Microsoft 365, Intune, identity and endpoint engineeringAdelaide, Australia
Licensing update

Advanced Intune capabilities now included with Microsoft 365 E5

What changed in July 2026, how to confirm tenant readiness, and how to sequence adoption without treating every new entitlement as production-ready.

Microsoft has expanded the advanced Intune capabilities available through commercial Microsoft 365 E3 and E5. For E5 customers, this changes the commercial case for endpoint tooling, but it does not remove the need for technical validation, security design or controlled rollout.

What changedMicrosoft 365 E3 receives Remote Help, Advanced Analytics and Intune Plan 2. Microsoft 365 E5 receives those capabilities plus Endpoint Privilege Management, Enterprise Application Management and Microsoft Cloud PKI. Eligible tenants are provisioned automatically during the rollout, with advance notification through the Microsoft 365 admin centre.

Understand the licence map

CapabilityM365 E3M365 E5Primary use
Remote HelpIncludedIncludedRole-controlled remote support
Advanced AnalyticsIncludedIncludedEndpoint health and troubleshooting
Intune Plan 2IncludedIncludedTunnel for MAM, specialty devices and supported Android FOTA
Endpoint Privilege ManagementNot part of E3 additionIncludedControlled task elevation for standard users
Enterprise Application ManagementNot part of E3 additionIncludedMicrosoft-hosted Win32 application catalogue
Microsoft Cloud PKINot part of E3 additionIncludedCloud-managed CA and SCEP issuance

The packaging update does not mean that every capability in the wider Intune Suite is automatically available through E5. Use the Microsoft licensing and advanced-capabilities pages as the source of truth, then confirm the service plans actually provisioned in your tenant.

Run tenant-readiness checks

  1. Check Message Centre. Look for the tenant-specific notification and rollout date. Capture it as a change dependency rather than relying only on a public announcement.
  2. Confirm subscriptions and service plans. In the Microsoft 365 admin centre, review Billing > Your products and Billing > Licences. Confirm the expected E5 subscription and associated service plans.
  3. Review Intune add-ons. In the Intune admin centre, go to Tenant administration > Intune add-ons. Confirm which capabilities show as active or eligible.
  4. Check role design. Identify who can configure, operate and report on each capability. Avoid granting Intune Administrator simply because a new feature appears.
  5. Assess technical dependencies. Remote Help needs client deployment and RBAC; Cloud PKI needs trust and certificate design; EPM needs audit and elevation rules; Enterprise App Management needs packaging governance.

Adopt in a risk-based order

A sensible sequence for a large organisation is:

  1. Advanced Analytics: low-disruption visibility improvement; useful for building operational value quickly.
  2. Enterprise Application Management: pilot with low-risk utilities where catalogue metadata can be independently validated.
  3. Remote Help: deploy once RBAC, support processes, privacy notices and network requirements are agreed.
  4. Endpoint Privilege Management: start in audit mode, build personas and rules, then remove standing administrator rights.
  5. Cloud PKI: treat as an architecture programme. Validate certificate use cases, RADIUS dependencies, revocation, trust distribution and migration design before production.

Validate rather than assume

  • Feature appears in the tenant and the correct users are licensed.
  • Admin roles are scoped through Intune RBAC and, where appropriate, PIM.
  • Pilot groups are separate from broad production groups.
  • Network allow-listing and SSL inspection exceptions are documented.
  • Audit, reporting and support ownership are agreed.
  • Rollback or containment steps are written before broad assignment.

Use the change to rationalise tooling carefully

The strongest business case is not “we now own it, so replace everything”. Compare capability, security, platform coverage, data retention, integration, support model and exit cost. A third-party remote support, privilege-management or PKI platform may still provide requirements Microsoft does not cover.

Risk to avoidDo not enable a tenant-wide capability merely because the licence is present. Provisioning is a commercial entitlement; production adoption remains a controlled technology change.

Microsoft references

  1. What’s new in Microsoft Intune
  2. Microsoft Intune advanced capabilities
  3. Microsoft Intune licensing
  4. Microsoft 365 pricing and packaging updates

Review note: Microsoft cloud licensing, rollout dates and portal labels can change. Validate your tenant, Message Centre notices and current documentation before production implementation.