Courtier TI is not affiliated with Microsoft; the features described here come from Microsoft Learn public documentation, read on October 9, 2026. The Device management page covers the device lifecycle, whatever the tool; this one focuses on Intune: what to check on the licensing side, how devices enrol and what the company can see or do on a personal device.
Short answer
You describe your devices, your Microsoft licences and your rules for personal devices: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. Configuration, rollout and schedule are set with you.
What the quote should cover
- Verification of the Intune and Microsoft Entra ID licences already held
- The choice of enrolment methods by device type
- Configuration, security and update policies
- Handling of personal devices: enrolment or app protection only
- Configuration of phones and tablets
- Wipe and retire procedures
- A pilot group, documentation and training for the person in charge
The steps of an Intune project
- Inventory of devices, operating systems and licences
- Decisions: company devices, personal devices, rules per group
- Preparation: licences assigned, Apple certificate, user groups
- Creation of baseline policies and testing with a pilot group
- Device enrolment in waves
- Documentation, departure procedures and follow-up
Licences to check
According to the Microsoft Learn licensing page, Intune comes in three plans: Plan 1, the base service, then Plan 2 and the Intune Suite, which add to it. Microsoft states that Intune can be obtained as part of a Microsoft 365 bundle rather than bought on its own, and that a licence is required for any user or device that benefits from the service. So start by checking what your current plans include.
For devices with no assigned user, such as a kiosk or a shared tablet, Microsoft offers device-only licences; they do not support app protection policies or Conditional Access. Conditional Access, which is part of Microsoft Entra, requires Microsoft Entra ID P1 licences according to Microsoft's documentation.
Device enrolment
The Microsoft Learn enrolment guide explains that during enrolment, Intune installs a mobile device management (MDM) certificate that lets it enforce your policies: enrolment restrictions, rules to meet and configuration settings. Intune distinguishes personal devices from corporate-owned devices; the latter allow more granular settings.
iOS/iPadOS and macOS devices require an Apple MDM push certificate. Devices already enrolled with another management solution must be unenrolled from it. And depending on the platform and method chosen, a factory reset may be required before enrolment.
Personal devices: two approaches
An employee can enrol a personal device using the Company Portal app. It is also possible not to enrol the device and to apply only app protection policies: Microsoft gives as examples requiring a PIN or fingerprint to open work email, preventing users from copying corporate data into personal apps, and restricting that data to approved apps. Microsoft recommends combining them with Conditional Access.
Employee privacy is a central question. According to Microsoft's page on what your organization can see, the organization cannot see calling and web browsing history, email and text messages, contacts, calendar, passwords, pictures or the content of documents; it can see the device owner, name, model, serial number and operating system, among other things. It cannot see a personal device's location, and sees only the last four digits of its phone number.
The Canadian Centre for Cyber Security, in its publication on bring your own device (BYOD) deployment models (ITSM.70.003), recommends written policies, including an acceptable use policy signed by employees.
Phones and tablets
For Android, Intune distinguishes among others the work profile on a personal device, the fully managed corporate device and the dedicated single-purpose device. On a corporate-owned Android device with a work profile, the organization sees only the apps installed in that profile. For iPhones and iPads, Microsoft specifies that the Apple MDM push certificate must be renewed annually, with the same Apple account used to create it: that account should belong to the company, not to an employee or a vendor.
Device status rules and updates
Device compliance policies define the rules a device must meet. A device that does not meet them can be subject to actions: being marked noncompliant, receiving an email or being remotely locked. With Microsoft Entra Conditional Access, that status can block access to company resources from the device.
For Windows, update rings define how and when updates are installed, and are used to create deployment stages, for example test, pilot and production. According to Microsoft, they require Plan 1 and apply to Windows editions including Pro, Enterprise and Education.
Wipe or retire
Intune offers two separate actions. Wipe restores factory settings and removes all data, personal and organizational; it suits a company device that is lost, stolen or repurposed. Retire removes company data, managed apps and profiles while preserving personal data; Microsoft presents it as suited to personally owned devices.
The Centre notes for its part that a full wipe of a personal device requires the owner's consent. For a Windows computer encrypted with BitLocker, Microsoft recommends backing up the recovery key before retiring it.
Questions to ask yourself before requesting a quote
- Which Microsoft 365 plans do you have, and for how many users?
- How many computers, phones and tablets need to be managed?
- Do employees use their personal devices for work?
- Are your devices already managed by another tool?
- Who will receive alerts and manage devices day to day?
- Do you have a written policy on personal devices?
Pitfalls to avoid
- Assuming your current licences cover all planned features
- Enrolling personal devices without explaining to employees what the company can see
- Wiping a personal device instead of retiring it
- Letting the Apple MDM push certificate expire
- Applying every policy to everyone without a pilot group
- Retiring an encrypted computer without backing up its recovery key
What to specify in your request
- Your Microsoft 365 plans and number of users
- The number of devices by type and operating system
- The share of personal devices and your current rules
- The current management tool, if any
- The policies wanted: security, updates, apps
- The person responsible for management after rollout
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
Is Intune included in our Microsoft 365 licences?
It depends on the plan. Microsoft states that Intune can be obtained as part of a Microsoft 365 bundle, and that a licence is required for any user or device that benefits from the service. The quote should include a check of your current licences.
Can the company see my photos or messages on my personal phone?
According to Microsoft's documentation, no: the organization cannot see pictures, email, text messages or contacts. It sees information about the device, such as the model and operating system.
Do personal devices have to be enrolled?
Not necessarily. App protection policies protect company data in apps without requiring device enrolment.
What is the difference between wipe and retire?
Wipe restores factory settings and removes all data. Retire removes only company data and apps and keeps personal data; Microsoft presents it as suited to personally owned devices.
How is this different from device management?
Device management covers the whole device lifecycle, whatever the tool. This page focuses on Intune specifically.