What’s Included
After the transfer or initial implementation described in the Onboarding section, Managed Solution will provide managed mobile device management (“MDM”) services utilizing Microsoft Intune to continuously manage and secure Client’s mobile device fleet across corporate-owned, BYOD, and kiosk devices. Managed Solution will maintain ongoing oversight of device enrollment, configuration profile management, application deployment, and security compliance policy enforcement to ensure that Client’s endpoints remain secure, compliant, and operational on a 24/7 basis.
Services include:
-
Managed Solution will configure Intune tenant settings and enrollment restrictions, including platform controls, minimum OS version requirements, and ownership type classifications (corporate-owned, BYOD, and kiosk). We will enroll and register devices across iOS and Android platforms using automated enrollment workflows such as Apple Automated Device Enrollment (ADE) and Android Enterprise, and will implement conditional access rules enforcing enrollment and compliance prior to accessing corporate resources. We will also manage device retirement and remote wipe procedures for lost, stolen, or decommissioned devices in accordance with Client’s policies.
-
Managed Solution shall deploy and maintain managed applications through Intune, including the Microsoft 365 mobile suite and approved third-party applications, using both device-based and app-based management policies. We will manage licensing distribution, application versioning, and update approvals, and will configure application protection policies (APP) to enforce data loss prevention controls (e.g., restricting copy/paste, requiring PIN access, and preventing data transfer to unmanaged applications) on both enrolled and unenrolled devices where applicable. Third party app management for Windows applications requires Intune Suite licensing and apps must be listed in the Enterprise App catalog.
-
Managed Solution will configure and maintain Intune compliance policies to ensure managed devices meet Client’s security standards prior to accessing corporate resources. This includes enforcing device encryption requirements, minimum OS version thresholds, screen lock and PIN policies, jailbreak and root detection, and integration with Microsoft Defender for Endpoint or equivalent mobile threat defense solutions where applicable. Non-compliant devices will be flagged and subject to conditional access restrictions until compliance is restored, and Client will be notified of persistent or unresolved compliance violations.
-
Note: Pricing excludes Microsoft Intune licensing. Client is responsible for maintaining applicable Intune licensing under a Microsoft Cloud Support Agreement or equivalent licensing arrangement. Managed Solution can assist Client in procuring the required licensing if needed.