Intune Plan 2 is now included in commercial Microsoft 365 E3 and E5. Its strongest value is in specific mobile, shared and specialty-device scenarios rather than a general Windows endpoint uplift.
What Plan 2 adds
| Capability | Use case | Key dependency |
|---|---|---|
| Microsoft Tunnel for MAM | Protected app connectivity from supported Android and iOS devices that are not enrolled | Tunnel gateway infrastructure, app-protection policy and supported apps |
| Specialty device management | AR/VR, smart screens, meeting-room and purpose-built devices | Supported device platform and management mode |
| Firmware over-the-air updates | Controlled Android firmware deployment without user action | Supported OEM integration and device model |
Plan Microsoft Tunnel for MAM
Start with an application and data-flow requirement. Tunnel for MAM is useful when an unmanaged mobile device needs per-app access to internal resources while corporate data remains protected by Intune app-protection policy.
- Identify supported iOS and Android apps.
- Design Linux tunnel gateways, high availability, certificates and outbound connectivity.
- Define per-app routes and DNS behaviour.
- Integrate app-protection policy, Conditional Access and authentication.
- Test alongside secure web gateway and mobile-threat-defence controls.
- Document fail-open or fail-closed behaviour for business-critical apps.
Assess specialty devices
Create an inventory of meeting-room, kiosk, rugged, shared, AR/VR and large-screen devices. Confirm whether the device is already supported by base Intune management. Plan 2 should be applied where its specialty-management capability materially improves lifecycle or security control.
Use Android FOTA deliberately
Firmware management is highly OEM and model dependent. Before a pilot, confirm supported hardware, current firmware, maintenance windows, battery and connectivity requirements, rollback limitations and help-desk recovery procedures.
- Create an RBAC role with only the required Android FOTA permissions.
- Import or identify eligible devices and firmware.
- Deploy to lab devices first.
- Test interruption, low battery and network-loss scenarios.
- Use staged rings and monitor deployment history.
- Keep OEM recovery and warranty escalation details available.
Decide whether to adopt
Prioritise Plan 2 where there is a clear internal-resource access requirement for unenrolled mobile apps, a supported specialty-device fleet or a measurable Android firmware risk. Do not create tunnel infrastructure merely because the entitlement exists.
Microsoft references
- Microsoft Intune advanced capabilities
- What’s new in Microsoft Intune
- Overview of Microsoft Tunnel
- Custom Intune RBAC roles
Review note: Microsoft cloud licensing, rollout dates and portal labels can change. Validate your tenant, Message Centre notices and current documentation before production implementation.