Purpose and prerequisites
The purpose of this article is to describe authentication and device management that a small or mid-size firm will actually follow. The discussion assumes Microsoft 365 Business Premium, or another SKU that includes Intune Plan 1 and Entra ID P1. On Business Standard, multifactor authentication can be required through security defaults; the tenant cannot honestly say that only a healthy, enrolled device may open mail. Readers who are still choosing a license should begin with Business Standard vs Premium. The remainder of this article assumes that SKU decision is settled and that the work is to join identity policy to device control.
Authentication and Intune are one design. A compliant device with a password-only account is not a design. An MFA prompt on an unmanaged, unencrypted laptop is only slightly better. Premium is the license that lets those two controls be joined. Using the license is the work described below.
Multifactor authentication for every mailbox
Security defaults already turn multifactor authentication on for Microsoft 365 business tenants. Those defaults should remain until Conditional Access is ready. The replacement policies should then require MFA for all users and all clouds, including older protocols that are still allowed; should block legacy authentication such as IMAP and POP with a password; and should prefer phishing-resistant methods where they can be required. If a scanner or copier still needs a password protocol, that device receives a dedicated mailbox and a tight exception, not a company-wide hole. SMS as the only factor is better than nothing and worse than an authenticator app or a passkey. Once Authenticator push is in place, the next authentication step is multi-device passkeys, because push and TOTP remain relayable.
Conditional Access instead of hope
Entra ID P1 is what allows the tenant to say more than “MFA, always.” The first useful policies for a firm of this size are few and named. Administrators should complete MFA every time, from a compliant device, with no persistent browser session. Everyone else should complete MFA, and should use a compliant Windows or macOS device or an app-protected iOS or Android client for Exchange and SharePoint. Guests should complete MFA and should not reach SharePoint unless the project actually needs it. Sign-ins that look like impossible travel or an unfamiliar location should require MFA again or be blocked, after the firm has looked at how its people travel. Three well-named policies beat a museum of unused drafts. Twenty policies on day one is how Conditional Access becomes folklore.
Break-glass accounts
Two cloud-only emergency administrator accounts should exist, with long random passwords stored in a sealed process that is not the office password manager everyone uses. Those accounts are excluded from most Conditional Access policies and are monitored for any sign-in. If they are never tested, they will not work the day Entra ID or the MFA vendor has an outage. The process that describes how to use them should live on paper as well as in a Teams channel, because the Teams channel depends on the tenant the firm is trying to recover. Break-glass is a tested procedure, not a pair of unused usernames.
Company devices in Intune
A company laptop should enroll during setup. Autopilot is appropriate when new hardware is purchased; a bulk or user enrollment covers what the firm already owns. Compliance we actually enforce on Windows is BitLocker with the recovery key escrowed to Entra or Intune, Secure Boot and a TPM where the hardware allows it, Defender antivirus with real-time protection and current signatures, the firewall on, and an operating system still in support. A machine that opens client files is not postponed to “we will upgrade next year.” Devices with no compliance policy should be marked as not compliant if Conditional Access is going to require compliance; otherwise a brand-new machine that has not checked in yet looks healthy. Lost or stolen devices are wiped from Intune. That is the feature owners remember after the first incident, and it only works if the device was enrolled before it left the building.
BYOD without taking over the phone
Most staff will not hand the firm a personal iPhone for full mobile device management, and the firm should not ask. App protection, or MAM, is the appropriate answer. Outlook, Teams, and OneDrive on iOS and Android receive a PIN, encryption, and rules that keep copy and paste inside the managed applications. A selective wipe removes company mail and files and leaves family photographs. Conditional Access can require an approved app with those protections without joining the phone to the corporate directory. If someone needs full device control — a warehouse scanner, a kiosk, a shared tablet — that device is a company device. A personal phone is not a kiosk, and pretending otherwise produces a policy nobody will follow.
Shared and frontline devices
A front-desk computer used by three people should not be whoever logged in last Tuesday. A shared-device or assigned-access model, or separate accounts that Intune can still constrain, is the correct shape. Shared devices are also where dedicated Teams phones belong; that design is described in Teams Phone. Identity and the plastic handset are separate questions, but both require an account the tenant can still control.
What users will tolerate
Adoption depends on how often people are interrupted, not on how many policies exist in draft. One extra prompt on a new PC or in a new country is tolerated. MFA every ten minutes on the same desktop is how people install a “helper” that steals tokens. Staff should be told why the personal phone is not fully managed; if the only story is that IT said so, they will forward mail to Gmail. The break-glass process should be documented on paper, not only in a channel that depends on the tenant being healthy. Those three habits are what keep the design from being routed around.
Authentication and Intune remain one design after the factor has changed. A compliant device with a password-only account is not a design. An MFA prompt on an unmanaged, unencrypted laptop is only slightly better. Premium is the license that lets those two controls be joined. Using it is the work.
Recommendations this practice will not make
This practice will not treat security defaults as a finished Conditional Access program. It will not enroll personal phones into full MDM as a condition of having mail. It will not leave break-glass accounts untested. Those refusals are part of the design. Business Standard vs Premium covers which SKU to buy. From Authenticator MFA to multi-device passkeys is the next authentication step once push MFA is no longer enough. The Assessment is the twelve-question version of this page. Organizations that want the design implemented rather than printed may contact us.
