← Back to blog
Microsoft 365

Intune Suite included in Microsoft 365 E3 and E5: what every IT admin should enable now

By Zarioh Digital Solutions5 min read
Share
Intune Suite included in Microsoft 365 E3 and E5: what every IT admin should enable now

From 1 August 2026, most Intune Suite capabilities are included in standard Microsoft 365 E3 and E5 licences. Remote Help, Advanced Analytics, and Endpoint Privilege Management come at no extra cost. What is ready in your tenant, and where do you start?

In early July 2026, Microsoft made an announcement that many IT administrators had to read twice: most Intune Suite capabilities would be included at no extra charge in existing Microsoft 365 E3 and E5 licences. The rollout began in June, proceeded tenant by tenant with a thirty-day notice in the admin centre, and was fully complete by 1 August 2026. If your organisation holds M365 E3 or E5, there are features ready in your tenant that you probably have not yet switched on.

Until recently, the Intune Suite was a separate add-on at roughly eight euros per user per month, on top of the base licence. For many organisations, that was a barrier. With the integration into E3 and E5, that barrier disappears. The question is no longer whether you use these capabilities, but when and how you configure them.

What is included in E3?

Microsoft 365 E3 licences are extended with Intune Plan 2, Remote Help, Advanced Analytics, Microsoft Tunnel for MAM, and management of specialised devices such as VR headsets and meeting-room displays. These are capabilities that were previously exclusive to organisations with an Intune Suite subscription.

Remote Help is immediately usable for helpdesk teams. Technicians connect via Entra ID to an end user's device once a session is requested. Each session is tied to an identity and fully logged, including which actions were taken. That makes Remote Help not only practical but also auditable, which matters for organisations in regulated sectors.

Advanced Analytics extends the existing Endpoint Analytics reporting with three new capabilities: device query, which lets an administrator retrieve real-time information about a specific device; anomaly detection, which signals deviations in device behaviour at an early stage; and battery health reporting, which shows per device how quickly battery capacity is declining. For organisations with a large laptop fleet, the latter is a useful input for replacement decisions.

Microsoft Tunnel for MAM allows unmanaged mobile devices — without Intune fully managing the device — to access on-premises resources through a secured tunnel. This is particularly relevant for BYOD scenarios where employees use personal phones but still work with internal applications.

What does E5 add on top?

E5 licence holders receive everything that comes with E3, plus three additional capabilities not available for E3: Endpoint Privilege Management, Enterprise Application Management, and Cloud PKI.

Endpoint Privilege Management (EPM) is the most strategically significant of the three for organisations working toward least-privilege. EPM lets administrators grant end users temporarily elevated rights for specific tasks — such as installing an approved application — without the account holding permanent local administrator rights. Every request and approval is logged. This replaces the practice of permanent local admin rights, one of the most exploited paths in ransomware attacks.

Enterprise Application Management (EAM) provides a catalogue of pre-packaged applications that administrators can distribute through Intune without having to manage installers themselves. Application updates are pushed automatically as soon as a new version appears in the catalogue. That relieves the IT team of a recurring manual task.

Cloud PKI replaces the traditional on-premises certificate infrastructure (NDES/SCEP) with a fully cloud-managed PKI. Devices receive their certificates through Intune without requiring an on-premises server. For organisations working to decommission on-premises infrastructure, this is a logical next step.

What does this mean for existing Intune Suite customers?

Organisations that already paid for a separate Intune Suite licence do not need to act. The functionality remains available and the add-on licence expires at the next renewal date. Microsoft has communicated separately with these customers through licence management in the admin centre. The transition is transparent: no functionality is lost.

Where do you start?

The order in which you configure the new capabilities depends on your current pain points. An approach that works for most IT teams follows three priorities.

First priority is Remote Help if you are still working with remote RDP connections, external management tools, or uncontrolled screen-sharing sessions. Remote Help replaces those with a solution that runs fully through Entra ID, grants session-based access, and keeps an audit log. For a helpdesk team of three people, this is typically configured in an afternoon.

Second priority is Advanced Analytics, specifically device query, if you need visibility into individual devices outside the normal reporting cycle. The battery health overview is a good starting page: it quickly shows which devices are due for replacement and helps you build a substantiated replacement plan.

Third priority — but the highest in terms of impact for E5 customers — is Endpoint Privilege Management if your end users currently have permanent local administrator rights. EPM is the most direct way to remove that risk without disrupting productivity. You start with a pilot group, define which actions justify a temporary elevation, and then remove the permanent admin account.

Points to keep in mind when configuring

A few practical points to consider. Remote Help requires that both the technician and the end user have the Remote Help application installed — a small but necessary step that you can automate via an Intune app deployment. Advanced Analytics requires that the Intune Data Collection Policy is enabled on devices; without that policy, no sensor data is collected. Cloud PKI requires planning around the revocation of existing on-premises certificates; a migration plan is not optional, it is essential.

Finally: the new capabilities are available, but they are not automatically on. You have to consciously enable and configure them. Leaving them untouched means leaving licence value unused.

Getting started

Would you like to know which Intune Suite features are already available in your tenant, which you should activate first, or how to roll out EPM without disrupting your end users? Zarioh helps organisations configure and manage Microsoft 365 Intune environments. Contact us for a no-obligation conversation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share