Category Intune

Designing, deploying, and operating Microsoft Intune. Home of the Intune Deployment Guide.

[10.5] Change Management: Making Changes Safely at Scale

Most Intune incidents aren’t caused by external threats or platform failures. They’re caused by changes – policy updates, application deployments, configuration adjustments – that behaved differently in production than expected. Change management in Intune isn’t bureaucracy. It’s the practice that…

[9.3.2] Work Profile vs Fully Managed: Making the Right Call

The choice between Work Profile and Fully Managed isn’t primarily a technical decision – it’s a device ownership decision that has technical consequences. Getting the ownership question right first makes the technical configuration straightforward. Getting it wrong produces a model…

[9.5] App Protection

App Protection Policies are the mechanism that makes MAM work – they define what managed applications can and can’t do with corporate data. Getting the design right matters because a policy that’s too restrictive creates user friction that drives people…

[7.4] Assignment Intent: Required, Available, and Uninstall

Assignment intent is one of the most consequential decisions in application deployment and one of the least deliberate. Required, Available, and Uninstall aren’t interchangeable options for achieving the same outcome – they’re fundamentally different contracts between Intune and the device,…

[7.3] Detection Logic: The Part Everyone Gets Wrong

Detection logic is where application deployment fails silently. The application installs. The user can open it. The help desk has no tickets. And Intune keeps reinstalling it every few hours because the detection rule never returns true. This happens more…