Choose between Basic Mobility and Security and Intune - Microsoft 365 admin (2024)

  • Article

Microsoft Intune is a standalone product included with certain Microsoft 365 plans, while Basic Mobility and Security is part of the Microsoft 365 plans.

Availability of Basic Mobility and Security and Intune

Both Basic Mobility and Security and Intune are included in various plans, described in the following table.

PlanBasic Mobility and SecurityMicrosoft Intune
Microsoft 365 AppsYesNo
Microsoft 365 Business BasicYesNo
Microsoft 365 Business StandardYesNo
Office 365 E1YesNo
Office 365 E3YesNo
Office 365 E5YesNo
Microsoft 365 Business PremiumYesYes
Microsoft 365 Firstline 3YesYes
Microsoft 365 Enterprise E3YesYes
Microsoft 365 Enterprise E5YesYes
Microsoft 365 Education A1YesYes
Microsoft 365 Education A3YesYes
Microsoft 365 Education A5YesYes
Microsoft IntuneNoYes
Enterprise Mobility & Security E3NoYes
Enterprise Mobility & Security E5NoYes

Note

You can't start using Basic Mobility and Security if you're already using Microsoft Intune.

For details, see Microsoft 365 and Office 365 platform service descriptions.

See Also
Robin Hobo

Differences in capabilities

Microsoft Intune and built-in Basic Mobility and Security both give you the ability to manage mobile devices in your organization, but there are key differences in capability, described in the following table.

Note

You can manage users and their mobile devices using both Intune and Basic Mobility and Security in the same Microsoft 365 Business Standard organization by setting up Basic Mobility and Security first, and then adding Microsoft Intune. This allows you to choose Basic Mobility and Security or the more feature-rich Intune solution. Assign an Intune license to enable the Intune features.

Feature areaFeature highlightsBasic Mobility and SecurityMicrosoft Intune
Device typesManaging different OS platforms and major management mode variants.Windows
iOS
Android
Android Samsung KNOX
Windows
iOS
Android
Android Samsung KNOX
mac OS, iPad OS
Device complianceSet and manage security policies, like device level PIN lock and jailbreak detection.Limitations on Android devices. See details.Yes
Conditional access based on device compliancePrevent noncompliant devices from accessing corporate email and data from the cloud.Not supported on Windows 10.
Limited to controlling access to Exchange Online, SharePoint Online, and Outlook.
Yes
Device configurationConfigure device settings (for example, disabling the camera)Limited set of settings.Yes
Email profilesProvision a native email profile on the device.YesYes
WiFi profilesProvision a native WiFi profile on the device.NoYes
VPN profilesProvision a native VPN profile on the device.NoYes
Mobile application managementDeploy your internal line-of-business apps and from apps stores to users.NoYes
Mobile application protectionEnable your users to securely access corporate information using the Microsoft 365 mobile app and line-of-business apps they know, while ensuring security of data by helping to restrict actions like copy, cut, paste, and save as, to only those apps managed approved for corporate data. Works even if the devices aren't enrolled to Basic Mobility and Security. See Protect app data using MAM policies.NoYes
Managed browserEnable more secure web browsing using the Edge app.NoYes
Zero touch enrollment programs (AutoPilot)Enroll large numbers of corporate-owned devices, while simplifying user setup.NoYes

In addition to features listed in the preceding table, Basic Mobility and Security and Intune both include a set of remote actions that send commands to devices over the internet. For example, you can remove Microsoft 365 data from an employee’s device while leaving personal data in place (retire), remove Microsoft 365 apps from an employee's device (wipe), or reset a device to its factory settings (full wipe).

Basic Mobility and Security remote actions include retire, wipe and full wipe. For more information on Basic Mobility and Security actions, see capabilities of Basic Mobility and Security.

With Intune you have the following set of actions:

  • Autopilot reset (Windows only)
  • Bitlocker key recovery (Windows only)
  • Use wipe, retire, or manually unenrolling the device
  • Disable activation lock (iOS only)
  • Fresh start (Windows only)
  • Full scan (Windows 10 only)
  • Locate device (iOS only)
  • Lost mode (iOS only)
  • Quick scan (Windows 10 only)
  • Remote control for Android
  • Remote lock
  • Rename device
  • Reset passcode Restart (Windows only)
  • Update Windows Defender Security Intelligence (Windows only)
  • Windows 10 PIN reset (Windows only)
  • Send custom notifications (Android, iOS, iPad OS)
  • Synchronize device

For more information on Intune actions, see Microsoft Intune documentation.

Choose between Basic Mobility and Security and Intune - Microsoft 365 admin (2024)
Top Articles
Latest Posts
Article information

Author: Dean Jakubowski Ret

Last Updated:

Views: 6382

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Dean Jakubowski Ret

Birthday: 1996-05-10

Address: Apt. 425 4346 Santiago Islands, Shariside, AK 38830-1874

Phone: +96313309894162

Job: Legacy Sales Designer

Hobby: Baseball, Wood carving, Candle making, Jigsaw puzzles, Lacemaking, Parkour, Drawing

Introduction: My name is Dean Jakubowski Ret, I am a enthusiastic, friendly, homely, handsome, zealous, brainy, elegant person who loves writing and wants to share my knowledge and understanding with you.