Microsoft 365, Intune, identity and endpoint engineeringAdelaide, Australia
Planning guide

Intune Plan 2: Tunnel for MAM, specialty devices and Android FOTA

Where the Plan 2 capabilities fit, what infrastructure they need and which use cases justify an enterprise pilot.

Intune Plan 2 is now included in commercial Microsoft 365 E3 and E5. Its strongest value is in specific mobile, shared and specialty-device scenarios rather than a general Windows endpoint uplift.

What Plan 2 adds

CapabilityUse caseKey dependency
Microsoft Tunnel for MAMProtected app connectivity from supported Android and iOS devices that are not enrolledTunnel gateway infrastructure, app-protection policy and supported apps
Specialty device managementAR/VR, smart screens, meeting-room and purpose-built devicesSupported device platform and management mode
Firmware over-the-air updatesControlled Android firmware deployment without user actionSupported OEM integration and device model

Plan Microsoft Tunnel for MAM

Start with an application and data-flow requirement. Tunnel for MAM is useful when an unmanaged mobile device needs per-app access to internal resources while corporate data remains protected by Intune app-protection policy.

  • Identify supported iOS and Android apps.
  • Design Linux tunnel gateways, high availability, certificates and outbound connectivity.
  • Define per-app routes and DNS behaviour.
  • Integrate app-protection policy, Conditional Access and authentication.
  • Test alongside secure web gateway and mobile-threat-defence controls.
  • Document fail-open or fail-closed behaviour for business-critical apps.

Assess specialty devices

Create an inventory of meeting-room, kiosk, rugged, shared, AR/VR and large-screen devices. Confirm whether the device is already supported by base Intune management. Plan 2 should be applied where its specialty-management capability materially improves lifecycle or security control.

Use Android FOTA deliberately

Firmware management is highly OEM and model dependent. Before a pilot, confirm supported hardware, current firmware, maintenance windows, battery and connectivity requirements, rollback limitations and help-desk recovery procedures.

  1. Create an RBAC role with only the required Android FOTA permissions.
  2. Import or identify eligible devices and firmware.
  3. Deploy to lab devices first.
  4. Test interruption, low battery and network-loss scenarios.
  5. Use staged rings and monitor deployment history.
  6. Keep OEM recovery and warranty escalation details available.

Decide whether to adopt

Prioritise Plan 2 where there is a clear internal-resource access requirement for unenrolled mobile apps, a supported specialty-device fleet or a measurable Android firmware risk. Do not create tunnel infrastructure merely because the entitlement exists.

Platform fit mattersCapability and support vary by operating system, management mode, OEM and device model. Confirm the current Microsoft support matrix before committing to a design.

Microsoft references

  1. Microsoft Intune advanced capabilities
  2. What’s new in Microsoft Intune
  3. Overview of Microsoft Tunnel
  4. Custom Intune RBAC roles

Review note: Microsoft cloud licensing, rollout dates and portal labels can change. Validate your tenant, Message Centre notices and current documentation before production implementation.