Managed Intune

Your Intune tenant, run every month.

Baseline, drift review, apps, updates, report, small changes. $6 per enrolled device per month, minimum $300, stop any month.

what this engagement is

Someone whose job it is to look after Intune.

Most tenants were set up once and never looked at again. Managed Intune is the steady state: a baseline, a monthly cycle, a report, and a named engineer who knows your tenant. It is not helpdesk and it is not a project; both of those exist separately, and we say clearly which is which.
PRICE
$6per enrolled device per month

Minimum $300 a month. Month to month, no initial term, stop any month. Microsoft licences stay billed by Microsoft.

Start Managed Intune
ONBOARDING
$500one off baseline

The first cycle documents every policy, app, ring and enrolment setting and flags the gaps. Waived if EndKeep built the tenant or you took the Full Assessment in the last 90 days.

RESPONSE
2 hoursfirst response, business hours

Small changes answered within two business hours in your covered hours. A lost device or a device security incident is answered within the hour.

success criteria

What good looks like six months in

ONE

A baseline exists

Every policy, profile, app, ring and enrolment setting is written down from onboarding, so drift is measured, not remembered.

TWO

Drift is found and fixed monthly

Assignment conflicts, stale policies and non compliant devices are investigated and remediated every month, with the reasons recorded.

THREE

The app catalogue is current

Agreed apps are repackaged, piloted and rolled out when new versions ship. Company Portal never shows a version from last year.

FOUR

Updates run deliberately

Rings and Autopatch configured, monitored and adjusted. Patch compliance is a number you see every month, not a guess.

FIVE

Requests get answered

Small moves, adds and changes go through one intake, get a first response within two business hours, and are closed with a note.

SIX

The report stands on its own

Monthly compliance and patch reporting specific enough for an auditor or an insurer, without rework and without a call.

what you receive

Deliverables, every month

DeliverableWhat it means in practice
Onboarding baselineFull documentation of policies, profiles, apps, update rings, enrolment and compliance state, gaps and risks flagged in writing. Delivered in the first cycle, yours to keep.
Monthly drift reviewConfiguration and compliance compared with the baseline. Conflicts and stale assignments fixed. Non compliant devices investigated: stale check ins, encryption failures, broken enrolments, worked to resolution with your contact.
Application catalogueAgreed apps packaged, updated and assigned, tested on a pilot group before broad rollout. Detection rules that check a real version, not a folder.
Update managementWindows Update for Business rings configured and watched, critical patch expedite decisions, Windows Autopatch operated where licensed, macOS and iOS update policies enforced.
Monthly reportDevice compliance by policy, encryption and baseline status, update success rates, app currency, changes made, exceptions, recommendations. Written for a director.
Small changesPolicy adjustments, group changes, single app deployments, configuration tweaks, enrolment support, joiner and leaver device handling. Inside the fee.
Platform currencyWe watch the Intune service releases and Message Center for changes that affect your tenant and flag the ones that matter before they bite.
Quarterly reviewThirty minutes on what to adopt, what to retire, and an honest statement when something has grown beyond monthly operations and needs a project.
how the work unfolds

The plan, in five steps.

1. Onboarding and baseline

Access through least privilege accounts or GDAP that you approve. Tenant inventory documented, gaps flagged. About 30 days.

2. Monthly drift and compliance cycle

Configuration changes, conflicts and compliance measured against the baseline. Non compliant devices worked to resolution.

3. Apps and updates

Catalogue updates packaged, piloted, rolled out. Rings monitored, Autopatch operated where licensed, critical patches expedited.

4. Requests and small changes

Named contacts raise changes through one intake. Small changes inside the fee. Projects named as projects and quoted separately.

5. Reporting and roadmap

Monthly report closes the cycle. Quarterly review sets the next three months.

BEFORE WE START

Prerequisites

  • A working Intune deployment with devices already enrolled. If not, start with a Hardening and Build project.
  • Intune licensing for the managed users (Business Premium, E3, E5 or equivalent), billed by Microsoft or your reseller.
  • Least privilege access approved: named accounts with MFA, or a GDAP relationship.
  • A named contact who can raise changes and approve anything users will notice.
  • For Autopatch, an eligible licence confirmed at onboarding.
  • Agreement on the app catalogue and the device scope.
WORKING TOGETHER

Who does what

EndKeep: documents the baseline; runs the monthly drift, compliance and remediation cycle; packages, pilots and rolls out catalogue updates; configures and monitors rings and Autopatch; handles small changes within the response target; delivers the monthly report and quarterly recommendations; tracks Intune releases; names and quotes anything beyond monthly scope.

You: keep licences current; approve access and keep a named intake contact; approve user visible changes, pilot groups and maintenance timing; handle first line user support or keep your helpdesk; tell us early about headcount, office and device changes; read the report and decide on project recommendations.

SCOPE

What is not included

  • Initial Intune design, enrolment and platform onboarding. That is a Hardening and Build project.
  • End user helpdesk. Users go to your first line.
  • Migration from another MDM (Jamf, Workspace ONE, Google). A scoped project with discovery and cutover.
  • Large app onboarding waves or wholesale repackaging. The fee keeps the agreed catalogue current.
  • Security incident response and compromise recovery. We escalate honestly; the response is separate work.
  • Conditional Access architecture, identity redesign and email security. Flagged and routed to a security engagement.
  • Intune Suite add ons (Remote Help, EPM, Advanced Analytics) unless licensed; then folded in by agreement.
  • Microsoft licences and hardware. Billed by Microsoft or the vendor, never marked up.
FINE PRINT

Limitations and technical notes

  • Intune is a moving platform. Microsoft changes features, defaults and licensing over time; we keep up, and flag what changes for you.
  • Compliance reporting reflects what enrolled devices report. Offline, retired or irregular devices appear with caveats.
  • The service covers the agreed device scope. The bill follows the actual in scope devices that month. Material growth is re baselined by agreement.
  • Autopatch needs an eligible licence. Entitlement is confirmed at onboarding, not assumed.
  • Response targets apply in your agreed covered hours. P1 device incidents are answered within the hour.
questions

Frequently asked questions

What is Managed Intune?

A monthly service where EndKeep runs your Microsoft Intune tenant: a documented baseline at onboarding, a drift and compliance review every month, the agreed app catalogue kept current, update rings and Windows Autopatch looked after, small changes handled inside the fee, and a monthly report. $6 per enrolled device per month.

Who is it for?

Companies that already have Intune, set up by us, a previous provider or their own IT, and nobody whose job it is to look after it afterwards. Typically 10 to 100 people, up to a few hundred devices, with an IT company or an internal person doing helpdesk.

How does per device billing work?

$6 a month for each device enrolled in Intune and inside the agreed scope, counted on the invoice date. Minimum $300 a month. Devices come and go through the normal intake; if the fleet changes materially we agree a new baseline rather than quietly stretching the fee.

What counts as a small change, and what is a project?

Small changes are the routine of running Intune: a policy tweak, a group change, one app deployed or updated, an enrolment that will not complete, a new starter's laptop. Projects reshape the estate: a new platform, a migration from another MDM, a wave of new apps, a Conditional Access redesign, Autopilot from scratch. We name a project as a project and quote it separately, in writing, before starting.

What happens with application updates?

The apps in the agreed catalogue are repackaged when a new version ships, tested on a pilot group, then rolled out by ring. Company Portal stays current and users stop installing things themselves. Adding a batch of new apps to the catalogue is a project.

Do you run Windows Autopatch for us?

Yes, where the licence allows it (Microsoft 365 Business Premium, Windows Enterprise E3 or E5, or an equivalent SKU). We confirm entitlement at onboarding, configure it, watch it, and fold the results into the monthly report. Where it is not licensed we run Windows Update for Business rings instead.

We already have an IT company or a helpdesk. Why would we need this?

Different layers. A helpdesk answers users. Managed Intune operates the platform underneath: policy drift, app currency, patch posture, compliance reporting. Most of our clients keep their helpdesk; we hand them the documentation and stay out of their way.

How fast do you respond?

First response to a request within two business hours in your agreed covered hours. A lost or stolen device, or a security incident involving devices, is a P1 and is answered within the hour. Response means an engineer has started, not that it is fixed; we tell you the expected time when we pick it up.

What access do you need?

Least privilege. Either named EndKeep engineer accounts in your tenant with MFA and only the roles the work needs, or a GDAP relationship you approve. Never standing Global Administrator; where a change needs it, we ask for a defined window and it is removed after. You hold a break glass account we never see.

Our Intune tenant is a mess. Can you still take it on?

Usually yes. The onboarding baseline documents what exists and flags what is broken or risky in writing. Ordinary tidy up is absorbed into the first cycles. If it needs rebuilding rather than tidying, we say so and quote it as a Hardening project first.

What is in the monthly report?

Device compliance by policy with the reasons for failures, encryption and baseline status, update and patch success rates including Autopatch, app catalogue currency, what changed, what we fixed, exceptions, and what we recommend next. Written so a director or an insurer can read it without us on the call.

Do you cover co managed Configuration Manager devices?

Where Intune owns the workloads, yes. Where SCCM still owns most of them we assess the fit at onboarding, and moving the workloads across is a project we do often.

Which platforms?

Whatever is already managed in Intune: Windows, macOS, iOS and iPadOS, Android. Bringing a new platform under management, for example Macs through Apple Business Manager for the first time, is a setup project.

How does billing work, and can we stop?

Invoiced monthly in advance on the device count, in US dollars, due within 14 days. No initial term. Stop any month after paying the invoices already approved, and you keep the baseline, the documentation and everything configured in your tenant.

Start Managed IntuneGet a quote

often combined with

Ways in, and what sits beside it

BEFORE

Hardening and Build

Intune built or fixed from the assessment roadmap, then handed to Managed Intune with the onboarding fee waived.

Details →
BEFORE

Full Security Assessment

The whole tenant scored, with a priced roadmap. Take it within 90 days and the Managed Intune onboarding fee is waived.

Details →
THE FULL SET

Every Intune service we deliver

43 services in six groups: enrolment, configuration, apps, updates, endpoint security, migrations. Anything outside the monthly scope is here.

The radar →

Talk to an engineer, not a sales deck.

Fifteen minutes on video. Tell us roughly how many people and devices, and we will tell you what we would look at first and what it would cost.

Book a 15 minute callOr email [email protected]. An engineer replies within one business day.