Mobile devices, laptops and personal smartphones are today's primary access point to business data – and the biggest risk for Swiss SMBs. Microsoft Intune is Microsoft's endpoint management solution (MDM/MAM) and is already included in Microsoft 365 Business Premium. This guide shows Swiss SMBs how to deploy Intune productively in 2026.
What is Microsoft Intune?
Microsoft Intune (part of the Microsoft Intune Suite) is a cloud-based endpoint management platform. It covers:
- Mobile Device Management (MDM) – managing the full device
- Mobile Application Management (MAM) – protecting data in single apps (BYOD)
- Endpoint configuration – policies for Windows 11, macOS, iOS, Android, Linux
- Endpoint security – antivirus, disk encryption, firewall, Defender integration
- App deployment – Microsoft Store, Win32 apps, LOB apps, updates
Prerequisites for Swiss SMBs
| Item | Recommendation |
|---|---|
| Licence | Microsoft 365 Business Premium (~CHF 22 / user / month) or M365 E3/E5 |
| Identity | Microsoft Entra ID Premium P1 (included in Premium / E3) |
| Tenant | Default region Switzerland for Swiss data centres |
| Devices | Windows 11 (Pro / Enterprise), macOS, iOS 16+, Android 10+ |
| Pilot | 5–10 devices from a pilot department |
The six phases of an Intune rollout
1. Discovery (1–2 weeks)
- Inventory of all devices (corporate vs. BYOD)
- Existing MDM solution (often Active Directory Group Policy – or none)
- Apps and use cases per persona
- Compliance requirements (FADP, ISO 27001, FINMA)
2. Tenant setup (1 week)
- Microsoft Entra ID hardening (see security page)
- Enable device platforms (Windows / Apple / Android)
- Apple Business Manager / Android Enterprise configuration
- Baseline Conditional Access policies
3. Compliance policies (2 weeks)
- Windows 11 – BitLocker, Defender, min OS, firewall
- macOS – FileVault, SIP, min OS
- iOS – passcode, jailbreak detection, min OS, app restrictions
- Android – Work Profile, encryption, verified boot, min OS
Devices that fail compliance are blocked from M365 by Conditional Access.
4. Configuration profiles (2–3 weeks)
- Wi-Fi profiles (e.g. CNEXT-Corporate)
- VPN configuration (always-on for laptops)
- Email profiles (auto-configure Outlook)
- Browser hardening (Microsoft Edge security policies)
- BitLocker / FileVault recovery keys stored in Entra ID
5. App deployment (2 weeks)
- Microsoft 365 Apps update channel (Monthly Enterprise recommended)
- LOB apps (e.g. Bexio, Abacus, Swisscom apps)
- Win32 app packaging with Intune Win32 Content Prep Tool
- Microsoft Store apps
- Update rings for Windows 11 feature and quality updates
6. Pilot, rollout and adoption (4–8 weeks)
- Pilot group of 5–10 devices / personas
- Helpdesk training
- Employee communication (what changes, what stays private – key for BYOD)
- Wave rollout (e.g. 25 devices / week)
BYOD with Microsoft Intune
In Swiss SMBs, personal smartphones for Outlook and Teams are common. With MAM (app protection policies), Intune protects business data inside the apps – without managing the whole private device:
- Business data cannot be copied to personal apps
- Business data requires PIN / biometrics to open
- Remote wipe only of business data
- Personal photos remain private
Important for FADP compliance: clear employee information and consent for BYOD.
Microsoft Defender for Endpoint integration
With Microsoft Defender for Business (included in M365 Business Premium), Intune becomes a complete endpoint security platform:
- Antivirus / antimalware
- Endpoint Detection & Response (EDR)
- Attack Surface Reduction rules
- Web protection (anti-phishing)
- Vulnerability management with Microsoft Defender Vulnerability Management
Swiss specifics
- Data residency: Intune data sits in the EU Data Boundary; telemetry can be reduced
- Languages: UI in DE / FR / IT / EN for multilingual Swiss teams
- Local apps: Bexio, Abacus, Swisscom apps deployable via Intune
- Home-office laptops: always-on VPN, Conditional Access and Defender for Endpoint are mandatory
FAQ
Do we really need Intune if all devices are in the office? Yes. Intune provides patch management, compliance, reporting and Conditional Access for fixed devices too – and it is included in Microsoft 365 Business Premium.
How does Intune integrate with our existing Active Directory? Hybrid scenarios are supported (Hybrid Azure AD Join, co-management with SCCM/Intune). For SMBs CNEXT usually recommends moving to cloud-only with Entra ID + Intune.
What does an Intune rollout cost for a 50-person SMB? Typically CHF 15,000–35,000 for discovery, concept, implementation and training – depending on device count and compliance.
Can we manage Apple devices (Mac, iPhone) as well? Yes. Intune supports Windows, macOS, iOS and Android equally. Apple Business Manager (free for Swiss companies) is required for Apple.
Conclusion
Microsoft Intune is the 2026 standard for endpoint management in Swiss SMBs. With Microsoft 365 Business Premium it is included – use it. CNEXT, a Microsoft Solutions Partner in Bern, runs structured Intune rollouts for Swiss SMBs.

