The device management problem for small businesses
When a small business grows past 5 people, device management becomes a real problem. You have laptops in different locations, phones accessing company email, and no way to know whether they're all encrypted and up to date.
The typical response is one of three things:
1Nothing - hope for the best, deal with problems when they happen
2Manual IT visits - expensive, slow, doesn't scale
3A contracted IT person - costly, and they can only be in one place at a time
Microsoft Intune is the fourth option: a cloud-based device management platform that lets you control every company device from a single dashboard, regardless of where those devices are.
What Intune actually does
Intune sits between your devices and your company's cloud accounts. When a device tries to access Microsoft 365 email, Teams, or SharePoint, Intune checks whether that device meets your security requirements first.
Patch speed is the reason this stops being administrative housekeeping and becomes a control. Mandiant measured the average time from disclosure to exploitation in the wild falling from 63 days in 2018-19 to 5 days in 2023[1].
Average time from disclosure to exploitation in the wild
Days
2018-2019
2020-2021
2021-2022
2023
A patch cycle measured in weeks was defensible when exploitation took two months. Mandiant excluded 15 statistical outliers to reach the 5-day figure for 2023; including them the average is 47 days. Either way the direction is one way, and its 2026 report puts the mean at negative seven days - exploitation before the patch ships.
Show the data
Column chart showing average time-to-exploit falling from 63 days in 2018-2019, to 44 days in 2020-2021, 32 days in 2021-2022, and 5 days in 2023.
Its 2026 report puts the mean at negative seven days - exploitation routinely happening before a patch exists[2]. A monthly manual patch round cannot meet that; an automated update ring can[3].
What you can enforce from the Intune console:
BitLocker disk encryption - automatically enabled on all Windows devices
Password policies - minimum length, complexity, lockout after failed attempts
Windows Update rings - devices automatically install updates within a defined window, not whenever the employee gets around to it
App deployment - push approved software to every device silently
Conditional Access - block login from unmanaged or non-compliant devices
What you can do when something goes wrong:
Remote lock - lock a device immediately if it's lost or stolen
Remote wipe - delete all company data from the device; the employee's personal files remain untouched[4]
Retire - unenrol a device from management (used when someone leaves the company)
What an Intune rollout actually takes for a 15-person business
Elapsed working time
Timeline of an Intune rollout for a 15-person business: 4-6 hours of tenant configuration, 2-3 hours setting update rings, 3-4 hours of Apple Business Manager integration, a one-day pilot, then 3-5 days of fleet enrolment.
1
Tenant configuration and compliance policies4-6 hours
Encryption, screen lock, minimum OS version and the baseline your devices are measured against.
2
Update rings and deferral windows2-3 hours
The pilot ring patches first, the fleet follows a few days later, with a deadline that installs regardless.
3
Apple Business Manager integration (Macs only)3-4 hours
4
Pilot enrolment on 2-3 devices1 day
5
Fleet enrolment, remaining devices3-5 days
Runs alongside normal work - devices enrol as people log in, without a rebuild.
The update-ring step is the short one and the decisive one: it is what turns patching from a monthly manual round into something that keeps pace with a mean time-to-exploit now measured in negative days.
TechSuit deployment timings from Intune rollouts for businesses of 10-25 people.
What it costs and what's included
Intune is included in Microsoft 365 Business Premium at approximately €22/user/month. For a 10-person business, that's around €220/month - which also includes Outlook, Teams, SharePoint, OneDrive, Word, Excel, PowerPoint, and Microsoft Defender endpoint protection.
If you need Intune without the full M365 suite (for managing Macs in a Google Workspace environment, for example), standalone Intune Plan 1 licences are available at approximately €8/user/month[5].
Macs and iPhones, managed the same way
Intune manages Windows, macOS, iOS, and Android[6]. Mac management requires Apple Business Manager integration, which takes a few hours to configure. iPhone and Android management is simpler and covers the key requirements (email profile, remote wipe, VPN if needed).
Questions we get asked
Sources
Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.
Don't know what's running on every company device?
Book a free 30-minute call. We'll walk through your current device setup and show you what Intune would give you - and whether M365 Business Premium already covers the cost.