← All services
Endpoint Management

Endpoint Management: Microsoft Intune & Configuration Manager

Intune managed properly and reported on honestly, alongside whatever Configuration Manager still owns, so you can prove the state of every device rather than assume it.

Overview

Know what your devices are running, not what a policy says

In short: Day-to-day Intune management plus the reporting layer Intune does not give you: what every device is actually running, whether policies landed, and evidence of patching you can hand an auditor. Covers Configuration Manager and co-management where an on-premises estate is still doing real work. For IT teams who cannot currently answer what state their devices are in.

Intune will tell you a policy is assigned. What it will not tell you, without a great deal of clicking, is whether your estate is actually in the state that policy describes, or was last Tuesday, or has been all quarter.

Who this is for
You cannot currently prove every device was patched inside the window an auditor or insurer asks about
Devices show as compliant and you are not confident that means what it says
You are running Configuration Manager and being told to move to Intune, with no plan
Nobody owns the endpoint estate day to day, so policies accumulate and nothing gets retired

The problem

An endpoint estate nobody reports on drifts quietly. Policies stack up until no one knows which one is winning, devices fall out of compliance without anyone noticing because nothing is watching the trend, and the first time the gap becomes visible is when a certification body, an insurer or an incident asks a question that has to be answered with evidence rather than intent.

What we would do

Fix the reporting before you change anything else. Until you can see what is genuinely deployed, patched and compliant across the estate, every other decision is being made on assumption. It is also the cheapest stage, and it often shows the estate is in better shape than feared.

  • If Configuration Manager is doing work Intune genuinely cannot do yet, co-manage rather than migrate. Moving workloads one at a time is supported, reversible and much safer than a cutover.
  • If devices are unmanaged rather than badly managed, enrolment comes first and reporting follows it, because there is nothing to report on yet.
  • If a certification deadline is driving this, do the patching evidence first and the rest afterwards. It is the control most likely to fail and the slowest to fix retrospectively.

When we are not the answer: If you want someone to take Intune off your hands and send you a monthly ticket count, cheaper options exist. This is for teams who want to know the real state of their estate, which means we will show you things you would rather were not true.

How we help

We manage Microsoft Intune day to day: enrolment and Autopilot provisioning, configuration and compliance policies, application deployment, update rings and the ongoing work of keeping all of it coherent as the estate changes. Where Configuration Manager is still doing real work, we run that alongside it under co-management rather than treating it as something to be removed on principle.

More on how we deliver endpoint management

What we lead with is reporting, because it is where most estates are genuinely blind. Intune is a good management plane and a frustrating reporting one: it answers questions about an object well and questions about an estate over time poorly. So we put a reporting layer over it that shows what is deployed, what is patched, what has drifted and what you can put in front of an auditor, which changes endpoint management from a set of assumptions into something you can evidence.

The estate-wide Intune reporting behind this service is delivered with EtherInsights from our partner EfficientEther, which is what lets us answer questions about an estate over time rather than a device at a moment.

Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.

Retro pixel-art illustration of a row of managed devices reporting to a central console, in the style of a classic arcade status screen
What's included

Everything you need, managed for you

Microsoft Intune management: policies, compliance, applications and update rings
Estate-wide Intune reporting, including evidence of patching over time rather than at a moment
Autopilot provisioning, so a replacement device is a delivery rather than a build
Configuration Manager management, co-management and workload migration at your pace
Compliance evidence mapped to what Cyber Essentials and insurers actually ask for
Policy rationalisation, because most estates have accumulated conflicting policies nobody retired
Application deployment, including the packaging work when an application resists it

Why is Intune reporting the part everyone struggles with?

Because Intune is built to manage objects and most of the questions you actually get asked are about estates over time. Those are different problems, and the console is good at the first one.

Ask whether a specific device is compliant and Intune answers immediately. Ask whether every device in the business received a critical update inside fourteen days, every month, for the last quarter, and you are into exports, manual joining and a spreadsheet, which is precisely the position the certification was supposed to move you out of.

The specific questions that turn out to be hard:

  • What is actually installed across the estate, as opposed to what was deployed to it
  • Which devices have not checked in recently enough for their compliance state to mean anything
  • Why a policy shows as applied on a device that is visibly not in that state
  • What changed between last month and this month, and who changed it
  • Which of several overlapping policies is the one actually winning on a given setting
  • Evidence of a control holding continuously, rather than a screenshot of it holding today

None of this means Intune is the wrong product. It means the reporting layer is a separate job, and treating it as one is the difference between an estate you manage and an estate you can account for.

What does compliant actually mean in Intune?

It means the device met the conditions in the compliance policies assigned to it, at the last time it checked in and reported. Each part of that sentence is a place the answer can quietly stop being true.

The most common trap is staleness. A device that has not checked in for weeks can still show its last known state, so an estate that looks healthy may partly be an estate that has stopped talking. Any reporting worth trusting starts by separating devices that are compliant from devices that are merely quiet.

The second trap is that a compliance policy only checks what you asked it to. A tenant configured years ago against the threats of the time can report a fully compliant estate while never evaluating the controls anyone would ask about now, which is a reporting result rather than a security one.

The third is scope. Devices that were never enrolled do not appear as non-compliant, they simply do not appear, and unmanaged devices are the ones most likely to be a problem. A compliance figure is only meaningful next to an honest count of what should be enrolled, which is why we reconcile against identity sign-ins rather than trusting the device list on its own.

Should we move from Configuration Manager to Intune?

Eventually, probably, and rarely as a single project with a date on it. The framing that causes damage is treating this as a migration with a cutover, because it turns a manageable sequence of reversible steps into one event with a rollback nobody has tested.

Co-management is the supported route and it is deliberately incremental: Configuration Manager and Intune manage the same devices at once, and individual workloads move across one at a time, at your pace. Compliance policies, device configuration, Windows Update policies, endpoint protection, resource access and client applications can each shift independently, and each can shift back.

That structure means you can move the workloads with clear benefit early, leave the ones Configuration Manager still does better, and stop wherever the value runs out. Plenty of estates settle permanently in a mixed state and are correct to.

Where Configuration Manager still earns its place:

  • Complex application deployment with sequencing, dependencies and detection logic built over years
  • Operating system deployment through task sequences, particularly for specialised builds
  • Estates with real bandwidth constraints, where local content distribution genuinely matters
  • Servers and anything on-premises that Intune was never designed to manage
  • Reporting somebody has already built against the database and depends on

The honest test is not whether Intune can do a thing, it is whether doing it in Intune is better for you than the working arrangement you already have. We will tell you when the answer is no.

How do you prove devices are patched?

With a record over time rather than a screenshot, and this is the control most likely to fail an assessment because it is the hardest to reconstruct after the fact.

Cyber Essentials requires that critical and high-severity updates are applied within fourteen days of release, and an assessor will want to see that this held rather than that it holds today. Insurers ask the same question in different words, and so does anyone doing supply chain due diligence on you.

Intune manages the updates well through update rings and deferral settings. What it does not do easily is produce the historical evidence, so the practical answer is a reporting layer that keeps the record continuously: what was released, when it reached the estate, what did not take it, and what was done about the exceptions.

Exceptions are the part worth designing for rather than hiding. There is always a device that was off for a month, a machine that cannot take an update because of an application on it, and a build that fails for its own reasons. An assessor is far more comfortable with a documented, managed exception than with a report showing a hundred per cent that nobody believes.

What does day-to-day endpoint management actually involve?

Mostly it is the unglamorous work of keeping an estate coherent while it changes, which is why it degrades so reliably when nobody owns it.

The recurring work:

  • Provisioning, so a new or replacement device arrives configured rather than being built by hand
  • Application packaging, deployment and the updates that follow, including the applications that resist both
  • Update rings maintained deliberately, with a pilot group that is genuinely representative
  • Policy hygiene, retiring what is superseded so that conflicting settings do not accumulate
  • Watching the reporting for drift, which is the difference between managing and reacting
  • Retirement and wipe when people leave, which is an access control matter as much as a device one

The item that surprises people is policy hygiene. Estates rarely suffer from a lack of policy, they suffer from years of accumulation: overlapping assignments, settings applied twice with different values, and configurations created for a project that finished. Nothing announces it, and the symptom is an estate where changes do not produce the results anyone expects.

Where does endpoint management meet security and certification?

At almost every control anybody asks you about, which is why endpoint management is usually the fastest route to a better security position rather than a separate exercise.

Of the five Cyber Essentials control themes, endpoint management directly delivers secure configuration, security update management and malware protection, and carries a substantial part of user access control through device compliance and Conditional Access. That is most of the scheme, done through one management plane.

The relationship runs the other way too. Conditional Access decisions are only as good as the device state they are conditioned on, so a compliance policy that is stale or shallow quietly weakens an access model that looks strong on paper.

So we treat these as one piece of work rather than two. If certification is what is driving your interest, the endpoint estate is where most of the effort will land, and the evidence problem is the part worth starting on now rather than in the week before an assessment.

Intune, Configuration Manager and co-management
Microsoft IntuneConfiguration ManagerCo-management
Best atCloud-joined devices, wherever they areComplex deployment and on-premises estatesMoving between the two without a cutover
Devices off the corporate networkNative. No line of sight requiredNeeds connectivity back to infrastructureHandled by whichever workload owns it
Complex application sequencingWorkable, less granularStrong, and often years of work already investedLeave it here until Intune is genuinely better for you
Operating system deploymentAutopilot, which suits standard buildsTask sequences, which suit specialised onesCommon to run both for different device types
Reporting out of the boxGood per object, weak across an estate over timePowerful if someone has built it, dated if notNeeds a deliberate layer either way
Right choice whenThe estate is modern and mobileReal work still depends on what it does bestYou have both and want to move without risk
Frequently asked

Questions we hear a lot

Why do we need extra reporting if we already have Intune?

Because Intune answers questions about objects well and questions about estates over time poorly, and the questions you get asked are nearly always the second kind. Whether a device is compliant right now is easy. Proving that every device took critical updates inside fourteen days, every month, across a quarter means exporting, joining and reconciling data by hand, which is exactly the manual position certification was supposed to remove. The management plane is fine. It is the evidence layer that is missing, and that is a separate job rather than a criticism of the product.

Do we have to move off Configuration Manager?

No, and we would push back on anyone telling you otherwise without looking at what it is doing for you. Co-management lets Configuration Manager and Intune manage the same devices at once, with individual workloads moving across one at a time and back again if a move does not work out. Plenty of estates settle permanently in a mixed state because Configuration Manager still does complex application deployment, task sequences and on-premises work better. The question is never whether Intune can do something, it is whether doing it there is better than the arrangement you already have.

Our devices show as compliant. Is that enough?

Not on its own, for three reasons worth checking. Compliance is reported at the last check-in, so an estate that looks healthy may partly be an estate that has gone quiet, and stale devices need separating from compliant ones before the number means anything. A compliance policy also only evaluates what it was told to, so a tenant configured years ago can report a fully compliant estate while never testing the controls anyone would ask about today. And devices that were never enrolled do not show as non-compliant, they simply do not appear, which is why the figure only means something next to an honest count of what should be enrolled.

Can you help us prove patching for Cyber Essentials or an insurer?

That is one of the most common reasons people come to us for this, and it is worth starting early because historical evidence cannot be reconstructed after the fact. Cyber Essentials asks that critical and high-severity updates are applied within fourteen days of release, and an assessor wants to see that this held over time rather than that it holds today. We keep that record continuously, including the exceptions, because a documented and managed exception is far more credible to an assessor than a perfect figure nobody believes.

What is Autopilot and do we need it?

Autopilot provisions a new device into your configuration from its out-of-box state, so a replacement machine can be delivered straight to a person and be usable without anyone building it. It is worth it if you issue devices regularly, support people who are not in an office, or currently have someone spending time imaging machines by hand. It is worth less if you buy devices rarely in batches and have an imaging process that works. It also depends on having your configuration and application deployment in good order first, because Autopilot delivers whatever state you have defined, including a messy one.

Do you manage Macs and mobile devices as well as Windows?

Yes, and the reporting question applies just as much to them, often more, because mixed estates are where visibility falls apart first. In practice the depth of what can be enforced differs by platform, so the honest position is that the management approach is consistent while the specific controls available are not identical. Worth flagging early if a framework you are being assessed against expects the same evidence for every device type, because the work to produce it is not the same on each.

Can you take this on if our Intune tenant is already a mess?

That is the usual starting point rather than an exception, and the first piece of work is a review rather than a rebuild. Most tenants are not broken, they are accumulated: overlapping assignments, settings applied twice with different values, and policies created for projects that finished years ago. Untangling which policy is actually winning on which setting is unglamorous work that usually improves the estate more than anything new we could add, and it frequently shows the estate is in better shape than feared and that the real problem was that nobody could see it.

Endpoint management is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Barnsley, Halifax, Doncaster, Wakefield, Harrogate and Huddersfield and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Does your compliance number mean anything?

What is enrolled against what should be, which devices have gone quiet, which policies are actually winning, and what you could put in front of an assessor today. Forty-five minutes and a written summary.