Skip to content
Microsoft Intune for SCCM Admins Part 1

Microsoft Intune for SCCM Admins Part 1

Written By Anoop C Nair
Last Updated July 8, 2024
Posted In SCCM
SHARE

Let’s explore Microsoft Intune for SCCM Admins Part 1 and its key components. I’m hoping to cover a fair bit about it.

I aimed to become a System Administrator during college because I thought I wouldn’t have to learn anymore. However, I eventually realized that learning is an ongoing process, regardless of your profession. Nowadays, social media and technology news play a significant role, and we should keep ourselves updated with the latest trends and developments.

I don’t want to make this post very long, so I will divide it into multiple posts. I will cover the basics in the first part of Intune for SCCM admins. SCCM is excellent, and it will not die, as per Microsoft. But don’t abandon Intune learning. I strongly recommend going through the Intune learning process.

Microsoft Intune is a cloud-based tool by Microsoft designed to manage user access to company resources and control apps and devices across multiple platforms. Experienced SCCM (Configuration Manager) users are encouraged to transition to Microsoft Intune for future device management needs.

Patch My PC

What to Learn Intune? Great Resource Around you!

Index
What is Microsoft Intune for SCCM Admins?
Intune Servers & Management?
Intune Infra Administration
Discovery of User, Groups, & Devices
Client Installation & Upgrade
Collections & Groups
Configuration Items & Compliance Policies
Microsoft Intune for SCCM Admins Part 1 – Table.1

NOTE! – This post is from an SCCM Admin (Windows Device Management) perspective. You might have a different perspective, depending on your job role.

What is Microsoft Intune for SCCM Admins?

Intune can perform most of the SCCM functionalities. According to Microsoft, Intune is built on modern modular cloud components. Intune is a ready-to-use SaaS (Software-As-A-Service) solution from Microsoft for device management. This solution decouples the monolith services from development, deployment, and maintenance perspectives.

Microsoft Intune is a Microsoft Enterprise Mobility Management (EMM) solution. It helps manage all device flavours (Windows, iOS, Android, and macOS) and delivers network and other device management settings. 

Microsoft Intune combines Device, Application, Information Protection, Endpoint Protection (antivirus software), Security, and Configuration policy management solutions.

Intune Servers & Management?

Microsoft Intune for SCCM Admins Part 1 -Fig.1
Microsoft Intune for SCCM Admins Part 1 -Fig.1

Microsoft handles Intune servers and their management. Microsoft Intune is a software-as-a-service (SaaS) solution from Microsoft. The following are some of the useful points with Intune from some of the organizations’ perspectives.

  • There is no Server requirement to install Intune (Purchase an EMS or Microsoft 365 license and start using it)—Microsoft manages it.
  • Maintenance of servers is not required to update Intune to the latest version, which Microsoft manages.
  • Intune Web Console access anytime, anywhere – Managed by Internal IT (Intune Admin)
  • Intune admin won’t be able to check and edit Intune Database, unlike SCCM Database, which Microsoft manages.
  • Intune Admin doesn’t have the option to go back to the previous Intune version.
  • Perform Intune Server-side troubleshooting – Managed by Microsoft
Microsoft Intune for SCCM Admins Part 1 -Fig.2
Microsoft Intune for SCCM Admins Part 1 -Fig.2

Intune Infra Administration

As I mentioned above, Microsoft manages Intune server infra as this solution is SaaS. As an SCCM admin, all infra-admin tasks are in the Administration workspace. This is the logical view of Microsoft Intune for SCCM Admins.

There are very few or no server admin tasks for Intune admins. However, you might need to install connectors and global policies before starting Intune deployment. Most of these activities are one-time activities. You can just set up Intune and forget.

You might need to configure the following components from an Infra administration perspective.

Microsoft Intune for SCCM Admins Part 1 -Fig.3
Microsoft Intune for SCCM Admins Part 1 -Fig.3

Discovery of User, Groups, & Devices

SCCM can discover the resources from the network (Active Directory, Azure Active AD, or Network Discovery) and install clients on those devices. However, you don’t have to configure this for Intune.

Intune is tightly integrated with Azure Active Directory, and the Intune blade will have all the Device, User, and Group resources available for you to use without making any discovery configurations.

Microsoft Intune for SCCM Admins Part 1 -Fig.4
Microsoft Intune for SCCM Admins Part 1 -Fig.4

NOTE! Microsoft Intune Setup steps are explained in HTMD Intune Free Training.

Client Installation & Upgrade

SCCM client installation and enrollment methods are different from Intune enrollment options.

Unlike SCCM, Intune doesn’t have a separate client component. It manages Windows devices using the built-in MDM client agent component of the Windows 10 or Windows 11 Operating System. So, installing the Intune client on Windows 10 devices is unnecessary.

NOTE: Intune supports only Client operating systems. It does NOT support Windows Server Operating systems, so you won’t be able to manage servers with Intune.

NOTE! Intune Company Portal is an end-user application for Microsoft Intune. This app can be installed as an Intune client component on a Windows 10.

Two main Intune Enrollment Options are explained in the following blog posts. More details are available in my Intune Learning post. Intune enrollment can also be done via Microsoft Autopilot (Windows Autopilot).

Microsoft Intune for SCCM Admins Part 1 -Fig.5
Microsoft Intune for SCCM Admins Part 1 -Fig.5

NOTE 1 – No, there is nothing called Intune Client upgrade for Windows devices. Intune is using the Windows 10 MDM component for management. So, the MDM component will get updated with Windows 10 updates.

NOTE 2—Intune also uses the Intune Management Extension agent for Win32 App deployment. The installation and update of this agent are handled automatically in 99% of the scenarios.

Collections & Groups

SCCM collections are used to group the resources that you want to manage. There is no collection concept in Microsoft Intune.

Intune uses Azure AD User & Device groups instead of collections. You can create the following types of groups in Azure AD and deploy applications and policies to them.

Microsoft Intune for SCCM Admins Part 1 -Fig.6
Microsoft Intune for SCCM Admins Part 1 -Fig.6

NOTE! – Many years (I feel like) before even Intune had their own separate Intune Groups, and they removed Intune Groups as part of Azure Intune portal migration from the Intune Silverlight portal.

Configuration Items & Compliance Policies

SCCM CI (Configuration Items), Baselines, Compliance Policies, and others are available in Microsoft Intune. The following details would be helpful in Microsoft Intune for the SCCM admin’s context.

In the Intune portal, you can create similar policies (as mentioned above) from Device Compliance, Device Configuration, and Device Security nodes.

Microsoft Intune for SCCM Admins Part 1 -Fig.7
Microsoft Intune for SCCM Admins Part 1 -Fig.7

NOTE! – I will continue more settings and details in upcoming posts (Microsoft Intune for SCCM Admins Part 2). So, in this post, I covered the SCCM Administration, Assets & Compliance Workspace.

Resources

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His primary focus is Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 10 comments

  1. Hi. Can I use Microsoft Intune for patching with updates Windows servers that are physical servers non-domain joined ?

  2. But SCCM does it? Or there is any software develop by Microsoft that does manage physical non-domain joined Windows servers?

  3. sorry for replying back. i am still in confusion. I know SCCM requires AD integration. so my question is, can I use SCCM (which is part of an AD domain) to do server patching for physical NON-domain servers (servers that belong to WORKGROUP) ?

  4. I like to understand the backend flow (at the server level) what will happen when we enroll devices, add applications, create a policy in Intune Console. This is not about Push notification and how complete MDM flow occurs.

    I want to know activities that occur only at the server level.

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read