Choose between Basic Mobility and Security and Intune - Microsoft 365 admin (2024)

  • Article

Microsoft Intune is a standalone product included with certain Microsoft 365 plans, while Basic Mobility and Security is part of the Microsoft 365 plans.

Availability of Basic Mobility and Security and Intune

Both Basic Mobility and Security and Intune are included in various plans, described in the following table.

PlanBasic Mobility and SecurityMicrosoft Intune
Microsoft 365 AppsYesNo
Microsoft 365 Business BasicYesNo
Microsoft 365 Business StandardYesNo
Office 365 E1YesNo
Office 365 E3YesNo
Office 365 E5YesNo
Microsoft 365 Business PremiumYesYes
Microsoft 365 Firstline 3YesYes
Microsoft 365 Enterprise E3YesYes
Microsoft 365 Enterprise E5YesYes
Microsoft 365 Education A1YesYes
Microsoft 365 Education A3YesYes
Microsoft 365 Education A5YesYes
Microsoft IntuneNoYes
Enterprise Mobility & Security E3NoYes
Enterprise Mobility & Security E5NoYes

Note

You can't start using Basic Mobility and Security if you're already using Microsoft Intune.

For details, see Microsoft 365 and Office 365 platform service descriptions.

Differences in capabilities

Microsoft Intune and built-in Basic Mobility and Security both give you the ability to manage mobile devices in your organization, but there are key differences in capability, described in the following table.

Note

You can manage users and their mobile devices using both Intune and Basic Mobility and Security in the same Microsoft 365 Business Standard organization by setting up Basic Mobility and Security first, and then adding Microsoft Intune. This allows you to choose Basic Mobility and Security or the more feature-rich Intune solution. Assign an Intune license to enable the Intune features.

Feature areaFeature highlightsBasic Mobility and SecurityMicrosoft Intune
Device typesManaging different OS platforms and major management mode variants.Windows
iOS
Android
Android Samsung KNOX
Windows
iOS
Android
Android Samsung KNOX
mac OS, iPad OS
Device complianceSet and manage security policies, like device level PIN lock and jailbreak detection.Limitations on Android devices. See details.Yes
Conditional access based on device compliancePrevent noncompliant devices from accessing corporate email and data from the cloud.Not supported on Windows 10.
Limited to controlling access to Exchange Online, SharePoint Online, and Outlook.
Yes
Device configurationConfigure device settings (for example, disabling the camera)Limited set of settings.Yes
Email profilesProvision a native email profile on the device.YesYes
WiFi profilesProvision a native WiFi profile on the device.NoYes
VPN profilesProvision a native VPN profile on the device.NoYes
Mobile application managementDeploy your internal line-of-business apps and from apps stores to users.NoYes
Mobile application protectionEnable your users to securely access corporate information using the Microsoft 365 mobile app and line-of-business apps they know, while ensuring security of data by helping to restrict actions like copy, cut, paste, and save as, to only those apps managed approved for corporate data. Works even if the devices aren't enrolled to Basic Mobility and Security. See Protect app data using MAM policies.NoYes
Managed browserEnable more secure web browsing using the Edge app.NoYes
Zero touch enrollment programs (AutoPilot)Enroll large numbers of corporate-owned devices, while simplifying user setup.NoYes

In addition to features listed in the preceding table, Basic Mobility and Security and Intune both include a set of remote actions that send commands to devices over the internet. For example, you can remove Microsoft 365 data from an employee’s device while leaving personal data in place (retire), remove Microsoft 365 apps from an employee's device (wipe), or reset a device to its factory settings (full wipe).

Basic Mobility and Security remote actions include retire, wipe and full wipe. For more information on Basic Mobility and Security actions, see capabilities of Basic Mobility and Security.

With Intune you have the following set of actions:

For more information on Intune actions, see Microsoft Intune documentation.

Choose between Basic Mobility and Security and Intune - Microsoft 365 admin (2024)

FAQs

What's the difference between MDM for Office 365 and Microsoft Intune? ›

The main difference of MDM for Office 365 versus Intune is that Intune is not limited to Office 365-related scenarios. For most organizations, the management boundaries must expand to include all apps and data that can be exposed via AAD and all apps on devices that can use modern authentication.

What is the difference between mobile device management and Intune? ›

MDM is device centric, so device features are configured based on who needs them. For example, you can configure a device to allow access to Wi-Fi, but only if the signed-in user is an organization account. In Intune, you create policies that configure features & settings and provide security & protection.

What is basic mobility and Security? ›

The built-in Basic Mobility and Security for Microsoft 365 helps you secure and manage users' mobile devices such as iPhones, iPads, Androids, and Windows phones. You can create and manage device security policies, remotely wipe a device, and view detailed device reports.

Does 365 Business Basic include Intune? ›

Both Basic Mobility and Security and Intune are included in various plans, described in the following table.
...
Availability of Basic Mobility and Security and Intune.
PlanBasic Mobility and SecurityMicrosoft Intune
Microsoft 365 AppsYesNo
Microsoft 365 Business BasicYesNo
14 more rows
Feb 16, 2023

How do I choose MDM? ›

Here are 7 Factors you Must Consider While Choosing a Mobile Device Management (MDM) Solution
  1. Types of the devices supported. ...
  2. Security Management. ...
  3. Trial Period. ...
  4. App Management. ...
  5. Device Monitoring. ...
  6. Content Management. ...
  7. Support and Service Management.
Oct 25, 2018

Is Intune a full MDM? ›

Microsoft Intune is a cloud-based mobile device management (MDM) service that helps you manage and secure mobile devices used by your employees. With Intune, you can manage apps, devices, and data for your employees. You can also set up security policies to help protect your company's data.

Which activity cannot be carried out by Intune MDM administrators? ›

Intune admins can't see phone call history, web surfing history, location information (except for iOS 9.3 and later devices when the device is in Lost Mode), email and text messages, contacts, passwords, calendar, and cameral roll.

What is the difference between Endpoint management and MDM? ›

It is workable on network-connected devices whether employee-used, customer-used, or industrial-used. The biggest difference between EMM and MDM falls in device ownership - EMM is for Bring Your Own Device while MDM is for company-owned devices. This is brought by the management of apps and files.

How many devices can I manage with Intune? ›

You can register up to five devices.

What is the difference between mobility and security? ›

Mobility is barrier crossing. Security has to do with the ability or inability to cross barriers.

Is mobility a basic need? ›

Spatial mobility goes far beyond the issue of transport: Mobility is a basic prerequisite for the functioning of a market economy. We understand the term as including all types of mobility.

What kind of tool is Microsoft Intune? ›

Microsoft Intune is a cloud-based unified endpoint management (UEM) tool that aims to help organizations manage the mobile devices employees use to access corporate data and applications, such as email.

Which 365 licenses include Intune? ›

Microsoft 365 Enterprise includes Microsoft Intune.

What are the requirements for Intune? ›

Intune requires Android 8. x or higher for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies. This requirement does not apply to Microsoft Teams Android devices as these devices will continue to be supported.

What is the difference between Intune and Endpoint Manager? ›

Account editing: Microsoft Intune does not allow administrators to edit user accounts in the program's interface. Endpoint Manager allows users to manage accounts across its suite from its admin center.

What are the 4 levels of MDM? ›

The original four levels of MDM (straightforward, low, moderate, and high) have not changed for 2021.

What are the four types of MDM? ›

The four most common master data management implementation styles and architectures followed by companies are: 1) Registry style, 2) Consolidation style, 3) Coexistence style and 4) Transaction/Centralized style.

Should I use MAM or MDM? ›

MDM is ideal for complete control over a corporate device. However, MAM is often popular for bring-your-own-device (BYOD) environments where you only need control over company data and software assets.

What is Microsoft Intune called now? ›

Microsoft Intune new name. Effective October 12, 2022, Microsoft Intune becomes the name of the endpoint management family with the name Microsoft Endpoint Manager no longer being used.

What are the advantages of Intune? ›

Some of the key benefits of Microsoft Intune include the choice of multiple devices, unparalleled management of Office mobile apps, advanced endpoint analytics, data protection, automation, and self-service.

What is the difference between MDM System Center Configuration Manager and Intune? ›

Both solutions are parts of Microsoft Endpoint Manager – a single, integrated platform for managing all the endpoints in the organization. Intune is a cloud-based solution that allows you to manage company-owned and personal devices, while SCCM is a more traditional on-premises solution.

Can MDM see your screen? ›

No, not generally. Most MDM solutions only track and monitor the apps installed on a device, not its web browsing history.

Can Intune track personal data? ›

Your organization can't see your personal information when you enroll a device in Microsoft Intune. Enrolling your device makes certain information, such as device model and serial number, visible to IT administrators and support people with administrator access.

How do I give admin access to Intune? ›

Sign in to the Microsoft Intune admin center with a global administrator account > Users > then choose the user you want to give admin permissions. Select Assigned roles > Add assignments. In the Directory roles pane, select the roles you want to assign to the user > Add.

Why choose MDM? ›

MDM keeps your business data protected and ensures your company retains control over confidential information. If a mobile device is lost or stolen, MDM can remotely lock and wipe all data. Remote locking and wiping capabilities enable companies to keep devices and data secure.

Is MDM part of IAM? ›

MDM is an important component of IAM because MDM allows security and the ability to provision apps to the device. MDM works in conjunction with IAM to help protect each device and therefore create security for the user.

What are two benefits of using an MDM solution? ›

5 Key Benefits of Mobile Device Management Software
  • Reduce IT Administration. Most IT departments are drowning in service requests and project ideas. ...
  • Improve End-user Productivity. ...
  • Reduce IT Risk. ...
  • Optimize Mobile Device Spending. ...
  • Enable Enterprise Growth.

How do I know if my machine is managed by Intune? ›

How to Confirm a Device Is Enrolled in Intune
  1. Click Start on your Windows device.
  2. Click on Settings.
  3. Click Accounts.
  4. Click Access work or school.
  5. Click Connected to MESA AD domain then click Info. Note: If the Info button does not appear on your device, your device has not been successfully enrolled.
Mar 2, 2021

Can Intune and SCCM be used at the same time to manage devices? ›

Co-management enables you to concurrently manage Windows 10 or later devices by using both Configuration Manager and Microsoft Intune. It lets you cloud-attach your existing investment in Configuration Manager by adding new functionality.

Do I need an Intune license for every device? ›

Each device that accesses and uses the online services and related software (including System Center software) must have a device license available in the Microsoft 365 tenant. If a device is used by more than one user, each device requires a device based software license or all users require a user software license.

What are the 3 general kinds of security? ›

There are three main types of IT security controls including technical, administrative, and physical. The primary goal for implementing a security control can be preventative, detective, corrective, compensatory, or act as a deterrent.

What are the three types of security system? ›

There are three primary areas or classifications of security controls. These include management security, operational security, and physical security controls.

What are the three major types of security? ›

What are the Types of Security? There are four main types of security: debt securities, equity securities, derivative securities, and hybrid securities, which are a combination of debt and equity.

What are 3 benefits of mobility? ›

The benefits of mobility training are plentiful:

Helps prevent knots and injuries. Relieves tension associated with sedentary lifestyles or over-exercising. Improves all-round functional fitness performance. Increases range of movement, helping us stay active and healthy longer in life.

What are the three components of mobility? ›

The three main areas of functional mobility are the following:
  • Bed Mobility : The ability of a patient to move around in bed, including moving from lying to sitting and sitting to lying.
  • Transferring : The action of a patient moving from one surface to another. ...
  • Ambulation : The ability to walk.

How many users require mobility? ›

An estimated 5.5 million people, or 2.3% of the United States adult population, uses a wheelchair for mobility. Adults greater than age 65 are four times more likely to use a wheelchair.

Who uses Microsoft Intune? ›

Companies Currently Using Microsoft Intune
Company NameWebsiteHQ Address
Kulicke & Soffakns.com23A Serangoon North Avenue 5 #01-01
Wantablewantable.com112 E Mineral St
Zurich NAzurich.comCorporate Center, Mythenquai 2
MNS Engineers Inc.mnsengineers.com201 N Calle Cesar Chavez, Ste 300
2 more rows

Is Microsoft Intune a monitoring tool? ›

In Intune, you can create a Windows Health Monitoring device configuration profile to enable this data collection, and then deploy this profile to your devices. Use this profile as part of your mobile device management (MDM) solution to optimize your Windows devices.

What is the difference between Azure and Intune? ›

Azure Active Directory (Azure AD) is a universal identity management platform that incorporates user credentials and strong authentication policies to safeguard your company's data, while Microsoft Intune provides cloud-based mobile device management (MDM) and mobile application management (MAM).

Can I use Intune without Office 365? ›

Microsoft Intune capabilities. Microsoft Intune is a UEM platform that provides MDM and MAM functionality and comes with additional costs, as it's not part of the different Office 365 subscriptions. It requires an organization to have licenses that include the rights to use Microsoft Intune.

What is the difference between Office 365 and Microsoft 365 license? ›

Office 365 is a cloud-based suite of productivity apps like Outlook, Word, PowerPoint, and more. Microsoft 365 is a bundle of services including Office 365, plus several other services including Windows 10 Enterprise.

How many licenses does Microsoft 365 have? ›

With Microsoft 365, you can install Office on all your devices and sign in to Office on five devices at the same time. This includes any combination of PCs, Macs, tablets, and phones.

Does Intune administrator need a license? ›

You can give administrators access to Microsoft Intune without them requiring an Intune license. This feature applies to any administrator, including Intune administrators, global administrators, Azure AD administrators, and so on.

Who needs an Intune license? ›

First, all users that are required to have their devices managed must have an Intune subscription via a standalone license or another license that includes Intune.

Does Intune include antivirus? ›

You can use Intune to manage tamper protection on Windows devices as part of Windows Security Experience profile (an Antivirus policy). This includes both devices you manage with Intune, and devices you manage with Configuration Manager through the tenant attach scenario.

What is the difference between Windows Admin Center and Intune? ›

Intune focuses on enabling you to secure company information by controlling how your workforce accesses and shares information. In contrast, Windows Admin Center is not policy-driven, but enables ad-hoc management of Windows 10 and Windows Server systems, using remote PowerShell and WMI over WinRM.

Why would a company choose to use Microsoft Intune? ›

Intune can isolate organization data from personal data. The idea is to protect your company information by controlling the way users access and share information. For organization-owned devices, you want full control over the devices, especially security.

What are the disadvantages of using Microsoft Intune? ›

  • Intune CONS :
  • * Narrow focus on mobile devices; not a full systems-management platform.
  • * Doesn't support server-side applications.
  • * Not intended for large applications.
  • * Doesn't have the feature-set to handle complex package deployments.

How do I change my Office 365 MDM to Intune? ›

Add Intune MDM authority
  1. Sign in to the Microsoft Intune admin center with Azure AD Global or Intune service administrator rights.
  2. Navigate to Devices.
  3. The Add MDM Authority blade displays.
  4. To switch the MDM authority from Office 365 to Intune and enable coexistence, select Intune MDM Authority > Add.
Mar 5, 2023

What is the MDM for Office 365? ›

The built-in Mobile Device Management (MDM) for Office 365 helps you secure and manage your users' mobile devices like iPhones, iPads, Androids, and Windows phones. You can create and manage device security policies, remotely wipe a device, and view detailed device reports.

What is MDM with Intune? ›

What is Microsoft Intune Mobile Device Managment (MDM) ? Microsoft Intune provides mobile device management, mobile application management, and PC management capabilities from the cloud.

Do you need Configuration Manager with Intune? ›

One advantage of Configuration Manager is that it manages Windows servers. There is no equivalent (yet) in Microsoft Intune. For those with a heavy server footprint, Configuration Manager may need to be part of your device management strategy.

What is the difference between Endpoint Management and MDM? ›

It is workable on network-connected devices whether employee-used, customer-used, or industrial-used. The biggest difference between EMM and MDM falls in device ownership - EMM is for Bring Your Own Device while MDM is for company-owned devices. This is brought by the management of apps and files.

How do I change my Microsoft 365 admin status? ›

In the Yammer admin center, click admins. In the row for the admin, select Change status of Microsoft 365 Admins. This takes you to the Microsoft 365 page where the role can be changed.

How do I check MDM authority in Office 365? ›

First, you need to login into the Azure Intune Admin console. Once you have logged in, select the Apps option from the left panel in the Intune Admin Portal. Once you click on the App option, MDM Authority is shows Microsoft 365 Authority instead of Microsoft Intune.

How do I check my MDM policy in Office 365? ›

Go to Microsoft 365 admin center > Groups, and then select group name. Select Edit members and admins. - Remove the security group the users are a member of from the device policy. Go to Security & Compliance Center > Security policies > Device security policies.

What are the two core functions of Microsoft's MDM app Intune? ›

Over the years, Microsoft Intune has evolved into a cross-platform tool for managing devices and apps. The most important features and capabilities include the following: Manage personally owned and company-owned devices of the most common platforms and provide secure access to company data on those devices.

Should I allow an MDM? ›

The most important reason to put MDM in place is to ensure your network isn't breached via a mobile device. If you allow employee devices to connect to your network without any type of monitoring in place, you leave yourself open to all kinds of attacks, including ransomware, spyware, and insider breaches.

Is Intune included in E3? ›

Microsoft Intune Plan 1

A cloud-based unified endpoint management solution that is included in the following licenses: Microsoft 365 E5. Microsoft 365 E3.

Is MDM the same as CRM? ›

CRM is different from MDM since it supports business functions such as sales and service versus prioritizing the technology to perform data management. With CRM, one is managing the processes and lifecycle from prospect to purchase, service, may be an initial or first significant step into that style of solution.

Top Articles
Latest Posts
Article information

Author: Amb. Frankie Simonis

Last Updated:

Views: 6296

Rating: 4.6 / 5 (56 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Amb. Frankie Simonis

Birthday: 1998-02-19

Address: 64841 Delmar Isle, North Wiley, OR 74073

Phone: +17844167847676

Job: Forward IT Agent

Hobby: LARPing, Kitesurfing, Sewing, Digital arts, Sand art, Gardening, Dance

Introduction: My name is Amb. Frankie Simonis, I am a hilarious, enchanting, energetic, cooperative, innocent, cute, joyous person who loves writing and wants to share my knowledge and understanding with you.