Eliminate Configuration Manager: all 6 workloads moved to Intune in 77 days.
Built for the IT Director or head of end user computing who is still running Configuration Manager on infrastructure nobody wants to patch, for a workforce that has not been near the corporate network in years. This engagement will eliminate the on-premises endpoint management footprint and reduce the cost of managing devices that never come to an office.
Who this is for
Organizations running Microsoft Configuration Manager for a workforce that is now mostly remote, where the distribution point estate, the site servers, and the VPN dependency have all become liabilities, not assets. The head of end user computing usually wants this and has been blocked by application packaging debt. The IT Director signs it when the site server hardware refresh quote lands.
What we deliver
- A co-management enablement covering all six Configuration Manager workloads, moved one at a time with a pilot collection per workload so a rollback is a single slider, not a project.
- Application migration: inventory of what is actually deployed versus what is merely packaged, repackaging to Win32 app format for what survives, and honest retirement of the applications nobody has installed in a year.
- Windows Autopilot provisioning with Entra ID join, an Enrollment Status Page profile that reflects your real build time, and a device preparation path so a replacement laptop ships directly to the user.
- Compliance policies, configuration profiles migrated from Group Policy with the Group Policy analytics tooling, and Windows Update for Business ring design, followed by the Configuration Manager decommission plan including distribution point and site server retirement.
Outcomes our customers see
One customer moved all 6 co-management workloads to Intune in 77 days and retired 4 distribution point servers. Application rationalization cut a 640-package estate to 210 packages, a 67 percent reduction, before any repackaging effort was spent. Autopilot provisioning reduced device build and dispatch from 5 days to under 4 hours at a 2,900-seat customer.
How this compares
Most Configuration Manager migrations stall on application packaging, because the project inherits the full package library and tries to move all of it. The rationalization step comes first here, and it typically removes half to two thirds of the work before it starts. The decommission plan is included, not left implied: an organization running both Configuration Manager and Intune indefinitely has doubled its cost, and that is the most common outcome of a migration that stops at co-management.
Architecture and Microsoft alignment
Migration runs Configuration Manager and Intune in co-management, shifting workload authority one at a time. Devices join Entra ID with hybrid join as a transitional state where required. Applications deploy as Win32 apps through Intune. Policy migrates from Group Policy using Group Policy analytics into configuration profiles and settings catalog policies. Windows Autopilot handles provisioning, Windows Update for Business handles patching through update rings, and Defender for Endpoint provides the security posture signal into Intune compliance. Aligned to the Microsoft solution plays Scale with Cloud and AI Endpoints and Secure AI Productivity.
Plans
Plans, prices, and full scope per plan are on the Plans tab of this listing.
Prerequisites
Intune licensing through Microsoft 365 E3 or E5 or a standalone plan, an existing Configuration Manager environment at a supported current branch version, Intune Administrator and Configuration Manager full administrator rights, and a decision from the business on which legacy applications may be retired rather than repackaged.
Limitations
Server operating systems remain in Configuration Manager or move to Azure Arc and Azure Update Manager, which is scoped separately. Applications with hard dependencies on local network resources may require remediation work outside this engagement. Where a line-of-business application cannot be repackaged, the engagement documents it and recommends a path instead of forcing the migration. Third-party patching for non-Microsoft applications requires additional tooling.
How to buy
Buy through the Azure portal, using Get it in Azure portal on this listing, so the purchase is billed through your existing Microsoft agreement. Private offers on request.
Next step
Get it now in the Azure portal, or request a private offer if the scope or the price needs adjusting first.