[BP 4.4] Intune Licensing: The Suite That Dissolved Into Microsoft 365

The Intune Suite is being distributed into Microsoft 365 tiers. What that changes, what it costs, and the licensing floors that decide whether a control works at all.


Every wave of this pillar has one argument that reframes the rest, and for Intune it is licensing, because the shape of the product changed four weeks before I wrote this. The Intune Suite, which for two years was a separate thing you bought, is being distributed into Microsoft 365 tiers. If your understanding of what Intune costs was formed before July 2026, it is wrong, and the direction it is wrong in is that you may already own capabilities you have been quoting as add-ons.

The redistribution, and how to write about it while it is happening

Starting July 2026, Suite capabilities are distributed across Microsoft 365 license tiers. Microsoft 365 E3 includes Intune Plan 2, Remote Help and Advanced Analytics. Microsoft 365 E5 includes everything in E3 plus Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise Application Management. For customers on other plans, the Suite remains available as a separate subscription. One mechanical detail worth carrying, because it decides where you look to confirm it: the E3 tranche arrives through Enterprise Mobility and Security E3, which is itself included with Microsoft 365 E3, rather than being attached to the Microsoft 365 SKU directly.

Three qualifications, and they are the difference between an article that ages well and one that is wrong on publication day.

It is a gradual rollout, not a switch. Eligible tenants are provisioned automatically with no action required, and Microsoft posts a notification in the Microsoft 365 admin center thirty days before the change takes effect in a given tenant. So on any given day some readers have it and some do not, and the correct thing to check is your own admin center rather than a blog post, including this one.

It is commercial only. Education and frontline worker plans are explicitly excluded at this stage. Government plans are described as planned to align with the equivalent enterprise plans, subject to compliance and regulatory requirements, which is not a commitment with a date on it.

And there is a small inconsistency worth naming rather than papering over. Microsoft’s planning guide includes Microsoft 365 E7 alongside E5 in the redistribution. Nothing else does. The release note announcing the change is titled for E3 and E5 and closes by saying the update applies to commercial Microsoft 365 E3 and E5, and E7 appears nowhere on the what’s new page at all. The licensing page mentions E7 only as an example of a bundle that carries Intune, which is a different claim. So it is one page, and I would plan on E7 being included while not putting it in a client proposal without checking the tenant, because a licensing claim is the kind of thing somebody procures against.

Some readers of this article already own Endpoint Privilege Management and do not know it. Others will own it next month. That is an unusual thing for a licensing article to have to say, and it is the current state.

What this confirms and widens is a claim this site made during the Cloud PKI work, that Cloud PKI was arriving in E5 during 2026. That was right, and it understated the change. Cloud PKI did not ride alone; Endpoint Privilege Management and Enterprise Application Management came with it into E5, and a separate lower tranche landed in E3.


The three plans, the prices, and one contradiction I will not resolve for you

Plan 1 is the base service, cloud-based unified endpoint management for devices and apps. Plan 2 is additive to Plan 1. The Suite is additive to Plan 1 and includes Plan 2. Most organisations acquire Intune inside a Microsoft 365 bundle rather than buying the plans directly.

List prices as published, per user per month, paid yearly, and every one of these decays so re-check before you quote it:

SKUListNote
Intune Plan 1$8.00The base licence every add-on requires
Intune Plan 2$4.00Additive to Plan 1
Intune Suite$10.00Additive to Plan 1, includes Plan 2
Remote Help$3.50Standalone add-on
Endpoint Privilege Management$3.00Standalone add-on
Advanced Analytics$5.00Standalone add-on
Enterprise Application Management$2.00Standalone add-on
Microsoft Cloud PKI$2.00Standalone add-on

Not sold standalone at all, available only through Plan 2 or the Suite: Microsoft Tunnel for Mobile Application Management, firmware-over-the-air updates, and specialized device management. I have seen Tunnel for MAM quoted as a standalone add-on more than once, including in my own older notes, and it is not one.

Now the contradiction, which I am recording rather than resolving because Microsoft has not resolved it. The Intune licensing page describes Plan 2 as advanced endpoint management capabilities including Remote Help and Advanced Analytics. Three other surfaces describe it more narrowly. The June 2026 release note announcing the redistribution says Plan 2 includes Microsoft Tunnel for mobile application management, specialty device management and firmware over-the-air updates, and lists Remote Help and Advanced Analytics as separate items alongside it. The pricing page sells Remote Help and Advanced Analytics as their own SKUs at their own prices. And the planning guide’s redistribution sentence lists Plan 2, Remote Help and Advanced Analytics as three separate things arriving in E3, which implies they are not inside each other.

Four first-party surfaces, two different answers to what Plan 2 contains, and three of the four agree against the one. My reading, offered as a reading rather than a fact, is that the licensing page describes the post-redistribution framing while the release note and the pricing page describe the SKU mechanics you actually purchase against, and the surfaces will converge. Until they do, build your licensing position on the SKU structure and know that the plan description currently says something broader.

The advanced capabilities surface in the admin center under tenant administration as either active or available for trial or purchase, which is the fastest way to answer what a given tenant actually holds today, and it is a better source than any documentation page while the documentation itself is being rewritten around the redistribution.


The floors that decide whether a control works at all

Licensing articles usually stop at the SKU table. The more useful half is the set of floors that determine whether a baseline recommendation functions, because those are the ones that turn a design into an argument with procurement.

Compliance enforcement is the big one and it is stated plainly in Microsoft’s own planning guidance: to enforce the compliance or password rules you create in Intune, you need at minimum Intune and Entra ID P1 or P2. Compliance policy without Conditional Access is a report. This is the sentence that decides whether the critical tier’s compliance work produces a control or a dashboard, and it belongs in the first conversation rather than the last.

Requiring multifactor authentication at enrollment is a Conditional Access policy and therefore also Entra ID P1 or P2. Enrollment restrictions themselves are Plan 1 with no separate gate.

And here is a floor almost nobody states, which I only found by reading the configuration service provider documentation rather than the Intune documentation. Managing BitLocker through the CSP, beyond simply enabling and disabling it, requires Windows 10 or 11 Enterprise E3 or E5, or Education A3 or A5, regardless of your management platform. Turning encryption on and off is unrestricted. Setting the encryption algorithm, the recovery options and the PIN rules is not. Which means a Microsoft 365 Business Premium tenant configuring granular BitLocker policy is operating outside Microsoft’s stated licensing floor, and I have never seen that raised in a Business Premium design review. It does not stop the policy applying. It is a compliance exposure sitting inside a security control, which is an uncomfortable combination.


Business Premium, device licences, and unlicensed administrators

Business Premium includes Intune Plan 1, stated directly in Microsoft’s own device management documentation for the SKU. It also includes Windows Autopatch, which reached Business Premium in April 2025 when feature activation was removed. The precise limit is that support requests for Autopatch are available on E3 and above and on F3, and are not available on Business Premium or A3. Everything else, the update policy management and the groups and the reporting, is available. So the accurate sentence for a proposal is that Business Premium gets the Autopatch product and does not get Autopatch support tickets.

Device-only subscriptions exist for devices with no user attached: kiosks, dedicated devices, phone-room devices, single-use and IoT machines. They apply to Autopilot self-deploying mode, Apple automated device enrollment and Apple School Manager and Apple Configurator without user affinity, Android Enterprise dedicated devices, and enrollment by a device enrollment manager account. They are cheaper and they carry a limitation that reshapes the design rather than trimming it: a device enrolled with a device licence does not support Intune app protection policies, does not support Conditional Access, and does not support user-based features such as email and calendaring.

Read that against the critical tier. If compliance is enforced by Conditional Access, and Conditional Access does not apply to device-licensed devices, then a kiosk estate on device licences cannot be governed by compliance-based Conditional Access at any price. That is not a gap you close with configuration. It is a licensing decision that removes a control, and it should be made knowingly rather than discovered during an audit.

Unlicensed administrator access is enabled by default for tenants created after July 2021. Older tenants enable it under tenant administration, and it cannot be undone once turned on. Intune supports up to a thousand unlicensed administrators per security group, members of nested security groups are not included, and access changes can take up to forty-eight hours to take effect. The nesting exclusion is the one that produces the support call.

Two smaller notes. Co-management auto-enrollment includes Intune Plan 1 automatically, so you no longer assign individual Intune licences for that scenario, though Entra ID P1 or P2 is still required per user. And Copilot in Intune is licensed through Microsoft Security Copilot rather than through any Intune plan, which surprises people who assume it arrives with the Suite.


What to do about it

Three actions, in order of how much money they are likely to be worth.

Open tenant administration and look at the add-ons page before you buy anything. In the middle of a redistribution, the answer to what you own is a live reading rather than a memory, and the tenants I would check first are the E3 and E5 ones that have been paying separately for Remote Help or Endpoint Privilege Management. Those line items may have become redundant, or may be about to.

Watch the message center for the thirty-day notice rather than watching the blogs. The notice is per tenant and it is the only thing that tells you your date.

And re-examine the designs you shaped around not having Suite capabilities. Endpoint Privilege Management is the clearest case, because the standard workaround for not having it is standing local administrator rights, and that trade looks very different when the capability is included in the licence you already renewed. A capability arriving for free does not automatically justify a project. It does justify re-opening a decision that was made on cost grounds.


The licensing positions, collected

DecisionPositionWhy
What the tenant holds todayRead tenant administration, add-onsMid-rollout, memory and documentation both lag the tenant
Redistribution timingMessage center notice, thirty days ahead, per tenantGradual provisioning; no global date exists
E7 inclusionPlan for it, verify before proposing itThe planning guide alone includes it; the release note names only E3 and E5
Plan 2 compositionDesign on the SKU structure, not the plan descriptionFour first-party surfaces, three of them narrow and one broad
Tunnel for MAMNot a standalone purchasePlan 2 or Suite only, alongside FOTA and specialized device management
Compliance enforcementBudget Entra ID P1 or P2 with IntuneWithout it, compliance is reporting
Granular BitLocker policyRequires Windows Enterprise or EducationOn and off is unrestricted; algorithms and recovery options are not
Business Premium and AutopatchProduct yes, support requests noPrecise enough for a statement of work
Device-only licencesOnly where no Conditional Access and no app protection is acceptableThe limitation removes a control rather than trimming one
Unlicensed admin accessDecided deliberately; nested groups excludedIrreversible on tenants that have to enable it
Copilot in IntuneBudget under Security CopilotNot part of any Intune plan

Every price and every inclusion in this article should be re-read before you rely on it, and I would say that even if the product were stable, which right now it is not. The next article is the calendar of things that have already moved and things with dates attached, which is the other half of the same problem.


Best Practices
‹ Previous: [BP 4.3] Privileged Access in Intune: Roles, Scope Tags, and the Second Signature
Next: [BP 4.5] Intune on a Clock: Retirements and the Defaults That Changed Under You