| Account / person | Role held | Why they have it | Type | Still needed? |
|---|---|---|---|---|
Endpoint Management Engagement
This captures the environment detail needed to design a Microsoft Intune deployment built on least-privilege administration. Answers drive the RBAC model, enrolment method, policy baseline and rollout sequence. Anything you leave blank becomes an assumption we have to validate later, which costs time.
Two answers change almost every downstream decision, so answer them first even if you skip the rest: your exact Microsoft 365 / Entra licence SKUs and counts (item 12) and whether on-premises Active Directory is still in the picture (item 15). Entra ID P1 on its own does not include Privileged Identity Management, and a hybrid-joined estate rules out the simpler Autopilot device preparation path.
The core of the engagement. The goal is that no person holds standing Global Administrator - including us. There are a small number of tasks Microsoft still gates behind that role; we name each one where it comes up rather than pretending it does not exist.
Microsoft's own guidance is stronger than most teams expect: don't use Global Administrator for Intune, and don't use the Intune Administrator Entra role for day-to-day work either. Daily tasks should run on Intune's own RBAC roles, scoped to specific groups of users and devices. These questions establish where you are now and what the target model looks like.
| Account / person | Role held | Why they have it | Type | Still needed? |
|---|---|---|---|---|
Is MFA enforced by Conditional Access policy, by Security Defaults, or per-user?
PIM needs Entra ID P2, Entra ID Governance or Microsoft Entra Suite. Microsoft 365 Business Premium includes Entra ID P1 only, so PIM is not included there - but it does not have to be bought for everyone. A licence is required only for admins with eligible assignments plus their approvers and reviewers, so a handful of seats can be enough, and check for Enterprise Mobility + Security E5, which carries P2. If PIM genuinely is not available that is workable - the model shifts to static scoped RBAC roles plus multi admin approval and a review cadence. Confirm your exact SKUs in item 12 either way.
| Person / team | Tasks they must be able to do | Which devices/users they cover |
|---|---|---|
Who would be the approver(s), and what is an acceptable turnaround? Approvers have to sit in a security group, directly assigned, with direct members only - other group types fail silently.
Which tools drive Intune through the Graph API today (RMM, scripts, reporting, third-party connectors)? Multi Admin Approval intercepts app-authenticated Graph calls too, so anything not explicitly excluded stops working the day it is switched on.
Administrator accounts do not need an assigned Intune licence in tenants created after July 2021, where unlicensed admin access is on by default. In an older tenant it has to be switched on manually, and that switch cannot be undone. Members of nested security groups still need a licence, and so by default does anyone taking part in multi admin approval. Tell us roughly when the tenant was created (item 13) and we will confirm before assuming our access is free.
Do routine changes - policy pushes, update-ring promotions, certificate rotations, co-management cutovers - have to land outside your working hours?
Licence SKUs decide which features exist at all. Getting this exactly right prevents designing around something you cannot use.
| Licence / SKU | Purchased | Assigned | Have it? |
|---|---|---|---|
| Microsoft 365 Business Premium | |||
| Microsoft 365 Business Standard / Basic | |||
| Microsoft 365 E3 | |||
| Microsoft 365 E7 | |||
| Microsoft 365 E5 | |||
| Microsoft 365 F1 / F3 | |||
| Intune Plan 1 (standalone) | |||
| Intune Plan 2 (add-on) | |||
| Intune Suite (add-on) | |||
| Microsoft Entra ID P1 | |||
| Microsoft Entra ID P2 | |||
| Enterprise Mobility + Security E3 / E5 (E5 carries Entra ID P2 - check which one) | |||
| Microsoft Entra Suite | |||
| Microsoft Entra ID Governance | |||
| Defender for Endpoint P1 / P2 | |||
| Defender for Business | |||
| Microsoft Cloud PKI (Intune Suite, standalone, or via E5) | |||
| Windows 365 / Cloud PC | |||
| Other (write in) |
Since July 2026 Microsoft has been rolling several advanced endpoint management capabilities into Microsoft 365 E3 and E5. E3 gains Remote Help, Advanced Analytics and the Intune Plan 2 capabilities; E5 additionally gains Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise App Management. Cloud PKI matters most - it removes the need for an on-premises certificate authority for device and user certificates (see item 34). Entitlement is rolling out rather than switching on everywhere at once, so tell us what your tenant actually shows under Intune add-ons before anyone buys anything.
Which Microsoft cloud is the tenant in?
In GCC High and DoD, Windows Autopilot is not available and there is no plan to add it, and Autopatch, Remote Help, Cloud PKI and device health attestation are not there yet. In 21Vianet there is no Android Enterprise or Google Play at all. There is no migration path between clouds in either direction, so if the answer is anything other than Commercial, most of sections 6, 7 and 10 have to be designed differently.
Whether on-premises Active Directory is still involved decides the device join model, and that decides everything about enrolment.
Entra Cloud Sync cannot synchronise devices, so it cannot support Entra hybrid join. If you need hybrid-joined Windows devices (item 17), Entra Connect Sync is the only option of the two. Please do not tick Cloud Sync and hybrid join together without telling us - that combination cannot be built.
AD FS in the picture usually means identity modernisation work happens before Intune work. Say so early - it changes sequencing, not just effort.
Microsoft stops all Entra Connect Sync synchronisation on 30 September 2026 for any server below version 2.5.79.0, and 2.5.79.0 itself retires on 23 October 2026 - so the answer is to upgrade to the current version, not to that one. If your sync server is below it, directory sync stops before any Intune work begins, and this is more urgent than anything else on this form.
If a mixture, roughly what proportion of each?
What Intune is replacing, sitting beside, or migrating from. A device can only have one MDM authority, so leaving the incumbent is real work - supervised iPhones and iPads in particular have to be wiped to move across, which makes it a user-impact conversation rather than a background task.
| Category | Product | Covers which devices | Staying or retiring? |
|---|---|---|---|
| MDM / UEM | |||
| RMM | |||
| Antivirus / EDR | |||
| Configuration Manager | |||
| Other |
Enabling tenant attach or co-management requires a one-time sign-in with a Global Administrator account in the Cloud Attach wizard. Microsoft states plainly that this feature requires the role and that no lesser role can be used. If either is in scope, that single action is the one place the "nobody holds standing Global Administrator" rule has to bend.
It is genuinely one-off: Microsoft's own documentation says you sign in once for the purposes of the wizard and the credentials are not stored or reused elsewhere. It can be done under an approved change with the account secured again immediately afterwards, and it does not need to be us who performs it. Enabling co-management also needs Configuration Manager Full Administrator across all scopes, which is usually a different person.
Approximate counts are fine. Platform mix drives the enrolment work far more than total headcount does.
| Platform | Company-owned | Personal (BYOD) | Oldest OS version in group | Notes |
|---|---|---|---|---|
| Windows 11 Pro | ||||
| Windows 11 Enterprise | ||||
| Windows 10 (any edition) | ||||
| macOS - Apple silicon | ||||
| macOS - Intel | ||||
| iPhone / iPad | ||||
| Android | ||||
| Shared / kiosk / frontline | ||||
| Windows Server (not Intune-managed) |
Windows 10 reached end of support on 14 October 2025. For most devices there is no free extended support phase, so they need paid Extended Security Updates or replacement - but Cloud PCs and Azure VMs get ESU at no extra cost, and so does a physical PC used to reach a Windows 365 Cloud PC - provided it is Entra joined or Entra hybrid joined, the user signs in at least once every 22 days, and an Intune policy flag is set. Entra registered or domain-joined-only devices do not qualify. Tell us if you have Windows 365 (item 12) before anyone buys ESU. ESU is cumulative and the price doubles each year to a maximum of three years, and only devices already on version 22H2 qualify, so anything still on 21H2 or older has to be updated to 22H2 first.
Intel Macs: macOS 26 Tahoe is the last release that runs on Intel, and only four Intel models can run it. macOS 27 Golden Gate, due 14 September 2026, is Apple silicon only.
OS version changes what Intune guarantees, not whether a device can enrol. Intune fully supports the three most recent releases of a platform. Below that a version is “allowed”: it still enrols and still gets eligible features, with no guarantee it behaves as expected, and Microsoft does not recommend running on it. Intune blocks nothing on version alone - a hard floor is an enrolment restriction you choose to set, which is what item 27 asks about. macOS support today is 14 and later; when macOS 27 ships that becomes 15. iOS/iPadOS support today is 17 and later; when iOS 27 ships that becomes 18. Android support is 10 or later for user-based management and 8 or later for userless, and Microsoft retires one or two versions each October until only the latest four remain.
Can your reseller register new devices to your tenant at point of purchase, and enrol Apple devices into Apple Business (or Apple School Manager)?
These are the external accounts and certificates without which enrolment simply cannot be configured. They also have owners and expiry dates that become operational risk.
| Item | Exists? | Owned by (account) | Shared mailbox? | Expiry |
|---|---|---|---|---|
| Apple Business account (called Apple Business Manager until April 2026) | ||||
| Apple MDM Push Certificate | ||||
| Automated Device Enrolment (ADE) token (the .p7m enrolment program token) | ||||
| Apps and Books content token (a location token in Apple Business; still labelled "Apple VPP token" in Intune) |
How should company-owned Apple devices authenticate during Setup Assistant? This has to be decided before the build - changing an enrolment policy afterwards means factory-resetting every assigned device.
Are there existing Apple ADE enrolment profiles in the tenant? The current experience is Enrollment program tokens > Enrollment policies; anything still under > Profiles is the older experience, which Microsoft will retire.
Which Android modes do you need? (Personally-owned work profile, corporate-owned work profile, fully managed, dedicated/kiosk, or AOSP for devices with no Google services - common on rugged and warehouse hardware, and enrolled one device at a time)
Do any Android devices lack Google Mobile Services (rugged scanners, warehouse handsets)?
By 31 October 2026 - Intune will be enforcing Google Play's Strong Integrity check. An Android 13 or later device that has not had a security update in the past twelve months stops meeting it, so those devices start failing compliance and app protection checks. If you have older handsets, tell us now rather than at go-live.
Personally-owned work profile is moving to Google's Android Management API. Three consequences worth knowing before we design anything: enabling web-based enrolment is tenant-wide and cannot be reversed; devices using a username and password for Wi-Fi lose Wi-Fi during migration unless certificate-based Wi-Fi is in place first (see items 34 and 36); and the Microsoft Intune app replaces Company Portal as what users see, which changes the branding in item 41.
It also changes what item 27 can promise. The restriction that blocks personally-owned Android at enrolment does not apply to devices once they move to the new API, and Microsoft will remove the setting entirely when every device has moved. It still works today, but we should not design around it - if you want personal Android devices kept out for the long term, we do it by allowing only named groups, or by using corporate-owned work profile instead.
How do the Windows devices you already own get to Intune - migrated in place, or replaced as they come up for refresh? This is usually the single largest work item in the whole project and it is easy to leave undecided.
Should users be shown a setup progress screen that blocks desktop access until apps and policies land? This is the Enrollment Status Page, and it exists only on classic Autopilot - Autopilot device preparation does not use it, so answering yes here pushes the Windows build towards classic.
Are there applications or roles that genuinely require elevation to work? List them.
Application packaging is usually the largest single block of effort. The more complete this list, the more accurate the estimate.
| Application | Installer type | Licensing / activation | Who needs it | Business critical? |
|---|---|---|---|---|
Continue on a separate sheet or spreadsheet if the list is long - a spreadsheet is preferred for more than about fifteen applications.
Any site with poor connectivity where a first-boot provisioning download would be painful?
Are there devices that must never auto-reboot (clinical, production line, reception, kiosk)?
Press Send and your answers go to Orlando IT Services. A copy is emailed to the address in Your email at the top of this form. Prefer not to send? Use Print / Save as PDF instead and return it yourself.