Forum Discussion
Looking at Intune subscriptions and its related features
- Apr 11, 2022It seems like you want a bit of MAM and MDM, it's best to completely manage the devices with MDM in my opinion. Are the devices BYOD or COD? Per licensed user you can have 15 devices registered. Licensing a user can be done manual or, if you have Azure AD Premium P1 and Azure AD Connect, by assinging Windows Active Directory Groups to that license. You can set the max amount of devices to one user if you want, that way you know that they can only use one device.
But without Azure AD Connect and syncing users, you will have users having a seperate account next to their Active Directory account with different passwords.. I wouldn't recommend it, running Azure AD Connect is free and will only cost you some server resources.
But without Azure AD Connect and syncing users, you will have users having a seperate account next to their Active Directory account with different passwords.. I wouldn't recommend it, running Azure AD Connect is free and will only cost you some server resources.
Thanks for the clear explanation. I'm starting to get a bigger picture. Those devices we are managing are BYOD.
Considering Azure AD connect as optional (I'm not sure if my senior IT would be comfortable opening up on-prem AD connections), I can basically subscribe to EMS + E3 to perform the required tasks mentioned.
I also undertsand the cons of manual user entries that will end up separate accounts for the users apart from their AD accounts.
For subscription sizing wise, I just need to subscribe the total amount of users accounts, doesn't matter how many administrators there are.
Then there are no on-prem requirements like server os versions, AD versions and exchange versions etc.
Hope I have a good rough summeries here?
- Apr 12, 2022
Sounds like it 👌But the admins should have a Intune license too for administration.
- Yeo-ZaoApr 13, 2022Copper ContributorYup I understood. Total subscription sizing = users + admins. Don't mind me asking few last questions here.
- I checked and notice the operation of iPhone and Android is slightly different. Android devices after registered, will create a "work" space of apps.
IPhone does not. All apps are together in homepage. So when wiping the phone, are we still able to just wipe company's data only for iPhone?
- other than deploying standard office apps to mobile devices, can we also deploy and control 3rd party apps from appstore/play store?- Apr 13, 2022You can retire a device to wipe the company data only https://docs.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#retire. And yes, everything that you can see in Appstore or Play store can be deployed to the device. Controlling settings inside of those apps is limited to just the Microsoft Apps AFAIK