HomeBlogCybersecurity

Intune Policies for Small Business: A Starting Baseline

Illustration of a robot on a ship's deck at night raising a glowing blue shield against red bug-shaped threats flying in over the waves

Intune policies are the rules Microsoft Intune pushes to company devices. Compliance policies define what a healthy device looks like, configuration profiles and endpoint security policies set it up that way, and app protection policies guard company data on personal phones. A sensible small-business baseline covers encryption, Defender, the firewall, local admin passwords, updates and Conditional Access.

Below we explain what Intune is used for, how the policy types differ, and the baseline we recommend as a starting point, with a rollout that starts small. It is a recommendation, not a copy of any client's configuration; every environment needs its own exceptions. Our Intune management service builds, pilots and maintains these policies, and Microsoft's own Business Premium guidance, cited below, sets the bar we start from.

What is Microsoft Intune used for?

Intune is Microsoft's cloud service for managing the laptops, desktops, phones and tablets that touch company data. A small business typically uses it to:

  • Set up new Windows PCs with apps and settings ready on first sign-in, through Windows Autopilot
  • Deploy and update apps without visiting each desk
  • Enforce encryption, antivirus, firewall and update settings
  • Check that devices are healthy before they reach email and files
  • Protect company data in Outlook and Teams on personal phones
  • Lock or wipe a lost or stolen device

Business Premium includes Intune Plan 1, which covers all of the above. For the definition, see what Microsoft Intune is; for licensing, see Intune Plan 1 vs Plan 2.

What types of Intune policies are there?

Policy typeWhat it doesExample
Compliance policySets the rules a device must meet to count as compliant, with actions when it falls shortRequire BitLocker, Secure Boot and real-time antivirus
Configuration profileTurns device features and settings on or off, from templates or the settings catalogWi-Fi and VPN profiles, Bluetooth restrictions
Endpoint security policyPurpose-built security profiles, grouped by jobAntivirus, disk encryption, firewall, Windows LAPS
Security baselineA Microsoft-recommended bundle of preconfigured Windows security settingsSecurity Baseline for Windows, version 25H2 or 26H2
App protection policyProtects company data inside managed apps, with or without device enrollmentRequire a PIN for Outlook; block copying into personal apps
Update ring and feature update policyControls when Windows quality and feature updates installPilot ring first, then everyone; pin a Windows version

Conditional Access lives in Microsoft Entra, not Intune, but it is what gives compliance teeth: it can let only compliant devices reach Microsoft 365. One rule to keep: Microsoft treats every Intune policy type as an equal source of settings, so two policies that set the same thing differently conflict. Decide where each setting lives, and never manage BitLocker in a baseline and an endpoint security policy at once. Our Conditional Access guide covers the Entra side.

What should a small business Intune baseline include?

This is the starting set we recommend for a Microsoft 365 Business Premium tenant. Much of it follows Microsoft's published Business Premium recommendations.

AreaRecommended starting settingWhere it lives
Windows complianceRequire BitLocker, Secure Boot, code integrity, firewall, TPM, antivirus and Defender real-time protection with current security intelligence; mark devices noncompliant after one dayCompliance policy
Devices with no policyTreat them as not compliant once Conditional Access is onCompliance policy settings
EncryptionBitLocker on Windows and FileVault on Macs, with recovery keys stored in Entra IDEndpoint security: disk encryption
AntivirusMicrosoft Defender Antivirus with real-time protection, onboarded to Defender for BusinessEndpoint security: antivirus
FirewallOn for every network profileEndpoint security: firewall
Local admin accountsWindows LAPS with passwords backed up to Entra ID and rotated; staff work as standard usersEndpoint security: account protection
UpdatesA pilot ring that updates first, a broad ring a few days behind, deadlines on both, and a feature update policy that pins the Windows versionUpdate rings and feature updates
Personal phonesApp protection for Outlook, Teams and OneDrive: PIN required, no backup of company data to iCloud or iTunes, copies saved only to OneDrive and SharePointApp protection policy
AccessRequire MFA to enroll, block unknown device platforms, require approved apps or app protection on phones, and require a compliant device or MFA for everyoneConditional Access in Entra

Microsoft's Windows security baseline is a useful cross-check, but Microsoft says its defaults are the most restrictive in almost all scenarios. Deploy it to the pilot group only, compare it with the settings above, and keep whichever source you choose as the single owner of each setting. For local admin rights, our Windows LAPS guide walks through the rollout, which applies the principle of least privilege to every PC.

How should you roll out Intune policies?

Pilot first, enforce last. The order we use:

  1. Build a pilot group. IT staff plus one or two volunteers from each department, on their real devices and apps.
  2. Assign compliance policies and read the report. Microsoft notes compliance is not enforced until a Conditional Access policy applies, so this stage shows you the problem machines safely.
  3. Turn on configuration and security policies for the pilot. Watch for broken apps, printers and VPN clients for a week or two.
  4. Create Conditional Access policies in report-only mode. Microsoft recommends this, along with excluding your emergency access accounts. Check the sign-in logs for who would have been blocked.
  5. Fix the exceptions. Old PCs without TPM 2.0, shared devices and personal phones each need a decision.
  6. Widen in waves, then enforce. Move department by department, and switch Conditional Access from report-only to on last.

Write down every exception, who approved it and when it will be reviewed. A pilot reduces surprises; it does not remove them, so keep a named contact for the first weeks.

What licenses do these policies need?

Intune Plan 1 covers compliance, configuration, endpoint security, app protection and update ring policies. Feature update policies also need a Windows license with the Autopatch entitlement, Conditional Access needs Microsoft Entra ID P1, and Windows LAPS needs only Intune Plan 1 and the free tier of Entra ID. Business Premium includes Intune Plan 1, Entra ID P1, the Autopatch entitlement and Defender for Business, so it covers the whole baseline. Just-in-time admin elevation through Endpoint Privilege Management costs extra: $3.00 per user per month as of October 2026, or included in Microsoft 365 E5.

Frequently asked questions

What is the difference between a compliance policy and a configuration profile?

A configuration profile changes a setting on the device, such as turning on BitLocker. A compliance policy checks whether the device meets a rule, such as BitLocker being on, and reports compliant or noncompliant. Conditional Access then uses that result to allow or block access. Most baselines need both: one to set the control, one to prove it.

Do Intune policies work on personal phones?

Yes, without taking over the phone. App protection policies apply inside managed apps like Outlook and Teams, so you can require a PIN and stop company data from being copied into personal apps without enrolling the device. Conditional Access can require that protection before email opens. Microsoft recommends full enrollment for company-owned devices.

What happens when a device falls out of compliance?

Intune applies the actions for noncompliance you chose, such as marking the device noncompliant after a grace period, emailing the user or locking the device remotely. With Conditional Access on, the device loses access to company resources until it is fixed. Microsoft's Business Premium guidance sets that grace period at one day.

Should we use Microsoft's security baselines?

As a reference, yes. Intune builds them with the same Windows security team that writes Microsoft's Group Policy baselines, and they give you a fast start. But their defaults are strict and can overlap with endpoint security policies, so test on a pilot group and keep one source of truth per setting.

Sources and further reading

Intune & Autopilot Deployment

Discuss intune & autopilot deployment for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore Intune & Autopilot Deployment 845-203-3914