Microsoft has expanded the advanced Intune capabilities available through commercial Microsoft 365 E3 and E5. For E5 customers, this changes the commercial case for endpoint tooling, but it does not remove the need for technical validation, security design or controlled rollout.
Understand the licence map
| Capability | M365 E3 | M365 E5 | Primary use |
|---|---|---|---|
| Remote Help | Included | Included | Role-controlled remote support |
| Advanced Analytics | Included | Included | Endpoint health and troubleshooting |
| Intune Plan 2 | Included | Included | Tunnel for MAM, specialty devices and supported Android FOTA |
| Endpoint Privilege Management | Not part of E3 addition | Included | Controlled task elevation for standard users |
| Enterprise Application Management | Not part of E3 addition | Included | Microsoft-hosted Win32 application catalogue |
| Microsoft Cloud PKI | Not part of E3 addition | Included | Cloud-managed CA and SCEP issuance |
The packaging update does not mean that every capability in the wider Intune Suite is automatically available through E5. Use the Microsoft licensing and advanced-capabilities pages as the source of truth, then confirm the service plans actually provisioned in your tenant.
Run tenant-readiness checks
- Check Message Centre. Look for the tenant-specific notification and rollout date. Capture it as a change dependency rather than relying only on a public announcement.
- Confirm subscriptions and service plans. In the Microsoft 365 admin centre, review Billing > Your products and Billing > Licences. Confirm the expected E5 subscription and associated service plans.
- Review Intune add-ons. In the Intune admin centre, go to Tenant administration > Intune add-ons. Confirm which capabilities show as active or eligible.
- Check role design. Identify who can configure, operate and report on each capability. Avoid granting Intune Administrator simply because a new feature appears.
- Assess technical dependencies. Remote Help needs client deployment and RBAC; Cloud PKI needs trust and certificate design; EPM needs audit and elevation rules; Enterprise App Management needs packaging governance.
Adopt in a risk-based order
A sensible sequence for a large organisation is:
- Advanced Analytics: low-disruption visibility improvement; useful for building operational value quickly.
- Enterprise Application Management: pilot with low-risk utilities where catalogue metadata can be independently validated.
- Remote Help: deploy once RBAC, support processes, privacy notices and network requirements are agreed.
- Endpoint Privilege Management: start in audit mode, build personas and rules, then remove standing administrator rights.
- Cloud PKI: treat as an architecture programme. Validate certificate use cases, RADIUS dependencies, revocation, trust distribution and migration design before production.
Validate rather than assume
- Feature appears in the tenant and the correct users are licensed.
- Admin roles are scoped through Intune RBAC and, where appropriate, PIM.
- Pilot groups are separate from broad production groups.
- Network allow-listing and SSL inspection exceptions are documented.
- Audit, reporting and support ownership are agreed.
- Rollback or containment steps are written before broad assignment.
Use the change to rationalise tooling carefully
The strongest business case is not “we now own it, so replace everything”. Compare capability, security, platform coverage, data retention, integration, support model and exit cost. A third-party remote support, privilege-management or PKI platform may still provide requirements Microsoft does not cover.
Microsoft references
- What’s new in Microsoft Intune
- Microsoft Intune advanced capabilities
- Microsoft Intune licensing
- Microsoft 365 pricing and packaging updates
Review note: Microsoft cloud licensing, rollout dates and portal labels can change. Validate your tenant, Message Centre notices and current documentation before production implementation.