Skip to main content
Valto — Keep ahead of tomorrow

Security

Microsoft Intune & endpoint management

Manage and secure every device your people work on, including the ones you do not own. Valto deploys and manages Microsoft Intune: device compliance and security baselines, zero-touch provisioning with Windows Autopilot, application protection on personal phones, and migration from a third-party MDM or on-premises Configuration Manager. We also help you have the conversation with your staff about what Intune can and cannot see, which is usually what actually decides whether a rollout succeeds.

Cloud and padlock illustration
Microsoft Solutions Partner

Trusted by organisations like yours

Mind
Greene King
Grosvenor
City of London logo
Chester Zoo
ABM
Human Appeal
John Deere
UKTV
Astrazenica
Money Supermarket
Princes
Sony
Shell
BBC
OVERVIEW

Every device, including the ones you do not own

Most organisations manage the laptops they bought and hope for the best with everything else. Personal phones reading company email, a contractor's machine on the network for six months, tablets shared between shifts on a site, and a handful of laptops issued before anyone was tracking them. Policy reaches the devices that happened to be enrolled. The gap is not usually capability. Intune is included in Microsoft 365 Business Premium, E3 and E5, so most organisations are already licensed for it and using a fraction of what it does, or paying a third party for something it covers. Valto establishes what is actually managed today and what is not, then puts consistent policy across the estate: compliance and security baselines, encryption and patching, application protection on personal devices, and zero-touch provisioning so a new starter's laptop arrives ready to work without anyone touching it. We also help you explain it to your staff. Intune rollouts stall on people not wanting their phone managed far more often than on anything technical, and that conversation goes considerably better when somebody can say precisely what the organisation can and cannot see.

What can Valto deliver with Intune?

Our specialists establish what is managed today, what your licences already cover and where the gaps are, before recommending an approach.

Device compliance and security baselines

Encryption, patching, password and access policy, and Microsoft's recommended security baselines applied consistently across Windows, macOS, iOS and Android rather than to whichever devices happened to be enrolled.

Windows Autopilot and zero-touch provisioning

A new laptop shipped from the supplier straight to the person who needs it, configuring itself on first boot into a managed, compliant, application-loaded device. No imaging, no visit, no IT time per machine.

BYOD and application protection

Protect company data on personal phones and laptops without managing the whole device, using application protection policies that control the corporate applications and leave everything else alone.

Migration from third-party MDM

Move from MobileIron, Ivanti, Workspace ONE, Jamf or Meraki Systems Manager onto a platform your Microsoft licences already include, with a plan for re-enrolment that does not lock people out of their own devices.

Configuration Manager co-management and migration

Where you still run Configuration Manager on premises, we establish which workloads should move to Intune, which should stay, and how to run both while that happens.

Managed endpoint support

Ongoing policy management, compliance monitoring, application deployment and patch oversight, with defined ownership of what sits with us and what sits with your team.

Our Intune services

Establish what is actually managed

We review which devices are enrolled, which are not, what policy reaches them, how your licences are being used and what you are paying a third party for. You get a coverage picture and a prioritised plan. Almost every assessment finds devices in active use that no policy reaches. Usually more than anyone expected.

Expertise
Microsoft endpoint and identity specialists
Coverage
Every device, not the enrolled ones
Value
Included in licences you already hold

What Intune can and cannot see on a personal device

Intune rollouts are delayed by people not wanting their phone managed far more often than by anything technical. The concern is reasonable and it is usually based on assumptions rather than on what the tool actually does. This is the honest answer.

Intune keeps information about the device rather than about the person. Required data includes the username, hardware information, administrative and account information, the audit log and application inventory. Optional diagnostic data, covering error reporting and performance analytics, can be switched on or off. Specifically, it can see the device type and manufacturer, the device owner and name, the serial number and IMEI, the operating system, and some level of application inventory.
On a personal device, Intune shows only the managed corporate applications. On a company-owned or fully managed device, it shows the full application inventory. That distinction is the single most useful thing to be able to tell somebody who is reluctant to enrol.
Browsing history. Passwords. Contacts. Images. Files. Emails. Calendar. Text messages. Call history. Location on a personally owned device.
Where staff are unwilling to enrol a personal device at all, application protection policies can secure the company data inside the corporate applications without managing the device itself. The organisation controls the corporate application and its data; nothing else on the phone is touched, and nothing else is visible.
Power Apps Envisioning Workshop

WHAT WE TYPICALLY FIND

Where device management turns out to be partial

Very little of what we find is missing licensing. It is devices nobody enrolled, policy that reaches part of the estate, and provisioning still being done by hand.

  • Devices in active use that were never enrolled, so no policy reaches them
  • Intune licensed in Business Premium or E3 and barely used
  • A third-party MDM being paid for alongside an Intune licence that covers the same ground
  • Personal phones with company email and no application protection policy
  • Contractors and temporary staff on unmanaged machines with full access

Turn endpoint management into business value

Device management is easier to fund when it is clear what changes. These are the outcomes the work is for.

Autopilot means a device is enrolled at purchase and provisions itself on first boot. For an organisation issuing even a few machines a month, that is a recurring block of IT time removed, and it scales with how distributed your people are.
Where you pay separately for device management while holding Intune in your Microsoft licences, consolidating removes a licence, a console and a supplier.
Application protection policies secure company data inside the corporate applications without managing the personal device. That is often the difference between a BYOD policy that people accept and one that gets resisted.
Secure configuration, security update management and malware protection are delivered largely through device management. Getting this right closes three of the five technical control areas.
Encryption enforced, access conditional on compliance, and remote wipe available means a laptop left on a train is an inconvenience rather than a notifiable event.
A new starter's device arrives ready. A leaver's device is wiped of company data and its licence reclaimed. Both currently depend on somebody remembering.

How we deliver Intune projects

From establishing what is managed today, through to consistent policy across the estate and provisioning that does not need anybody's time.

  1. Security assessments
    1

    Assessment

    Understand the current environment

    We assess your current device landscape, existing enrolment, security policies and licensing position. This establishes what is managed, what is not, what you are paying a third party for and what your Microsoft licences already cover.

  2. SharePoint Consultant hosting a requirements workshop
    2

    Planning

    Design the policy and enrolment model

    We define the compliance policies, security baselines, configuration profiles and enrolment methods appropriate to your organisation, including how corporate and personal devices are treated differently, and agree the communications for staff.

  3. People working on computers
    3

    Configuration

    Build and pilot

    We configure the policies and applications and test them with a pilot group, because device policy is felt by users and the problems only surface on real devices.

  4. Woman working at a computer
    4

    Enrolment

    Roll out in waves

    Devices are enrolled in controlled groups, with Autopilot set up for new hardware and a defined path for existing machines, so nobody loses access to their own device unexpectedly.

  5. 5

    Compliance & ongoing management

    Keep coverage from drifting

    We connect compliance to conditional access so policy is enforced rather than reported, then review coverage, new devices, leavers and Microsoft's changing baselines on an agreed cycle.

We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For our clients, that means working with specialists who understand how devices, identity and access fit together rather than treating device management as a separate exercise. Whether you're enrolling devices for the first time, moving off a third-party platform or working out why policy is not reaching everything, we help organisations get consistent control of the devices their people actually use.

WHY ORGANISATIONS CHOOSE VALTO

Microsoft Solutions Partner
Apps on a phone

CONNECTED, ACROSS MICROSOFT

A compliant device only matters if access depends on it

Intune decides whether a device meets your standard. Entra ID conditional access decides whether that matters. An organisation with well-configured compliance policies and no conditional access enforcing them has an accurate report and no protection. Valto brings together expertise across Microsoft 365, Entra ID, Defender, Purview and Azure. That lets our consultants connect device compliance to the access model, deploy and enforce Defender for Endpoint through Intune rather than separately, and apply data protection policies that work the same way on a managed laptop and a personal phone. The result is one consistent position across devices, identity and data, rather than three tools each doing part of the job.

auger case study
Auger working with Microsoft Partner Valto

Valto modernises Auger's Microsoft 365 environment to support remote working

Valto worked with Auger to migrate their legacy Exchange environment to a modern solution, utilising Intune for device security.

  • Tightened security
  • Increased employee engagement
  • Tightened security
Read the story

The team driving you forward

Rob Thomas
Rob ThomasMS365 & Azure Business Unit Lead
SharePoint Consultant hosting a requirements workshop
Harry BarnettPre-Sales Consultant
Girl with trophy
Will JonesSenior Cloud Consultant
James BelseySenior Project Manager

Questions, answered plainly

Practical answers on what Intune can and cannot see, whether your licences already include it, what happens to personal devices, and how a rollout is phased.

No, not in the way people usually fear. Intune records information about the device rather than about you: device type and manufacturer, name and owner, serial number and IMEI, operating system, and the managed corporate applications. It does not track browsing history, passwords, contacts, images, personal files, emails, calendar, text messages or call history. On a personal device, application inventory shows only the managed corporate applications, not everything you have installed.
No, and for personal devices we usually recommend you do not. Application protection policies secure the company data inside the corporate applications, controlling whether it can be copied out, backed up or opened elsewhere, without managing the device itself. Nothing else on the phone is touched or visible.
Probably. Intune is included in Microsoft 365 Business Premium, E3 and E5, and in the EMS plans. Device-only licences are also available for shared, kiosk or frontline devices that are not assigned to a named person. We confirm your exact position first, and in a good number of cases the useful work is configuration rather than purchase.
It means a new device is enrolled at the point of purchase and configures itself on first boot into a managed, compliant machine with applications installed. In practice, the laptop is shipped from the supplier straight to the person who needs it and nobody in IT touches it. It removes the build time per device entirely, and the saving grows the more distributed your people are.
Windows, macOS, iOS, Android, and also Linux and ChromeOS. It covers corporate-owned and personally owned devices, with different management approaches for each, and shared devices used by several people.
Substantially. Secure configuration, security update management and malware protection are three of the five technical control areas and all three are largely delivered through device management, with user access control partly so too. We configure with the certification in mind where that matters to you, and give you the evidence.
If you want us to. Some organisations take ownership with documentation and knowledge transfer; others prefer we retain policy management, compliance monitoring and patch oversight. Either way the scope, the hours and who authorises changes that affect users are written down rather than assumed.
That should be defined rather than improvised, and it usually is not. Corporate data can be removed from a personal device without touching anything else, and a company device can be wiped and reissued or retired with its licence reclaimed. We build that into the lifecycle design, because it is where both the security exposure and the licence waste sit.
Microsoft Intune is Microsoft's cloud-based endpoint management platform. It manages and secures the devices and applications your people use for work, across Windows, macOS, iOS, Android, Linux and ChromeOS, covering both company-owned and personal devices. It is included in Microsoft 365 Business Premium, E3 and E5, and works alongside Microsoft Entra ID, Defender and Purview to make access to company data conditional on the device meeting your standards.

Free Intune consultation

Find out which devices you are actually managing

Whether you're enrolling devices for the first time, moving off a third-party platform, planning Autopilot, working towards Cyber Essentials, or trying to work out why policy is not reaching everything, start by establishing your current coverage.

  • Microsoft endpoint specialists

    Speak directly with consultants who configure and manage these environments every day.

  • Start with what you own

    Intune is included in Business Premium, E3 and E5. We confirm what your licences already cover before recommending anything new.

  • We help you explain it to your staff

    A clear, honest account of what Intune can and cannot see, in a form you can circulate before anything changes.

  1. 1
  2. 2
What is your enquiry about?*