Microsoft Intune consulting

Microsoft Intune

We help teams run Microsoft Intune with configuration as code: policy inventory, safe import, security baselines, pull-request review, and controlled promotion to production.

Work with 536 Technologies from the live platform through handoff.

Where platform work gets stuck

The platform works. Changing it is the problem.

  • Policy changes are portal edits

    Configuration profiles, compliance policies, and baselines change directly in the portal, with no review and no history of who changed what and why.

  • The tenant drifts from its intent

    Duplicate and conflicting policies accumulate. The intended state of the estate exists only in the heads of a few administrators.

  • Migration and cleanup feel risky

    Group Policy imports, baseline updates, and assignment changes reach every device, so teams defer them rather than risk the fleet.

How we work

Put the right platform changes on a path your team can own.

We document the decisions, ownership, and controls your team needs to operate the platform.

  1. 01

    Live tenant

    Inventory the policies, security baselines, assignments, filters, and enrollment paths in use today.

  2. 02

    Ownership and guardrails

    Define who can request, review, approve, and release each policy change.

  3. 03

    Automation and release

    Codify the objects with dependable coverage using Microsoft Graph and Terraform, then validate changes in a development tenant before production.

  4. 04

    Team enablement

    Give the endpoint team standards, examples, and a documented way to change policy.

What your team keeps

Leave your team a platform they can own.

We work in the live delivery flow and leave a path the platform team can run.

  • A reviewed, versioned source of truth for the Intune configuration that belongs in code.
  • Security baselines and Settings Catalog policies that change through pull requests.
  • A validation path that tests policy changes in a development tenant before the fleet.
  • Documentation and runbooks the endpoint team can operate without us.

Common questions

Before we start.

Does every Intune object belong in Terraform?

No. The Microsoft Graph Terraform provider is in preview and resource coverage varies. We document the boundary between Terraform, Microsoft Graph automation, native import and export, and portal-managed configuration.

Can you start from an existing tenant?

Yes. The work starts with an inventory of the live tenant. We import the policies in scope, flag duplicates and conflicts, and propose a target model before changing anything.

How do you keep policy changes from breaking devices?

Changes are validated in a development tenant, reviewed in a pull request, and promoted with assignment filters and staged rollouts instead of fleet-wide edits.

A scoped way to begin

Microsoft Intune Assessment

Inventory the live tenant: policies, security baselines, assignments, filters, and enrollment paths. The findings identify duplicates, conflicts, and the configuration that belongs in code, then become a prioritized remediation plan.

Request an Intune assessment