Choosing a Microsoft 365 license for device management is not just a matter of picking the plan with the most features. The right answer depends on whether your organization needs user-based management, device-only enrollment, or advanced endpoint capabilities.
Talk with IGTech365 about your Microsoft 365 licensing and device-management needs.
In short, which Microsoft 365 licenses include Intune and device management? Microsoft 365 bundles such as E3, E5, and E7 include Intune capabilities, while organizations can also license Intune directly through Plan 1, Plan 2, or Intune Suite. Microsoft says the specific entitlement and license requirement depend on the user, device, and management scenario.
That distinction matters for businesses managing employee laptops, shared kiosks, mobile devices, or specialized equipment. It also helps prevent a common mistake: assuming that access to the Intune admin center means every user and device is properly licensed. Start by mapping the available license paths, then compare what each one actually supports.
Which Microsoft 365 licenses include Intune and device management?
The short answer is that Intune is available through dedicated Intune plans and through selected Microsoft 365 bundles. Microsoft’s current licensing documentation identifies Microsoft Intune Plan 1 as the base service, while Plan 2 adds advanced endpoint-management capabilities. The Intune Suite includes Plan 2 and adds further endpoint and security capabilities. Microsoft also says that many organizations receive Intune through a bundle such as Microsoft 365 E3 or E5 instead of buying an Intune plan directly. See the official Microsoft Intune licensing guide for the current matrix.
| License path | What Microsoft documents | Best way to read it |
|---|---|---|
| Intune Plan 1 | Base Intune service with cloud-based unified endpoint management for devices and apps. | Core device and application management entitlement. |
| Intune Plan 2 | Additive to Plan 1, with advanced capabilities such as Remote Help and Advanced Analytics. | Additional functionality, not a replacement for Plan 1. |
| Intune Suite | Additive to Plan 1 and includes Plan 2. | Broader advanced endpoint-management and security coverage. |
| Microsoft 365 E3 or E5 | Microsoft identifies these as examples of bundles that include Intune. | Check the specific assigned bundle and current terms before enrollment. |
| Microsoft 365 Education A3 or A5 | Intune for Education Plan 1 is included in these education licenses. | Relevant to eligible education tenants. |
For planning purposes, treat the rows as a map, not a blanket answer for every employee. A tenant may contain several subscription families, and advanced capabilities can depend on the licenses already assigned across the organization. Microsoft recommends reviewing existing licensing to avoid overlapping functionality before adding advanced Intune capabilities. That review makes it easier to separate endpoint management from optional enhancements and document the control set.
That map separates an entitlement from a practical configuration outcome. Having a plan does not automatically enroll devices, deploy applications, or create compliance policies. It gives the organization access to the applicable Intune service, while administrators still need to assign licenses, configure enrollment, and decide which controls fit the business.
Microsoft states that a user or device benefiting directly or indirectly from Intune requires an Intune license. Users must be assigned a license before they can enroll devices. And users receiving an Intune app protection policy need a license even if they do not enroll a device. Review the Microsoft license-assignment guidance before rollout.
There are important exceptions for dedicated equipment. Intune offers a device-only subscription for kiosks, dedicated devices, phone-room devices, IoT, and other single-use scenarios. Device-only licensing has limits, including unsupported Intune app protection policies, Conditional Access, and user-based email or calendaring management. Because plan names and included capabilities change, confirm the live Microsoft matrix for your tenant before a Tampa Bay or Florida device rollout.
Does Microsoft 365 Business Premium include Intune?
Yes. Microsoft 365 Business Premium includes Microsoft Intune Plan 1. The verified Microsoft Learn guidance for Business Premium describes Intune Plan 1 as a comprehensive device management solution for enrolling, monitoring, and managing devices. That includes company-owned computers, tablets, and phones, as well as personal devices used under a bring your own device (BYOD) policy.
Business Premium supports two high-level approaches. Mobile device management (MDM) gives the organization control over the enrolled device. Administrators can apply enrollment restrictions, install approved apps, manage settings, and take actions such as remotely wiping a lost or stolen device. MDM is generally the more natural fit for company-owned equipment because the business owns and manages the full device.
Mobile application management (MAM) takes a narrower approach for personal devices. The user keeps control of the device, while the organization controls access to company data inside managed applications. Policies can help prevent business information from being copied into personal apps, and can remove organizational data from managed apps without wiping the entire personal device. A business may use MDM, MAM, or both, depending on its device ownership and data-protection requirements.
The license is not the same thing as a finished rollout. Business Premium provides the Intune Plan 1 entitlement, but the tenant still needs deliberate configuration. That work can include identifying company-owned and BYOD devices, setting enrollment restrictions, completing platform prerequisites, choosing MDM or MAM policies, deploying applications, and defining compliance and access rules. Without those decisions, devices may remain unenrolled or receive inconsistent protection even though the subscription includes Intune.
Microsoft 365 E3 and E5 are also identified in the verified Intune licensing documentation as Microsoft 365 bundles that commonly include Intune. That does not make every plan identical. Intune Plan 1 is the base service, while advanced capabilities are available through Intune Plan 2, the Intune Suite, and select Microsoft 365 bundles. Therefore, compare the exact SKU and assigned licenses rather than assuming that Business Premium, E3, or E5 includes every advanced Intune function.
For broader context on the bundle-level decision, read Microsoft 365 E3 vs. E5. Then document which users and devices need management, which method fits each device category, and whether an advanced add-on is actually required. That process turns an Intune entitlement into a device-management plan that can be tested, documented, and maintained before wider deployment.
What is the difference between user, device-only, and admin licensing?
Intune licensing follows the person or device that benefits from the service. Microsoft states that an Intune license is required for any user or device that benefits directly or indirectly from Intune. A license determines whether the intended scenario is covered.
User licensing covers an employee with an assigned laptop, phone, or tablet. Microsoft says users must be assigned an Intune license before they can enroll devices. A user who receives an Intune app protection policy also needs an Intune license even if that person does not enroll a device. This matters for a bring-your-own-device program, because app protection and enrollment are different scenarios. Review Microsoft’s license-assignment guidance when mapping people to licenses.
Device-only licensing is designed for equipment without a specific user. Microsoft’s examples include kiosks, dedicated devices, phone-room devices, IoT, and other single-use devices. Eligible enrollment scenarios include Windows Autopilot Self-Deploying mode, Apple enrollment without user affinity. Apple School Manager without user affinity, Apple Configurator without user affinity, and Android Enterprise dedicated enrollment. A signed-in user without an Intune user license does not prevent device-targeted policies, applications, or management actions from processing on a device managed through a device-only subscription.
Device-only is not a full substitute for user licensing. Microsoft says Intune app protection policies and Conditional Access are not supported for devices enrolled with a device license. User-based management features such as email and calendaring are also not supported in that model. The Microsoft licensing guide should be checked whenever a shared device needs controls beyond device-targeted management.
Admin access is different. For tenants created after July 2021, unlicensed administrator access is supported by default. For older tenants, an administrator needs an Intune license unless the Allow access to unlicensed admins setting is enabled. Unlicensed admin access permits sign-in and management in the Intune admin center, but it does not replace licenses required for other features and services. Microsoft supports up to 1,000 unlicensed administrators per security group, and nested security-group members are not included.
For example, a Tampa office might assign user licenses to employees with managed laptops, a device-only subscription to a reception kiosk, and admin access to an IT team. The team should then test each scenario separately. That approach prevents a shared kiosk from being treated like an employee device, while keeping app protection and other user-based requirements tied to properly licensed people.
What device-management capabilities does Intune provide?
Microsoft Intune is more than a name on a license comparison. Intune Plan 1 provides cloud-based unified endpoint management for devices and apps. In practical terms, that gives a small business a central service for bringing eligible devices into management. Applying settings and applications, and carrying out management actions without relying on a separate on-premises console. Microsoft describes the core service and its licensing paths in its Intune licensing documentation.
That distinction is useful when a business is comparing Microsoft 365 bundles with standalone Intune options. The key question is not simply whether the word Intune appears in a plan name. It is whether the assigned entitlement covers the users and devices in scope, and whether it supports the management outcomes the business actually needs.
Enrollment is the first operational step. Users must have an Intune license assigned before they can enroll their devices. That requirement matters when a business has a mixed license population, seasonal staff, contractors, or shared devices. A license review should therefore map each person and device to the way it will actually be used. Rather than assuming that one administrator’s access covers every managed endpoint.
Once devices are enrolled, Intune can process device-targeted policies, applications, and management actions. The licensing documentation also describes a device-only subscription for devices that are not affiliated with a specific user. Including kiosks, dedicated devices, phone-room devices, IoT, and other single-use devices. This can fit a shared or specialized endpoint, but it is not interchangeable with user-based management. Microsoft states that app protection policies, Conditional Access, and user-based features such as email and calendaring are not supported for device-licensed enrollment.
Policies and compliance still require deliberate design. The entitlement makes the service available; it does not decide which security settings, applications, enrollment methods, or compliance requirements fit your business. An administrator must define the policy goals, assign them to the right users or devices, test the result, and review exceptions. Buying an Intune-capable license alone does not prove that an endpoint is configured or compliant.
Advanced requirements may call for a separate path. Microsoft says Intune Plan 2 and the Intune Suite add capabilities to Plan 1, while select Microsoft 365 bundles may include advanced capabilities. Those options can address needs such as Remote Help or analytics, but availability depends on the licenses already assigned across the organization. Review the current Intune add-ons documentation before selecting an add-on, and confirm the tenant’s configuration against the current licensing matrix.
How should a small business validate its Microsoft 365 license mix?
A license review should connect each entitlement to a real person, device, and management outcome. It should also distinguish a licensing entitlement from the configuration work needed to make that entitlement useful. Use this five-step checklist before changing assignments or adding Intune capabilities:
- Inventory users and endpoints. List employees, contractors, shared devices, kiosks, dedicated devices, and other single-use endpoints. Record who benefits from Intune, how each device will be enrolled, and whether the endpoint is user-affiliated. Microsoft requires an Intune license for a user or device that benefits directly or indirectly from the service.
- Map each use case to the required service. Separate cloud endpoint and app management, enrollment, device-targeted policies, application deployment, app protection, Conditional Access, and any advanced capability. Start with Microsoft’s current Intune licensing matrix, because plan details and available bundles can change. Do not assume that an Intune-capable bundle includes every advanced feature.
- Check device-only scenarios carefully. A device-only subscription can suit kiosks, dedicated devices, phone-room devices, IoT, or another single-use endpoint. Verify the enrollment method and the limitations before assigning it. Microsoft states that device-licensed enrollment does not support Intune app protection policies, Conditional Access, or user-based management features such as email and calendaring.
- Test assignment and administration. Confirm that users who need to enroll devices have the required license assigned. If an administrator is unlicensed, check the tenant’s age and access setting. Tenants created after July 2021 support unlicensed administrator access by default; older tenants require the setting to be enabled. That access does not replace licenses needed for other features.
- Document the decision and review it. Record the selected license path, enrollment method, policy owner, exceptions, and the evidence that the configuration works. If the business is moving from a lighter plan because device or security requirements have changed, review when to upgrade from Business Standard. Then have a qualified administrator validate the rollout or arrange managed IT support to maintain assignments, policies, and compliance checks as the business grows.
This process keeps the decision focused on actual users, devices, and controls instead of a generic best-plan recommendation. It also gives a small business a repeatable record to revisit when its workforce, device fleet, or compliance obligations change. Keep the record with the tenant’s administration documentation so future reviews can identify gaps without starting from scratch.
Request a practical Microsoft 365 licensing review from IGTech365.
Frequently Asked Questions
Which 365 license includes Intune?
Several Microsoft 365 bundles include Intune, including Microsoft 365 E3 and E5. Organizations can also license Intune directly through Plan 1, Plan 2, or the Intune Suite, depending on the device-management capabilities they need. Confirm the current Microsoft licensing matrix before assigning licenses because plan contents can change. Microsoft’s licensing guidance provides the authoritative list.
What license is needed to use Intune?
A user or device that benefits directly or indirectly from Intune generally needs an Intune license. Users must have an assigned license before enrolling devices, and users receiving Intune app protection policies need a license even if they do not enroll a device. Microsoft’s license-assignment guidance explains these requirements.
Does Office 365 E3 include Intune?
Do not assume that an Office 365 plan and a Microsoft 365 plan have the same entitlements. Check the exact subscription name in your tenant and compare it with Microsoft’s current Intune licensing documentation. If the subscription does not include Intune, you may need a standalone Intune plan or an eligible add-on.
Can I use a device-only Intune license for a shared kiosk?
Yes, a device-only subscription is intended for devices without a specific user, including kiosks, dedicated devices, phone-room devices, and some IoT scenarios. However, device-only enrollment does not support user-based features such as Intune app protection policies or Conditional Access, so shared-device requirements should be reviewed before choosing this model. See Microsoft’s device-license limitations.
Ready to Review Your Microsoft 365 License Mix?
License selection is only one part of effective device management. A focused review can help connect your Microsoft 365 entitlements with the users, devices, policies, and operational needs your team must support. Contact us to discuss your current setup and identify practical next steps.
Call IGTech365 at (866) 365-7798 to discuss your Microsoft 365 licensing needs.
