open session
Windows updatesQuality updates deferred 7 days, agreed restart timesUpdates keep moving with fewer interruptions
Microsoft 365 appsWord, Excel, PowerPoint and Outlook deployedA laptop is ready to work on
OneDriveSilent sign-in, Files On-Demand, known folders backed upFiles follow the person, not the laptop
ComplianceEncryption, antivirus and Windows version assessedMeasured first, with no new access block

In the example the policies go to a pilot group of laptops first, and each setting is confirmed on the device as well as in Intune before anything wider is enrolled.

How an engagement works

  1. Review devices and licensing

    What devices you have, who owns them, how they are set up now, and what your Microsoft 365 plan already includes.

  2. Agree what is managed, and how far

    Company laptops, shared devices, personal phones: which are in scope, which policies apply to each, and who may lock or wipe a device.

  3. A programme of work and an estimate

    You receive a written programme of work with estimated hours before you commit to it.

  4. Build and pilot

    Policies are built and applied to a small pilot group first, then checked on the devices themselves, not just in the console.

  5. Test the bad days

    Finding a recovery key, wiping a device and enrolling it again are all tested during the pilot, while nothing depends on them.

  6. Work record and handover

    You get a written work record and instructions for enrolling the rest, so your own administrator or IT provider can carry on.

What you are left with

A completed work record: each policy that was applied, the setting, the business reason for it, what was tested and the result. It is written for the person who has to explain it to a board or an insurer, not only for the person who has to maintain it.

An optional place to start

If you want a wider look at the tenant first, the Microsoft 365 Health Check is $599 GST inclusive, fixed. It does not include setting up Intune, and you do not need one before a device project.

The setup is project work, scoped and quoted after discovery. There is no ongoing management agreement to sign.

Who does the work

Hamilton365 is Jamie Hamilton. I have worked in enterprise IT for more than 25 years, including a decade running identity and messaging for an environment of more than 200,000 users. The person who scopes the work is the person who builds it and hands it over.

Device management depends on identity being right first, which is why the two are designed together. My Microsoft certifications are listed with links to their public Credly records on the Microsoft 365 support page, and the identity side of the work is described on the Entra identity management page.

Questions about Intune

Discuss device management

Tell me roughly what devices you have and what is going wrong. I reply personally, usually the same day.

A general description is enough. Please do not send serial numbers, recovery keys or passwords through this form.

Prefer to talk it through? Call 0403 401 250 or email [email protected]