Someone whose job it is to look after Intune.
Minimum $300 a month. Month to month, no initial term, stop any month. Microsoft licences stay billed by Microsoft.
Start Managed IntuneThe first cycle documents every policy, app, ring and enrolment setting and flags the gaps. Waived if EndKeep built the tenant or you took the Full Assessment in the last 90 days.
Small changes answered within two business hours in your covered hours. A lost device or a device security incident is answered within the hour.
What good looks like six months in
A baseline exists
Every policy, profile, app, ring and enrolment setting is written down from onboarding, so drift is measured, not remembered.
Drift is found and fixed monthly
Assignment conflicts, stale policies and non compliant devices are investigated and remediated every month, with the reasons recorded.
The app catalogue is current
Agreed apps are repackaged, piloted and rolled out when new versions ship. Company Portal never shows a version from last year.
Updates run deliberately
Rings and Autopatch configured, monitored and adjusted. Patch compliance is a number you see every month, not a guess.
Requests get answered
Small moves, adds and changes go through one intake, get a first response within two business hours, and are closed with a note.
The report stands on its own
Monthly compliance and patch reporting specific enough for an auditor or an insurer, without rework and without a call.
Deliverables, every month
| Deliverable | What it means in practice |
|---|---|
| Onboarding baseline | Full documentation of policies, profiles, apps, update rings, enrolment and compliance state, gaps and risks flagged in writing. Delivered in the first cycle, yours to keep. |
| Monthly drift review | Configuration and compliance compared with the baseline. Conflicts and stale assignments fixed. Non compliant devices investigated: stale check ins, encryption failures, broken enrolments, worked to resolution with your contact. |
| Application catalogue | Agreed apps packaged, updated and assigned, tested on a pilot group before broad rollout. Detection rules that check a real version, not a folder. |
| Update management | Windows Update for Business rings configured and watched, critical patch expedite decisions, Windows Autopatch operated where licensed, macOS and iOS update policies enforced. |
| Monthly report | Device compliance by policy, encryption and baseline status, update success rates, app currency, changes made, exceptions, recommendations. Written for a director. |
| Small changes | Policy adjustments, group changes, single app deployments, configuration tweaks, enrolment support, joiner and leaver device handling. Inside the fee. |
| Platform currency | We watch the Intune service releases and Message Center for changes that affect your tenant and flag the ones that matter before they bite. |
| Quarterly review | Thirty minutes on what to adopt, what to retire, and an honest statement when something has grown beyond monthly operations and needs a project. |
The plan, in five steps.
1. Onboarding and baseline
Access through least privilege accounts or GDAP that you approve. Tenant inventory documented, gaps flagged. About 30 days.
2. Monthly drift and compliance cycle
Configuration changes, conflicts and compliance measured against the baseline. Non compliant devices worked to resolution.
3. Apps and updates
Catalogue updates packaged, piloted, rolled out. Rings monitored, Autopatch operated where licensed, critical patches expedited.
4. Requests and small changes
Named contacts raise changes through one intake. Small changes inside the fee. Projects named as projects and quoted separately.
5. Reporting and roadmap
Monthly report closes the cycle. Quarterly review sets the next three months.
Prerequisites
- A working Intune deployment with devices already enrolled. If not, start with a Hardening and Build project.
- Intune licensing for the managed users (Business Premium, E3, E5 or equivalent), billed by Microsoft or your reseller.
- Least privilege access approved: named accounts with MFA, or a GDAP relationship.
- A named contact who can raise changes and approve anything users will notice.
- For Autopatch, an eligible licence confirmed at onboarding.
- Agreement on the app catalogue and the device scope.
Who does what
EndKeep: documents the baseline; runs the monthly drift, compliance and remediation cycle; packages, pilots and rolls out catalogue updates; configures and monitors rings and Autopatch; handles small changes within the response target; delivers the monthly report and quarterly recommendations; tracks Intune releases; names and quotes anything beyond monthly scope.
You: keep licences current; approve access and keep a named intake contact; approve user visible changes, pilot groups and maintenance timing; handle first line user support or keep your helpdesk; tell us early about headcount, office and device changes; read the report and decide on project recommendations.
What is not included
- Initial Intune design, enrolment and platform onboarding. That is a Hardening and Build project.
- End user helpdesk. Users go to your first line.
- Migration from another MDM (Jamf, Workspace ONE, Google). A scoped project with discovery and cutover.
- Large app onboarding waves or wholesale repackaging. The fee keeps the agreed catalogue current.
- Security incident response and compromise recovery. We escalate honestly; the response is separate work.
- Conditional Access architecture, identity redesign and email security. Flagged and routed to a security engagement.
- Intune Suite add ons (Remote Help, EPM, Advanced Analytics) unless licensed; then folded in by agreement.
- Microsoft licences and hardware. Billed by Microsoft or the vendor, never marked up.
Limitations and technical notes
- Intune is a moving platform. Microsoft changes features, defaults and licensing over time; we keep up, and flag what changes for you.
- Compliance reporting reflects what enrolled devices report. Offline, retired or irregular devices appear with caveats.
- The service covers the agreed device scope. The bill follows the actual in scope devices that month. Material growth is re baselined by agreement.
- Autopatch needs an eligible licence. Entitlement is confirmed at onboarding, not assumed.
- Response targets apply in your agreed covered hours. P1 device incidents are answered within the hour.
Frequently asked questions
What is Managed Intune?
A monthly service where EndKeep runs your Microsoft Intune tenant: a documented baseline at onboarding, a drift and compliance review every month, the agreed app catalogue kept current, update rings and Windows Autopatch looked after, small changes handled inside the fee, and a monthly report. $6 per enrolled device per month.
Who is it for?
Companies that already have Intune, set up by us, a previous provider or their own IT, and nobody whose job it is to look after it afterwards. Typically 10 to 100 people, up to a few hundred devices, with an IT company or an internal person doing helpdesk.
How does per device billing work?
$6 a month for each device enrolled in Intune and inside the agreed scope, counted on the invoice date. Minimum $300 a month. Devices come and go through the normal intake; if the fleet changes materially we agree a new baseline rather than quietly stretching the fee.
What counts as a small change, and what is a project?
Small changes are the routine of running Intune: a policy tweak, a group change, one app deployed or updated, an enrolment that will not complete, a new starter's laptop. Projects reshape the estate: a new platform, a migration from another MDM, a wave of new apps, a Conditional Access redesign, Autopilot from scratch. We name a project as a project and quote it separately, in writing, before starting.
What happens with application updates?
The apps in the agreed catalogue are repackaged when a new version ships, tested on a pilot group, then rolled out by ring. Company Portal stays current and users stop installing things themselves. Adding a batch of new apps to the catalogue is a project.
Do you run Windows Autopatch for us?
Yes, where the licence allows it (Microsoft 365 Business Premium, Windows Enterprise E3 or E5, or an equivalent SKU). We confirm entitlement at onboarding, configure it, watch it, and fold the results into the monthly report. Where it is not licensed we run Windows Update for Business rings instead.
We already have an IT company or a helpdesk. Why would we need this?
Different layers. A helpdesk answers users. Managed Intune operates the platform underneath: policy drift, app currency, patch posture, compliance reporting. Most of our clients keep their helpdesk; we hand them the documentation and stay out of their way.
How fast do you respond?
First response to a request within two business hours in your agreed covered hours. A lost or stolen device, or a security incident involving devices, is a P1 and is answered within the hour. Response means an engineer has started, not that it is fixed; we tell you the expected time when we pick it up.
What access do you need?
Least privilege. Either named EndKeep engineer accounts in your tenant with MFA and only the roles the work needs, or a GDAP relationship you approve. Never standing Global Administrator; where a change needs it, we ask for a defined window and it is removed after. You hold a break glass account we never see.
Our Intune tenant is a mess. Can you still take it on?
Usually yes. The onboarding baseline documents what exists and flags what is broken or risky in writing. Ordinary tidy up is absorbed into the first cycles. If it needs rebuilding rather than tidying, we say so and quote it as a Hardening project first.
What is in the monthly report?
Device compliance by policy with the reasons for failures, encryption and baseline status, update and patch success rates including Autopatch, app catalogue currency, what changed, what we fixed, exceptions, and what we recommend next. Written so a director or an insurer can read it without us on the call.
Do you cover co managed Configuration Manager devices?
Where Intune owns the workloads, yes. Where SCCM still owns most of them we assess the fit at onboarding, and moving the workloads across is a project we do often.
Which platforms?
Whatever is already managed in Intune: Windows, macOS, iOS and iPadOS, Android. Bringing a new platform under management, for example Macs through Apple Business Manager for the first time, is a setup project.
How does billing work, and can we stop?
Invoiced monthly in advance on the device count, in US dollars, due within 14 days. No initial term. Stop any month after paying the invoices already approved, and you keep the baseline, the documentation and everything configured in your tenant.
Ways in, and what sits beside it
Hardening and Build
Intune built or fixed from the assessment roadmap, then handed to Managed Intune with the onboarding fee waived.
Details →Full Security Assessment
The whole tenant scored, with a priced roadmap. Take it within 90 days and the Managed Intune onboarding fee is waived.
Details →Every Intune service we deliver
43 services in six groups: enrolment, configuration, apps, updates, endpoint security, migrations. Anything outside the monthly scope is here.
The radar →