Without the proper tools and resources, managing hundreds or thousands of devices in a school environment can be a complex and time-consuming task. Microsoft Intune is a collection of services that simplifies the management of devices at scale.
The Microsoft Intune service can be managed in different ways.
Intune admin center is the primary Intune interface that supports the entire device lifecycle, from the enrollment phase through retirement. IT administrators can manage all settings across all Intune supported platforms.
Intune for Education is a curated view of Intune that supports the entire device lifecycle, from the enrollment phase through retirement. IT administrators can start managing classroom devices with bulk enrollment options and a streamlined deployment. At the end of the school year, IT admins can reset devices, ensuring they're ready for the next year.
Intune and Intune for Education both configure the Intune service. Changes made in one console will be reflected in the other. However, Intune for Education only supports a subset of policies and apps curated to suit simple K-12 scenarios on Windows and iPadOS.
In this section you will:
Review Intune's licensing prerequisites
Configure the Intune service for education devices
Prerequisites
✅ Check out the requirements for device management
Before configuring settings with Intune, consider the following prerequisites:
Intune subscription. Microsoft Intune is licensed in three ways:
Intune for Education device platforms. Intune for Education can manage devices running a supported version of Windows 10, Windows 11, Windows 11 SE, and iPadOS
Intune device platforms. Intune can manage devices running a supported version of Windows 10, Windows 11, Windows 11 SE, iOS, iPadOS, macOS, Android, and Linux
Network requirements. Confirm all the required network endpoints can access without SSL inspection or any type of filtering. See Network endpoints for Microsoft Intune for a list of endpoints.
For more information, see Intune licensing and this comparison sheet, which includes a table detailing the Microsoft Modern Work Plan for Education.
Configure the Intune service for Education devices
The Intune service can be configured in different ways, depending on the needs of your school. In this section, you configure the Intune service using settings commonly implemented by K-12 school districts.
Configure enrollment restrictions
✅ Restrict which devices can be managed
With enrollment restrictions, you control which devices can enroll and be managed by Intune. For example, you can prevent the enrollment of personal devices.
✅ Disable functionality typically inaccessible to students
Windows Hello for Business is a biometric authentication feature that allows users to sign in to their devices using a PIN, password, or fingerprint. Windows Hello for Business is enabled by default on Windows devices, and to set it up, users must perform for multifactor authentication (MFA). As a result, this feature may not be ideal for students, who may not have MFA enabled.
Tip
Passwordless for Students
If you're interested in using Windows Hello for Business with students, you may be interested in checking out our guidance on how you can use Temporary Access Pass. For more information, see Passwordless for Students.
It's common for Windows Hello for Business to be disabled at the tenant level. Then, a policy can be targted at users or devices that need it. For example, staff and teachers.
To disable Windows Hello for Business at the tenant level:
This table provides the settings most commonly set by customers, but can be customized to suit your schools needs.
Setting
Common configuration
Device diagnostics are available for corporate-managed devices running Windows 10, version 1909 and later, or Windows 11. Diagnostics may include user identifiable information such as user or device name.
Enabled
Automatically capture diagnostics when devices experience a failure during the Autopilot process on Windows 10 version 1909 or later and Windows 11. Diagnostics may include user identifiable information such as user or device name.
Consider enabling the Enrollment Status Page if planning to use Windows Autopilot to enroll Windows devices in Intune.
The enrollment status page (ESP) displays the provisioning status to people enrolling Windows devices and signing in for the first time. You can configure the ESP to block device use until all required policies and applications are installed. Device users can look at the ESP to track how far along their device is in the setup process.
The Apple MDM certificate needs to be renewed yearly. Make a note in your calendar to renew the certificate in just under a year from when you add the certificate. You can can view the expiry date in the console at any time.
The Apple VPP token needs to be renewed yearly. Make a note in your calendar to renew the token in just under a year from when you add the token. You can can view the expiry date in the console at any time.
Configure Automated Device Enrollment (ADE)
If you plan to integrate Apple School Manager and use Automated Device Enrollment follow these steps.
The Apple ADE token needs to be renewed yearly. Make a note in your calendar to renew the token in just under a year from when you add the token. You can can view the expiry date in the console at any time.
Next steps
With the Intune service configured, you can configure policies and applications in preparation for the deployment of students' and teachers' devices.
Plan and execute an endpoint deployment strategy, using essential elements of modern management, co-management approaches, and Microsoft Intune integration.