The Intune Suite is the collection of advanced capabilities that used to be a deliberate paid add-on and, as of July 2026, is now folded into Microsoft 365 E3 and E5. For a large share of tenants that changes the question from whether to buy these controls into whether to turn on the ones you already own, and that is a different and more consequential decision than it sounds.
I want to treat the Suite as the coherent product it actually is, rather than a scattering of features, because the July 2026 licensing change gave it a single story for the first time. This is the anchor for that story. What landed in E3 versus E5, the trap in how it is licensed, what each component is and where I cover it in depth, and the posture I would take toward the whole thing now that a lot of it arrives whether you went looking for it or not.
What actually changed in July 2026
Microsoft folded the advanced Intune capabilities into the Microsoft 365 enterprise plans. The split is the part worth committing to memory. Microsoft 365 E3 now effectively carries what used to be Intune Plan 2: Remote Help, Advanced Endpoint Analytics, Microsoft Tunnel for mobile application management, specialty device management, and firmware-over-the-air updates. Microsoft 365 E5 carries all of that and adds the three capabilities that were the exclusive heart of the Suite: Endpoint Privilege Management, Enterprise App Management, and Microsoft Cloud PKI. The change rode in with service release 2606 and came with a modest per-user price increase on the affected plans.
The practical consequence is a large number of tenants that now hold entitlements to controls nobody in the organization decided to buy. That is not a criticism. It is the situation, and it is the reason this cluster of articles exists. The capabilities were always defensible. What changed is that the cost objection, which used to end a lot of these conversations before they started, is gone for anyone already standing on E3 or E5.
The licensing trap worth stating plainly
There is one trap in this that will catch people, and it is worth stating before anything else. The inclusion rides on Microsoft 365 E5, not on the standalone Enterprise Mobility and Security E5 suite. Those are different products, and a great many estates that consider themselves fully licensed are running EM+S E5 alongside a lower Microsoft 365 tier. Those estates do not get Endpoint Privilege Management, Enterprise App Management, or Cloud PKI included. They buy them separately, either as the Intune Suite bundle or as individual add-ons. F1, F3, and Business Premium receive none of the Suite capabilities at all. Before you plan a single deployment on the strength of the July change, confirm which E5 you are actually holding, because the answer decides whether you own these controls or still have to purchase them.
The Suite is a set of controls that arrive with responsibilities, not a set of features to switch on because the invoice already covers them.
What is in the Suite
The Suite is best understood as three genuinely architectural capabilities and a set of smaller operational ones. The architectural three are the reason to care.
Endpoint Privilege Management is the one I would reach for first, and I treat it as the flagship of the whole Suite. It lets you run users as standard and elevate specific tasks by policy, which is the closest thing endpoint management has to a real answer for the standing-local-admin problem that has outlived every attempt to solve it. Removing standing admin rights without breaking the people who occasionally need to install a printer driver or run a legitimate elevated tool is the objective every security framework asks for and almost no estate achieves. Endpoint Privilege Management is how you finally achieve it, and it earns its own article.
Microsoft Cloud PKI is a fully managed certificate authority that issues and manages device and user certificates from the cloud. It matters because it removes the on-premises certificate authority and the NDES and SCEP connector footprint that so many estates still carry purely to hand out Wi-Fi, VPN, and authentication certificates. For an organization modernizing off Active Directory Certificate Services, this is a real architectural simplification rather than a convenience. It is an endpoint certificate issuer, not a wholesale replacement for an enterprise PKI, and I scope it carefully where I cover it.
Enterprise App Management is Microsoft’s managed application supply chain: a hosted catalog of prepackaged applications, application inventory, and a deployment model that ties into App Control for Business. I have already written the foundational piece and the auto-update deep-dive on this one, because the reader who asked about it needed it before the rest of the Suite was on the table. It lives in the application-delivery phase where it belongs, and I link to it from here rather than repeat it.
Around those three sit the operational capabilities, most now included at the E3 level. Remote Help is first-party, Entra-gated remote assistance, which matters for anyone still paying for a third-party tool to do the same job with a weaker identity story. Advanced Endpoint Analytics and Device Query turn the fleet into something you can interrogate in close to real time rather than reporting on after the fact. Microsoft Tunnel for mobile application management provides secure access to internal resources from unenrolled devices, which is the BYOD access story without the enrollment argument. Each of these is a smaller decision than the architectural three, and I give the ones that warrant it their own treatment in this phase.
How I would approach adopting it
The instinct when a set of paid capabilities suddenly becomes free is to turn all of it on, and that instinct is wrong here. Every one of these is a control, and a control you enable is a control you are now responsible for operating, governing, and answering for. Endpoint Privilege Management changes who can do what on every managed device and needs elevation rules that are designed rather than improvised. Cloud PKI becomes part of your authentication chain and inherits all the lifecycle obligations that come with issuing certificates. Enterprise App Management changes how software arrives and, through its App Control trust integration, quietly changes your application-control posture. None of these are switches. They are commitments.
So the order I would take is deliberate. Start with the two that close standing architectural gaps rather than the ones that add convenience. Endpoint Privilege Management first, because standing local admin is the largest unresolved risk on most managed fleets and this is the tool that finally retires it. Cloud PKI close behind, if and only if you carry an on-premises certificate authority that exists mainly to serve endpoints, because retiring that footprint is worth real design effort. Enterprise App Management next for the estates whose packaging labor is a genuine cost. The operational capabilities, Remote Help and the analytics tooling, follow as they earn their place, and they are the easiest to adopt precisely because they carry the least new responsibility.
The framing I keep coming back to is that the licensing change did not hand you features. It handed you controls, and controls are worth adopting on the merits and on a schedule you set, not because the entitlement showed up in your tenant and it feels wasteful to leave it idle. The Suite is a strong set of capabilities and most estates should adopt most of it. The point is to adopt it as a series of deliberate architectural decisions, each with its own design and its own owner, which is exactly how the rest of this series treats every control worth having. The articles that follow take the components one at a time and do precisely that.
Intune Deployment Guide · Phase 12: The Intune Suite
Next: [12.2] Endpoint Privilege Management: Retiring Standing Local Admin ›




