
Intune policies are the rules Microsoft Intune pushes to company devices. Compliance policies define what a healthy device looks like, configuration profiles and endpoint security policies set it up that way, and app protection policies guard company data on personal phones. A sensible small-business baseline covers encryption, Defender, the firewall, local admin passwords, updates and Conditional Access.
Below we explain what Intune is used for, how the policy types differ, and the baseline we recommend as a starting point, with a rollout that starts small. It is a recommendation, not a copy of any client's configuration; every environment needs its own exceptions. Our Intune management service builds, pilots and maintains these policies, and Microsoft's own Business Premium guidance, cited below, sets the bar we start from.
What is Microsoft Intune used for?
Intune is Microsoft's cloud service for managing the laptops, desktops, phones and tablets that touch company data. A small business typically uses it to:
- Set up new Windows PCs with apps and settings ready on first sign-in, through Windows Autopilot
- Deploy and update apps without visiting each desk
- Enforce encryption, antivirus, firewall and update settings
- Check that devices are healthy before they reach email and files
- Protect company data in Outlook and Teams on personal phones
- Lock or wipe a lost or stolen device
Business Premium includes Intune Plan 1, which covers all of the above. For the definition, see what Microsoft Intune is; for licensing, see Intune Plan 1 vs Plan 2.
What types of Intune policies are there?
| Policy type | What it does | Example |
|---|---|---|
| Compliance policy | Sets the rules a device must meet to count as compliant, with actions when it falls short | Require BitLocker, Secure Boot and real-time antivirus |
| Configuration profile | Turns device features and settings on or off, from templates or the settings catalog | Wi-Fi and VPN profiles, Bluetooth restrictions |
| Endpoint security policy | Purpose-built security profiles, grouped by job | Antivirus, disk encryption, firewall, Windows LAPS |
| Security baseline | A Microsoft-recommended bundle of preconfigured Windows security settings | Security Baseline for Windows, version 25H2 or 26H2 |
| App protection policy | Protects company data inside managed apps, with or without device enrollment | Require a PIN for Outlook; block copying into personal apps |
| Update ring and feature update policy | Controls when Windows quality and feature updates install | Pilot ring first, then everyone; pin a Windows version |
Conditional Access lives in Microsoft Entra, not Intune, but it is what gives compliance teeth: it can let only compliant devices reach Microsoft 365. One rule to keep: Microsoft treats every Intune policy type as an equal source of settings, so two policies that set the same thing differently conflict. Decide where each setting lives, and never manage BitLocker in a baseline and an endpoint security policy at once. Our Conditional Access guide covers the Entra side.
What should a small business Intune baseline include?
This is the starting set we recommend for a Microsoft 365 Business Premium tenant. Much of it follows Microsoft's published Business Premium recommendations.
| Area | Recommended starting setting | Where it lives |
|---|---|---|
| Windows compliance | Require BitLocker, Secure Boot, code integrity, firewall, TPM, antivirus and Defender real-time protection with current security intelligence; mark devices noncompliant after one day | Compliance policy |
| Devices with no policy | Treat them as not compliant once Conditional Access is on | Compliance policy settings |
| Encryption | BitLocker on Windows and FileVault on Macs, with recovery keys stored in Entra ID | Endpoint security: disk encryption |
| Antivirus | Microsoft Defender Antivirus with real-time protection, onboarded to Defender for Business | Endpoint security: antivirus |
| Firewall | On for every network profile | Endpoint security: firewall |
| Local admin accounts | Windows LAPS with passwords backed up to Entra ID and rotated; staff work as standard users | Endpoint security: account protection |
| Updates | A pilot ring that updates first, a broad ring a few days behind, deadlines on both, and a feature update policy that pins the Windows version | Update rings and feature updates |
| Personal phones | App protection for Outlook, Teams and OneDrive: PIN required, no backup of company data to iCloud or iTunes, copies saved only to OneDrive and SharePoint | App protection policy |
| Access | Require MFA to enroll, block unknown device platforms, require approved apps or app protection on phones, and require a compliant device or MFA for everyone | Conditional Access in Entra |
Microsoft's Windows security baseline is a useful cross-check, but Microsoft says its defaults are the most restrictive in almost all scenarios. Deploy it to the pilot group only, compare it with the settings above, and keep whichever source you choose as the single owner of each setting. For local admin rights, our Windows LAPS guide walks through the rollout, which applies the principle of least privilege to every PC.
How should you roll out Intune policies?
Pilot first, enforce last. The order we use:
- Build a pilot group. IT staff plus one or two volunteers from each department, on their real devices and apps.
- Assign compliance policies and read the report. Microsoft notes compliance is not enforced until a Conditional Access policy applies, so this stage shows you the problem machines safely.
- Turn on configuration and security policies for the pilot. Watch for broken apps, printers and VPN clients for a week or two.
- Create Conditional Access policies in report-only mode. Microsoft recommends this, along with excluding your emergency access accounts. Check the sign-in logs for who would have been blocked.
- Fix the exceptions. Old PCs without TPM 2.0, shared devices and personal phones each need a decision.
- Widen in waves, then enforce. Move department by department, and switch Conditional Access from report-only to on last.
Write down every exception, who approved it and when it will be reviewed. A pilot reduces surprises; it does not remove them, so keep a named contact for the first weeks.
What licenses do these policies need?
Intune Plan 1 covers compliance, configuration, endpoint security, app protection and update ring policies. Feature update policies also need a Windows license with the Autopatch entitlement, Conditional Access needs Microsoft Entra ID P1, and Windows LAPS needs only Intune Plan 1 and the free tier of Entra ID. Business Premium includes Intune Plan 1, Entra ID P1, the Autopatch entitlement and Defender for Business, so it covers the whole baseline. Just-in-time admin elevation through Endpoint Privilege Management costs extra: $3.00 per user per month as of October 2026, or included in Microsoft 365 E5.
Frequently asked questions
What is the difference between a compliance policy and a configuration profile?
A configuration profile changes a setting on the device, such as turning on BitLocker. A compliance policy checks whether the device meets a rule, such as BitLocker being on, and reports compliant or noncompliant. Conditional Access then uses that result to allow or block access. Most baselines need both: one to set the control, one to prove it.
Do Intune policies work on personal phones?
Yes, without taking over the phone. App protection policies apply inside managed apps like Outlook and Teams, so you can require a PIN and stop company data from being copied into personal apps without enrolling the device. Conditional Access can require that protection before email opens. Microsoft recommends full enrollment for company-owned devices.
What happens when a device falls out of compliance?
Intune applies the actions for noncompliance you chose, such as marking the device noncompliant after a grace period, emailing the user or locking the device remotely. With Conditional Access on, the device loses access to company resources until it is fixed. Microsoft's Business Premium guidance sets that grace period at one day.
Should we use Microsoft's security baselines?
As a reference, yes. Intune builds them with the same Windows security team that writes Microsoft's Group Policy baselines, and they give you a fast start. But their defaults are strict and can overlap with endpoint security policies, so test on a pilot group and keep one source of truth per setting.
Sources and further reading
- Microsoft Learn: Device and app management in Microsoft 365 Business Premium: Microsoft's recommended compliance, Conditional Access and app protection settings.
- Microsoft Learn: Use compliance policies: compliance settings and actions for noncompliance.
- Microsoft Learn: Device profiles and endpoint security policies: policy types and how conflicts arise.
- Microsoft Learn: Security baselines: available baselines and their defaults.
- Microsoft Learn: App protection policies: protecting data without enrollment.
- Microsoft Learn: Intune support for Windows LAPS: capabilities and licensing.
- Microsoft Learn: Update ring policies and feature update policies: update stages and licensing.
- Microsoft Learn: Require device compliance with Conditional Access: exclusions and report-only mode.
- Microsoft Intune pricing: the Endpoint Privilege Management price, checked October 2026.
Discuss intune & autopilot deployment for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



