Intune Onboarding & Discovery Fill in below, then press Send at the end – or Print / Save as PDF if you prefer to return it yourself. Sections marked N/A are dropped from the PDF.
Orlando IT Services
Microsoft Intune Deployment
Onboarding & Discovery Questionnaire
Document version 1.0
Microsoft product facts verified 10 September 2026

Endpoint Management Engagement

Intune Onboarding & Discovery

This captures the environment detail needed to design a Microsoft Intune deployment built on least-privilege administration. Answers drive the RBAC model, enrolment method, policy baseline and rollout sequence. Anything you leave blank becomes an assumption we have to validate later, which costs time.

How to use this document

Return to
Questions to
Ideally back by
Read before section 1

Two answers change almost every downstream decision, so answer them first even if you skip the rest: your exact Microsoft 365 / Entra licence SKUs and counts (item 12) and whether on-premises Active Directory is still in the picture (item 15). Entra ID P1 on its own does not include Privileged Identity Management, and a hybrid-joined estate rules out the simpler Autopilot device preparation path.

1

Administration, access & least privilege

The core of the engagement. The goal is that no person holds standing Global Administrator - including us. There are a small number of tasks Microsoft still gates behind that role; we name each one where it comes up rather than pretending it does not exist.

Why we ask

Microsoft's own guidance is stronger than most teams expect: don't use Global Administrator for Intune, and don't use the Intune Administrator Entra role for day-to-day work either. Daily tasks should run on Intune's own RBAC roles, scoped to specific groups of users and devices. These questions establish where you are now and what the target model looks like.

  1. 1
    Who currently holds Global Administrator, or any other role with Intune access? List every account, including any that are shared, service, vendor or unused. Count matters more than names if you would rather not list people. Global Administrator is not the only role that matters: Security Administrator holds full admin rights over the Endpoint Security area, and Helpdesk Administrator is equivalent to Intune's own Help Desk Operator.
    Account / personRole heldWhy they have itTypeStill needed?
  2. 2
    Do you have break-glass (emergency access) accounts? Two or more cloud-only accounts on your .onmicrosoft.com domain, each registered with a passkey (FIDO2) or certificate-based sign-in, and excluded from any Conditional Access policy that blocks or restricts sign-in. Microsoft now enforces multi-factor authentication on every admin portal sign-in, break-glass accounts included, so a password sealed in an envelope no longer gets you back in. These are the only accounts that should keep standing Global Administrator.
    About those accounts
    Cloud-only (no sync)?
    Excluded from the policies that block sign-in?
    Sign-in method registered
    Where is the recovery material held?
    Last tested (date)
    Who can reach it out of hours?
  3. 3
    What multi-factor method is enforced on administrator accounts? Phishing-resistant methods (FIDO2 keys, Windows Hello for Business, certificate-based) are the target for anyone with elevated rights.

    Is MFA enforced by Conditional Access policy, by Security Defaults, or per-user?

  4. 4
    Is Privileged Identity Management (PIM) available and in use? PIM gives time-boxed, approval-gated elevation instead of standing rights. It requires Entra ID P2, Entra ID Governance or Microsoft Entra Suite - it is not included with Entra ID P1.
    What this means for the design
    Dependency

    PIM needs Entra ID P2, Entra ID Governance or Microsoft Entra Suite. Microsoft 365 Business Premium includes Entra ID P1 only, so PIM is not included there - but it does not have to be bought for everyone. A licence is required only for admins with eligible assignments plus their approvers and reviewers, so a handful of seats can be enough, and check for Enterprise Mobility + Security E5, which carries P2. If PIM genuinely is not available that is workable - the model shifts to static scoped RBAC roles plus multi admin approval and a review cadence. Confirm your exact SKUs in item 12 either way.

  5. 5
    Are any Intune RBAC roles configured today, or is all admin access through Entra roles? Intune has its own role system - Application Manager, Endpoint Privilege Manager, Endpoint Privilege Reader, Endpoint Security Manager, Help Desk Operator, Intune Role Administrator, Policy and Profile Manager, Read Only Operator, School Administrator, plus Cloud PC Administrator and Cloud PC Reader where Windows 365 is licensed - each scoped by group and by scope tag. Intune Role Administrator is the one that decides who can grant anyone else access, including us.
    Tell us which
  6. 6
    Who needs to do what? (Target admin model) Describe each person or team by the tasks they must perform. We map tasks to the least-privileged role that covers them - built-in where one fits, custom where the built-in over-grants.
    Person / teamTasks they must be able to doWhich devices/users they cover
  7. 7
    Should administrative changes require a second approver? Intune's Multi Admin Approval can require a second administrator to approve a change before it takes effect. It currently covers apps, compliance policies, settings catalog configuration policies, device wipe, retire and delete actions, role and RBAC changes, Windows PowerShell scripts, and device categories. It is the control that stops any single admin, including an external partner, acting unilaterally.
    Setting that up

    Who would be the approver(s), and what is an acceptable turnaround? Approvers have to sit in a security group, directly assigned, with direct members only - other group types fail silently.

    Which tools drive Intune through the Graph API today (RMM, scripts, reporting, third-party connectors)? Multi Admin Approval intercepts app-authenticated Graph calls too, so anything not explicitly excluded stops working the day it is switched on.

  8. 8
    How should our access be granted? We do not need and do not want Global Administrator. Two workable models below - the right one depends on whether you hold a Microsoft partner tenant. They are not equivalent: GDAP grants Microsoft Entra roles, and Microsoft's own guidance is to avoid Entra roles for day-to-day Intune work, so a guest account holding an Intune RBAC role is the tighter of the two. GDAP also cannot install or configure the Intune connectors, which rules it out on its own if the build needs the Active Directory connector for hybrid join, a certificate connector, or the Defender for Endpoint connector.
    GDAP path
    Do you hold a Microsoft partner tenant / CSP relationship?
    Who approves and revokes our access?
    Cost note

    Administrator accounts do not need an assigned Intune licence in tenants created after July 2021, where unlicensed admin access is on by default. In an older tenant it has to be switched on manually, and that switch cannot be undone. Members of nested security groups still need a licence, and so by default does anyone taking part in multi admin approval. Tell us roughly when the tenant was created (item 13) and we will confirm before assuming our access is free.

  9. 9
    Are there Conditional Access restrictions you want on administrators? Common: admin actions only from compliant/managed devices, only from named locations, session limits, and blocking legacy authentication.
  10. 10
    What review, audit and offboarding expectations do you have for admin access? Sets the operating rhythm: how often access is reviewed, what evidence you need for insurers or auditors, and how fast access must be removed when someone leaves.
    Access review cadence
    Audit evidence needed for
    Admin offboarding SLA
    Who owns the review?
  11. 11
    What is the engagement shape you want? Determines whether we hand the estate back after build, or hold ongoing administration.
    Change windows

    Do routine changes - policy pushes, update-ring promotions, certificate rotations, co-management cutovers - have to land outside your working hours?

    Which hours, which timezone
2

Tenant & licensing

Licence SKUs decide which features exist at all. Getting this exactly right prevents designing around something you cannot use.

  1. 12
    Exact licence SKUs and seat counts From the Microsoft 365 admin center. In Dashboard view this is Billing > Your products; in Simplified view it is the Subscriptions tile. Exact names and quantities, not "we have Microsoft 365".
    Licence / SKUPurchasedAssignedHave it?
    Microsoft 365 Business Premium
    Microsoft 365 Business Standard / Basic
    Microsoft 365 E3
    Microsoft 365 E7
    Microsoft 365 E5
    Microsoft 365 F1 / F3
    Intune Plan 1 (standalone)
    Intune Plan 2 (add-on)
    Intune Suite (add-on)
    Microsoft Entra ID P1
    Microsoft Entra ID P2
    Enterprise Mobility + Security E3 / E5 (E5 carries Entra ID P2 - check which one)
    Microsoft Entra Suite
    Microsoft Entra ID Governance
    Defender for Endpoint P1 / P2
    Defender for Business
    Microsoft Cloud PKI (Intune Suite, standalone, or via E5)
    Windows 365 / Cloud PC
    Other (write in)
    Timing note

    Since July 2026 Microsoft has been rolling several advanced endpoint management capabilities into Microsoft 365 E3 and E5. E3 gains Remote Help, Advanced Analytics and the Intune Plan 2 capabilities; E5 additionally gains Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise App Management. Cloud PKI matters most - it removes the need for an on-premises certificate authority for device and user certificates (see item 34). Entitlement is rolling out rather than switching on everywhere at once, so tell us what your tenant actually shows under Intune add-ons before anyone buys anything.

  2. 13
    Tenant basics Confirms we are working in the right place and flags anything unusual about the tenant's history.
    All verified domains
    Intune tenant location (Tenant administration > Tenant status; drives the region-specific firewall list in item 35)
    How many Microsoft 365 tenants do you have?
    Roughly how old is the tenant?

    Which Microsoft cloud is the tenant in?

    What that changes
    Answer this one even if you skip the rest of the section

    In GCC High and DoD, Windows Autopilot is not available and there is no plan to add it, and Autopatch, Remote Help, Cloud PKI and device health attestation are not there yet. In 21Vianet there is no Android Enterprise or Google Play at all. There is no migration path between clouds in either direction, so if the answer is anything other than Commercial, most of sections 6, 7 and 10 have to be designed differently.

    Total staff headcount
    Number of physical sites
  3. 14
    Is Intune already partially configured, or is this greenfield? A half-configured tenant with orphaned policies is a different job from an empty one. Existing policy that nobody owns is the most common cause of unexplained device behaviour.
    What is already there
3

Identity & directory

Whether on-premises Active Directory is still involved decides the device join model, and that decides everything about enrolment.

  1. 15
    What is the identity model?
    Describe it
    If you pick Cloud Sync
    Dependency

    Entra Cloud Sync cannot synchronise devices, so it cannot support Entra hybrid join. If you need hybrid-joined Windows devices (item 17), Entra Connect Sync is the only option of the two. Please do not tick Cloud Sync and hybrid join together without telling us - that combination cannot be built.

    If you are federated
    Flag

    AD FS in the picture usually means identity modernisation work happens before Intune work. Say so early - it changes sequencing, not just effort.

  2. 16
    On-premises Active Directory detail Only if AD exists. Skip if cloud-only.
    Forest / domain name(s)
    Number of domain controllers
    Oldest DC operating system
    Sync server OS and version
    Connect Sync server
    Entra Connect Sync agent version
    Time-critical - check this before anything else on the form

    Microsoft stops all Entra Connect Sync synchronisation on 30 September 2026 for any server below version 2.5.79.0, and 2.5.79.0 itself retires on 23 October 2026 - so the answer is to upgrade to the current version, not to that one. If your sync server is below it, directory sync stops before any Intune work begins, and this is more urgent than anything else on this form.

    Password hash sync / pass-through?
    Password writeback enabled?
  3. 17
    How are Windows devices joined today? Entra hybrid join rules out Autopilot device preparation and forces the classic Autopilot path. Entra join is the target for a cloud-native build.
    Roughly how it splits

    If a mixture, roughly what proportion of each?

  4. 18
    Are self-service password reset and Windows Hello for Business in use?
4

Current endpoint management

What Intune is replacing, sitting beside, or migrating from. A device can only have one MDM authority, so leaving the incumbent is real work - supervised iPhones and iPads in particular have to be wiped to move across, which makes it a user-impact conversation rather than a background task.

  1. 19
    What manages devices today?
    CategoryProductCovers which devicesStaying or retiring?
    MDM / UEM
    RMM
    Antivirus / EDR
    Configuration Manager
    Other
  2. 20
    Group Policy estate Intune's Group Policy analytics imports your GPO exports, reports which settings have a direct Intune equivalent, and can build a Settings Catalog policy from the supported ones - so the migration is measured rather than guessed. Export each GPO from the Group Policy Management console with Save report, as XML, under 4 MB each.
    Roughly how many GPOs?
    Can you export them to XML?
    Anyone who knows what they do?
    Login scripts / mapped drives in use?
  3. 21
    Is Configuration Manager in play, and in what mode?
    What that involves
    Where Global Administrator is still required

    Enabling tenant attach or co-management requires a one-time sign-in with a Global Administrator account in the Cloud Attach wizard. Microsoft states plainly that this feature requires the role and that no lesser role can be used. If either is in scope, that single action is the one place the "nobody holds standing Global Administrator" rule has to bend.

    It is genuinely one-off: Microsoft's own documentation says you sign in once for the purposes of the wizard and the credentials are not stored or reused elsewhere. It can be done under an approved change with the account secured again immediately afterwards, and it does not need to be us who performs it. Enabling co-management also needs Configuration Manager Full Administrator across all scopes, which is usually a different person.

    Who would perform that one-time sign-in?
    How is the account secured afterwards?
5

Device inventory

Approximate counts are fine. Platform mix drives the enrolment work far more than total headcount does.

  1. 22
    Device counts by platform and ownership Tick the platforms you actually have first. Everything further down the form that only applies to a platform you do not use will stay hidden, so you answer less and print less.
    PlatformCompany-ownedPersonal (BYOD)Oldest OS version in groupNotes
    Windows 11 Pro
    Windows 11 Enterprise
    Windows 10 (any edition)
    macOS - Apple silicon
    macOS - Intel
    iPhone / iPad
    Android
    Shared / kiosk / frontline
    Windows Server (not Intune-managed)
    What changes scope

    Windows 10 reached end of support on 14 October 2025. For most devices there is no free extended support phase, so they need paid Extended Security Updates or replacement - but Cloud PCs and Azure VMs get ESU at no extra cost, and so does a physical PC used to reach a Windows 365 Cloud PC - provided it is Entra joined or Entra hybrid joined, the user signs in at least once every 22 days, and an Intune policy flag is set. Entra registered or domain-joined-only devices do not qualify. Tell us if you have Windows 365 (item 12) before anyone buys ESU. ESU is cumulative and the price doubles each year to a maximum of three years, and only devices already on version 22H2 qualify, so anything still on 21H2 or older has to be updated to 22H2 first.

    Intel Macs: macOS 26 Tahoe is the last release that runs on Intel, and only four Intel models can run it. macOS 27 Golden Gate, due 14 September 2026, is Apple silicon only.

    OS version changes what Intune guarantees, not whether a device can enrol. Intune fully supports the three most recent releases of a platform. Below that a version is “allowed”: it still enrols and still gets eligible features, with no guarantee it behaves as expected, and Microsoft does not recommend running on it. Intune blocks nothing on version alone - a hard floor is an enrolment restriction you choose to set, which is what item 27 asks about. macOS support today is 14 and later; when macOS 27 ships that becomes 15. iOS/iPadOS support today is 17 and later; when iOS 27 ships that becomes 18. Android support is 10 or later for user-based management and 8 or later for userless, and Microsoft retires one or two versions each October until only the latest four remain.

  2. 23
    Hardware procurement Whether devices arrive pre-registered decides how much of the build is zero-touch. Classic Autopilot needs a hardware hash or reseller registration before the device ships; Autopilot device preparation needs no registration at all.
    Who buys hardware?
    Which reseller / vendor?
    Standard models?
    Refresh cycle
    Point-of-purchase registration

    Can your reseller register new devices to your tenant at point of purchase, and enrol Apple devices into Apple Business (or Apple School Manager)?

6

Enrolment prerequisites

These are the external accounts and certificates without which enrolment simply cannot be configured. They also have owners and expiry dates that become operational risk.

  1. 24
    Apple estate prerequisites The push certificate and both tokens expire 365 days after they are created, and each is tied to the Apple account that created it. The push certificate has a 30-day grace period and must be renewed with the same account. If nobody can sign in to that account you cannot renew it - Apple can sometimes migrate an existing certificate to a different account, and if the certificate ends up having to be replaced rather than renewed, every Apple device has to be wiped and re-enrolled. Microsoft's guidance is to own these with a company address on a mailbox more than one person monitors, never a personal Apple ID.
    ItemExists?Owned by (account)Shared mailbox?Expiry
    Apple Business account (called Apple Business Manager until April 2026)
    Apple MDM Push Certificate
    Automated Device Enrolment (ADE) token (the .p7m enrolment program token)
    Apps and Books content token (a location token in Apple Business; still labelled "Apple VPP token" in Intune)

    How should company-owned Apple devices authenticate during Setup Assistant? This has to be decided before the build - changing an enrolment policy afterwards means factory-resetting every assigned device.

    Are there existing Apple ADE enrolment profiles in the tenant? The current experience is Enrollment program tokens > Enrollment policies; anything still under > Profiles is the older experience, which Microsoft will retire.

  2. 25
    Android prerequisites

    Which Android modes do you need? (Personally-owned work profile, corporate-owned work profile, fully managed, dedicated/kiosk, or AOSP for devices with no Google services - common on rugged and warehouse hardware, and enrolled one device at a time)

    Do any Android devices lack Google Mobile Services (rugged scanners, warehouse handsets)?

    Dates to know about
    Three Android changes inside a typical project window

    By 31 October 2026 - Intune will be enforcing Google Play's Strong Integrity check. An Android 13 or later device that has not had a security update in the past twelve months stops meeting it, so those devices start failing compliance and app protection checks. If you have older handsets, tell us now rather than at go-live.

    Personally-owned work profile is moving to Google's Android Management API. Three consequences worth knowing before we design anything: enabling web-based enrolment is tenant-wide and cannot be reversed; devices using a username and password for Wi-Fi lose Wi-Fi during migration unless certificate-based Wi-Fi is in place first (see items 34 and 36); and the Microsoft Intune app replaces Company Portal as what users see, which changes the branding in item 41.

    It also changes what item 27 can promise. The restriction that blocks personally-owned Android at enrolment does not apply to devices once they move to the new API, and Microsoft will remove the setting entirely when every device has moved. It still works today, but we should not design around it - if you want personal Android devices kept out for the long term, we do it by allowing only named groups, or by using corporate-owned work profile instead.

  3. 26
    Windows provisioning Autopilot device preparation is the simpler modern path but supports Microsoft Entra join and Windows 11 only, and needs no hardware hashes. Classic Autopilot is still required for hybrid join, self-deploying kiosks, Autopilot Reset, the pre-provisioned technician flow, Autopilot for existing devices, a blocking setup screen at first sign-in (item 27), and any Windows 10 device. Neither is being retired - they run side by side, and the answers below decide which path each group of devices takes.

    How do the Windows devices you already own get to Intune - migrated in place, or replaced as they come up for refresh? This is usually the single largest work item in the whole project and it is easy to leave undecided.

    Device naming convention?
    Should users be local admin?
  4. 27
    Enrolment restrictions Decides whether personal devices can enrol, and what a user sees if they try. Microsoft is explicit that enrolment restrictions are not a security feature - they are a best-effort barrier for non-malicious users, and a compromised device can misrepresent itself. Blocking personally-owned Windows needs those devices recognised as corporate another way, by serial or model identifiers, because Autopilot device preparation uses no hardware hashes. The per-user device limit does not apply to Entra-joined, Autopilot, co-managed, GPO or device enrolment manager enrolments - those are limited in Entra device settings instead.

    Should users be shown a setup progress screen that blocks desktop access until apps and policies land? This is the Enrollment Status Page, and it exists only on classic Autopilot - Autopilot device preparation does not use it, so answering yes here pushes the Windows build towards classic.

7

Security & compliance

  1. 28
    What compliance obligations apply? Regulatory requirements and cyber-insurance questionnaires set hard minimums for encryption, MFA, patch windows and logging. They are also the usual reason a project has a deadline.
    What is driving it
  2. 29
    Disk encryption today If devices are already encrypted with keys held elsewhere, we need an escrow plan. BitLocker keys escrow to Entra ID. FileVault keys escrow to Intune, not Entra, and admins can see them only on devices marked corporate. An already-encrypted Mac does not need decrypting - Intune takes over after its FileVault policy applies, with the user either uploading the existing key through the Company Portal or generating a new one on the device.
    Windows
    BitLocker on Windows?
    Macs
    FileVault on macOS?
    Where are recovery keys held?
    Anyone able to test a recovery?
  3. 30
    Local administrator rights on end-user devices This is usually the most politically difficult change in an Intune rollout. Windows LAPS manages and rotates the password for one local admin account per device - the built-in one by default, or a named account - and needs only Intune Plan 1 and Entra ID Free. Endpoint Privilege Management allows specific elevations without standing rights, and is a paid add-on through Intune Suite, standalone, or included in Microsoft 365 E5 from July 2026 - see the rollout note in item 12.
    What needs elevation

    Are there applications or roles that genuinely require elevation to work? List them.

  4. 31
    How strict should the security baseline be? These are Microsoft's own published protection and configuration levels, so your answer maps to a documented policy set rather than a bespoke tier. There is a real trade-off between hardening and user friction, and choosing deliberately now avoids relaxing settings reactively later, which is how baselines rot. Level 3 is where LAPS, Endpoint Privilege Management and certificate-based authentication sit, so this answer largely settles items 30 and 34 too. Note that Level 3 relies on Endpoint Privilege Management, which is a paid add-on - if you are on Business Premium it is not included.
    Which groups get what
    Device controls
    Block USB / removable storage?
    Already onboarded to Intune?
    Are devices managed by another MDM today that we would migrate off? Onboard devices to Microsoft Defender for Endpoint as part of this build? Use Endpoint Privilege Management, so standard users can elevate approved apps without holding local admin rights?
8

Applications

Application packaging is usually the largest single block of effort. The more complete this list, the more accurate the estimate.

  1. 32
    Line-of-business and third-party applications For each: how it installs, how it is licensed, and whether it installs per-machine or per-user. Anything needing a licence server, dongle or on-premises connection is a scope flag.
    ApplicationInstaller typeLicensing / activationWho needs itBusiness critical?

    Continue on a separate sheet or spreadsheet if the list is long - a spreadsheet is preferred for more than about fifteen applications.

  2. 33
    Standard software and platform choices
    Microsoft 365 Apps update channel
    Any devices still on Semi-Annual Enterprise Channel? It merged into Monthly Enterprise Channel in July 2026 and its last build was supported only through 8 September 2026. Microsoft moves those devices automatically - no reinstall or policy change is needed - but we want to know they exist.
    Standard browser
    VPN client
    PDF / document tooling
    Printing - are the printers Universal Print ready, or is a connector host needed?
    Mapped drives / file shares still needed?
  3. 34
    Certificates and internal PKI Certificates for Wi-Fi or VPN can be issued three ways. Microsoft Cloud PKI issues them from Intune with no on-premises servers, connector or certificate authority at all, and is included in Microsoft 365 E5 from July 2026, or can be bought standalone or with Intune Suite - check the rollout note in item 12. SCEP through the Intune Certificate Connector needs an on-premises certificate authority and NDES; PKCS needs the certificate authority but not NDES. Only those last two are real infrastructure work, so the first thing to establish is whether you already own Cloud PKI.
    How many devices will hold certificates?
9

Network

  1. 35
    Is there a proxy or TLS/SSL inspection on outbound traffic? This is the single most common cause of enrolment failing silently. Intune, Autopilot, Defender for Endpoint, Endpoint Privilege Management and Microsoft Store endpoints must all be excluded from inspection, and the firewall team needs a maintained allow list. Note the old PowerShell scripts and the Microsoft 365 endpoint web service no longer return accurate Intune endpoints - Microsoft's consolidated endpoint list is now the only correct source. Device health attestation endpoints matter too and fail quietly - inspect those and Windows devices silently drop out of compliance rather than failing to enrol. The proxy also has to allow byte-range and partial HTTP responses, or app and script delivery breaks with no obvious error.
    Who changes it
    Firewall / filtering product
    Who can make firewall changes?
    Change lead time
    Guest / staff network separation?
  2. 36
    Wi-Fi and connectivity
    Corporate SSID name(s)
    Authentication type
    RADIUS / NPS server?
    Bandwidth at the smallest site

    Any site with poor connectivity where a first-boot provisioning download would be painful?

10

Updates & patching

  1. 37
    How are updates handled today, and what should change?
    Current patching tool
    Is WSUS still in use?
    Maintenance windows
    Reboot tolerance
    Target Windows feature version
    Third-party app patching expected?
    Driver and firmware updates

    Are there devices that must never auto-reboot (clinical, production line, reception, kiosk)?

  2. 38
    Do you want Windows Autopatch to manage OS and Microsoft app updates? Windows Autopatch manages Windows quality and feature updates, driver and firmware updates, and Microsoft 365 Apps, Edge and Teams through Autopatch groups and update rings. It also delivers hotpatch updates on Windows 11 24H2 and later, which deliver security fixes without a restart for eight months of the year - the other four are quarterly baseline months (January, April, July and October) that do require one. It needs virtualisation-based security enabled, and on Arm64 devices it also needs CHPE disabled. Intune update rings are now managed inside Autopatch rather than beside it, so the real question is how much ring design you want hand-tuned, not whether to use Autopatch. It needs Business Premium, E3, E5, F3 or A3 and above - Business Standard and Basic do not qualify.
11

End-user experience & support

  1. 39
    How does support work today, and who does what after go-live?
    Helpdesk / ticketing system
    Who handles first-line?
    Remote support tool in use
    Support hours
    Who provisions a new starter's device today?
    Remote vs onsite staff split
  2. 40
    Onboarding and offboarding process Device provisioning and wipe-on-exit should hook into whatever HR process already exists rather than being a separate manual checklist.
    Devices shipped to home addresses?
    Typical new starters per month
  3. 41
    Company Portal branding and user communication On Android, the Microsoft Intune app is replacing Company Portal as what users actually see, so any printed guidance naming Company Portal will need revising for that platform.
    Logo files available?
    Brand colour
    IT support contact to display
    Who writes user-facing comms?
12

Data & resilience

  1. 42
    Where does user data actually live? Before any device can be safely wiped or reset, user data has to be somewhere other than the device. OneDrive Known Folder Move is usually the prerequisite for the whole rollout.
    Endpoint backup product (if any)
    Retention or legal hold requirements
13

Timeline, constraints & success criteria

  1. 43
    Dates and constraints
    Target go-live
    What is driving that date?
    Blackout periods
    Change control process
  2. 44
    Pilot group A pilot of tolerant, representative users who cover the awkward cases - a Mac, a remote worker, someone with an unusual application - is worth more than a large pilot of easy cases.
  3. 45
    What does success look like? Written down now, this becomes the acceptance test at the end rather than a debate.
  4. 46
    Anything else we have not asked about? Known problems, past failed projects, internal politics, a system everyone is afraid to touch. These are the things that derail deployments, and they are never in an inventory.
14

Return & next steps

What happens after this comes back

  • We review the answers and confirm anything ambiguous in a short follow-up call.
  • You grant read-only access so we can validate the tenant against these answers rather than take them on trust. Intune's own Read Only Operator role is the right level and is consistent with the least-privilege model above. If you would rather grant a single directory role, Global Reader also works, but it reads the whole tenant rather than only Intune, so we would ask for it time-boxed and removed when the assessment is done.
  • We return a design covering the RBAC model, enrolment method, policy baseline, application approach and a phased rollout plan with acceptance criteria per phase.
  • Nothing is changed in your tenant until that design is signed off.
Completed by
Role
Date

Finished?

Press Send and your answers go to Orlando IT Services. A copy is emailed to the address in Your email at the top of this form. Prefer not to send? Use Print / Save as PDF instead and return it yourself.