For many organisations, endpoint management has reached an inflection point. The shift to hybrid work, increasing cyber threats, and growing compliance obligations have exposed the limitations of traditional, on premises management tools. At the same time, Microsoft has continued to invest heavily in Microsoft Intune, expanding both its capabilities and its value through Microsoft 365 licensing.
The developments announced throughout 2026 represent more than incremental product updates. They signal Microsoft’s continued move towards a cloud native endpoint management platform that combines device management, identity, security, automation, and AI into a single service.
For IT leaders still relying on traditional management infrastructure, the conversation is no longer whether to modernise, but how quickly they can.
The limits of traditional endpoint management
Traditional mobile device management (MDM) platforms and on premises management tools such as Microsoft Configuration Manager (formerly SCCM) were built for a different operating model. They assumed devices remained on corporate networks, administrators had reliable connectivity to endpoints, and organisations primarily managed Windows desktops.
Today’s environments look very different.
Workforces are distributed, organisations support Windows, macOS, iOS, Android, and purpose-built devices, and security threats evolve far faster than traditional maintenance windows. Maintaining on premises infrastructure also introduces ongoing costs for servers, storage, upgrades, and administration that many organisations are looking to reduce.
Cloud native endpoint management has become less about replacing infrastructure and more about enabling a modern security and operational model.
What changed in 2026 and why it matters
Advanced Intune capabilities are now included with Microsoft 365 E3 and E5
One of the biggest Microsoft endpoint management announcements this year is the inclusion of advanced Microsoft Intune capabilities within Microsoft 365 E3 and E5 subscriptions from 1 July 2026.¹
Under the updated licensing model
Microsoft 365 E3 includes
- Microsoft Intune Plan 2
- Remote Help
- Advanced Analytics
- Microsoft Tunnel for Mobile Application Management
- Firmware Over-the-Air updates for supported devices
- Speciality Device Management
Microsoft 365 E5 additionally includes
- Endpoint Privilege Management
- Enterprise Application Management
- Microsoft Cloud PKI¹
It is important to distinguish licensing from deployment. While entitlement became effective on 1 July 2026, Microsoft is rolling out these capabilities progressively across customer tenants. Some organisations will receive the features later than others, and Microsoft advises administrators to monitor the Microsoft 365 Admin Centre for rollout notifications.¹
For organisations already invested in Microsoft 365, these additions significantly increase the value of existing licensing and reduce the need for separate endpoint management investments.
AI is becoming part of everyday endpoint administration
Microsoft continues to integrate Security Copilot capabilities into Microsoft Intune, allowing administrators to investigate compliance issues, understand security posture, troubleshoot policies, and analyse endpoint data using natural language within the Intune admin centre.²
Security Copilot also assists with Endpoint Privilege Management by helping administrators evaluate application elevation requests using Microsoft Defender threat intelligence.
As Microsoft continues expanding AI across its security portfolio, endpoint administration is becoming increasingly proactive rather than reactive.
Apple’s move to Declarative Device Management changes the game
Apple’s transition to Declarative Device Management (DDM) represents one of the most significant changes for organisations managing Apple devices.
With the release of Apple OS 26, Apple deprecated legacy MDM software update commands, requiring organisations to move towards Declarative Device Management for modern software update management. Microsoft Intune provides native support for DDM, allowing organisations to prepare ahead of Apple’s ongoing transition away from legacy management methods.³
For organisations still relying on older Apple management workflows, this transition reinforces the need to modernise endpoint management platforms.
Industry recognition reflects the direction of the market
Microsoft was recognised as a Leader in The Forrester Wave™ Endpoint Management Platforms, Q2 2026.⁴
Forrester highlighted the growing importance of platforms that integrate endpoint management with identity, security, compliance, and AI driven operations, rather than focusing solely on device configuration.
This reflects a broader industry shift. Endpoint management is no longer an isolated administrative function. It has become a foundational component of Zero Trust security and modern workplace strategy.
What this means for IT decision makers
If your organisation licenses Microsoft 365 E3 or E5, you may already be entitled to significantly more Intune capability than you are currently using. As Microsoft’s rollout progresses, many organisations will gain advanced endpoint management functionality without purchasing additional standalone licences.¹
If you continue to operate Configuration Manager or another legacy MDM platform, the business case for cloud native management continues to strengthen. Modern provisioning through Windows Autopilot, co-management, integrated identity, and cloud based policy management provide a more agile and scalable operating model.
For organisations operating in regulated industries, the integration between Microsoft Intune, Microsoft Entra ID, Microsoft Defender, and Microsoft Cloud PKI supports stronger security controls, improved compliance, and simplified audit readiness through a unified Microsoft platform.
The bottom line
Endpoint management continues to evolve rapidly.
Microsoft’s licensing changes, continued AI investment, support for Apple’s Declarative Device Management model, and recognition from independent analysts all reinforce the direction of travel for enterprise endpoint management.
For many organisations, the question is no longer whether Microsoft Intune should play a central role in endpoint management. The real opportunity is ensuring you are taking full advantage of the capabilities already available within your Microsoft investment.
Whether you’re planning a migration from Configuration Manager, looking to optimise an existing Intune deployment, or preparing to adopt the latest capabilities included with Microsoft 365 E3 and E5, success depends on more than simply enabling new features.
Insentra’s Managed Intune service helps organisations design, deploy, secure, and continuously optimise their Microsoft Intune environment. From tenant uplift aligned with CIS benchmarks and policy optimisation through to Secure Score improvement, proactive monitoring, lifecycle management, and 24 by 7 expert support, our specialists help you maximise the value of your Microsoft investment while reducing operational complexity.
Learn how Insentra’s Managed Intune service can help you build a more secure, modern endpoint management platform.
Source
1. Microsoft Learn. Planning guide to move to Microsoft Intune
https://learn.microsoft.com/en-us/intune/fundamentals/planning-guide
2. Microsoft Learn. Planning guide to move to Microsoft Intune (Copilot in Intune licensing and capabilities)
https://learn.microsoft.com/en-us/intune/fundamentals/planning-guide
3. Microsoft Learn. What’s new in Microsoft Intune and Microsoft Intune Customer Success Blog. Move to Declarative Device Management for Apple software updates
4. Microsoft Intune Blog. Advanced Microsoft Intune capabilities now available in Microsoft 365 E3 and E5
https://techcommunity.microsoft.com/blog/microsoftintuneblog/advanced-microsoft-intune-capabilities-now-available-in-microsoft-365-e3-and-e5/4529335






