The rest of what the July 2026 change folded into the enterprise plans is operational rather than architectural: Remote Help, Advanced Analytics with Device Query, and Tunnel for mobile application management. These are the instruments you run a fleet with day to day, they landed at the Microsoft 365 E3 tier rather than E5, and most of them quietly replace something you are otherwise paying a third party to do.
I treated the three architectural capabilities of the Suite one at a time, because Endpoint Privilege Management, Cloud PKI, and Enterprise App Management each change something structural about how the environment is built. This operational set is different. Each of these is a smaller decision, they carry far less new responsibility, and they are the easiest things in the whole Suite to adopt. So I am covering them together, as the operational layer that now rides at E3, and I will come back to split any of them into a deeper piece when there is enough to warrant it. What follows is what each one is, where its real boundary sits, and why it is worth turning on.
Remote Help: assistance that inherits your identity
Remote Help is Microsoft’s first-party remote assistance tool, and the reason it matters is not the screen sharing, which every product does. It is that the session is built on your existing identity and device posture rather than bolted alongside it. Both the helper and the person being helped sign in with a Microsoft Entra account from the same organization, so you cannot assist someone outside your tenant and an outsider cannot use it to reach in. Role-based access control decides what a given helper can do, from viewing a screen to taking full control to acting through an elevation prompt. The helper sees a warning before connecting to a non-compliant device, and Conditional Access can require that helper accounts themselves are strongly authenticated. That is a materially better security story than a third-party remote tool that authenticates against its own directory and knows nothing about whether the device on either end is healthy.
Be clear-eyed about platform coverage, because it is uneven. Remote Help supports Windows, including Windows 365 and Azure Virtual Desktop, and macOS on current versions. Its Android support is real but narrow: it covers Samsung and Zebra devices enrolled as Android Enterprise dedicated devices, not general Android, and that is also the only place unattended sessions exist, where a helper connects to an unattended kiosk or frontline device without someone there to accept. On Windows and macOS the session is attended by design, which is the right default for a person’s own workstation. If your goal is to retire a paid remote-support product for a Windows and Mac estate, Remote Help does that cleanly. If your goal is broad unattended access across arbitrary Android hardware, it does not reach that far, and you should know it before you plan around it.
Advanced Analytics and Device Query: from reporting to asking
Endpoint Analytics in its base form tells you, on a schedule, how your fleet is doing: startup performance, application reliability, the recommendations that flow from them. The advanced tier extends that in two directions worth understanding. It adds proactive signal, an anomalies report that flags regressions before they become tickets, a low-latency device timeline, and battery and resource health reporting, all of which you can narrow to a subset of devices with scope tags. And it adds the capability I find most changes how the job feels, which is Device Query.
Device Query lets you ask a question of your devices in near real time using a proper query language, against a single device or across the whole fleet, and get an answer now rather than waiting for the next inventory cycle. Instead of hoping a scheduled report happens to contain the field you need, you interrogate the estate directly: which machines have a particular driver version, which have a service in a bad state, which match some condition you only thought of this morning. You can build an Entra group from the results of a fleet-wide query and export a large result set for analysis, and Copilot can write the query language for you from a plain-language question if you would rather describe what you want than compose it. It is worth stating plainly that both the single-device and the fleet-wide forms of Device Query are part of this advanced tier, not the base product, so this is one of the concrete things the E3 inclusion actually hands you. The shift it represents is from reporting after the fact to asking in the moment, and once a team has it they stop wanting to work the other way.
These are the instruments you run the fleet with, not the architecture you build it on.
Tunnel for MAM: resource access without the enrollment fight
Microsoft Tunnel deserves a moment of precision, because there are two things wearing the name and only one of them is the advanced capability. The base Microsoft Tunnel is a VPN gateway that gives enrolled iOS and Android devices access to on-premises and internal resources, and it comes with base Intune Plan 1, needing only somewhere to host the gateway. If your mobile devices are enrolled, you already have that and it is not what changed.
Tunnel for mobile application management is the advanced piece, and it extends that same secure access to devices that are not enrolled at all. On an unenrolled personal phone, protected apps reach internal resources through the tunnel under the control of app protection policies, with the Defender app acting as the tunnel client on Android and an equivalent path on iOS. That is the BYOD access story told without the enrollment argument that usually stalls it. You give a contractor or a personal device access to the specific internal applications it needs, governed by policy at the app layer, without taking management of the whole device and without the user having to hand their personal phone over to your MDM. For a lot of organizations that is the difference between a workable BYOD posture and one that everyone quietly circumvents, and it is what the E3 inclusion now puts within reach.
How to think about adopting them
These three are the easy yes of the Suite, precisely because none of them changes who can do what or how software and certificates arrive. They add capability without adding much obligation. Remote Help most likely retires a remote-support tool you are already paying for and gives you a better-authenticated one in its place. Device Query rewards you the first afternoon you use it and asks almost nothing in return. Tunnel for mobile application management opens a BYOD path you may currently be enrolling your way around. Adopt them as they earn their place in how your team already works, rather than as a project, because that is genuinely how lightweight they are.
Two caveats keep the picture honest. The first is the one that runs through this whole phase: the E3 and E5 inclusions landed on the Microsoft 365 plans, not on Enterprise Mobility and Security E5, so confirm in your own tenant that these capabilities are actually provisioned before you build on them, and treat the Message Center as the authority for your specific licensing rather than any summary, this one included. The second is that Copilot in Intune, including the natural-language help that can write your Device Query for you, is licensed separately and is not part of the E3 or E5 Intune inclusion, so do not assume it arrives in the same envelope.
With these three turned on alongside the architectural capabilities, the operational layer of the Suite is complete. The anchor set out what the whole thing is and the order I would adopt it in, Endpoint Privilege Management and Cloud PKI carry the structural weight, Enterprise App Management sits in the application phase where it belongs, and this operational trio is the day-to-day tooling that rides underneath all of it. Everything here is now something a large number of E3 and E5 tenants already own. The work left is not acquiring it. It is deciding, deliberately and one capability at a time, which of it you are going to actually use.
Intune Deployment Guide · Phase 12: The Intune Suite
‹ Previous: [12.3.6] Build Sheet: Certificate-Based Wi-Fi End to End




