Microsoft Intune

Your Intune,
Done Right.

Expert consultancy and automated baseline deployment for Microsoft Intune. We connect to your tenant via Graph API and deploy a production-ready configuration — covering compliance, device configs, app protection and conditional access — in minutes, not weeks.

Deploy Baseline Now View Pricing →

How it works

Deploy in four steps.

No manual portal clicks. Our engine does the work via Graph API.

01

Create App Registration

Create an Enterprise App in your Entra ID tenant and grant the required Graph API permissions. Takes 5 minutes.

02

Enter Your Credentials

Provide your Tenant ID, Client ID and Client Secret. We connect read/write to your Intune environment — nothing is stored.

03

Choose Your Baseline

Select from CIS Level 1, Microsoft Recommended, or a custom profile. Review exactly what will be deployed before committing.

04

Sit Back

InfraKit deploys all policies, profiles and conditional access rules. You get a full deployment report on completion.

Pricing

Simple, transparent pricing.

Starter
£299/tenant

Perfect for small businesses getting started with Intune. One-off baseline deployment with a 30-day support window.

Compliance policies (Windows + mobile)
5 device configuration profiles
App protection policies (iOS + Android)
Deployment report
Conditional access policies
Ongoing management
Get Started
Enterprise
POA

Multi-tenant deployments, custom policies, dedicated support and full managed service. For organisations with complex requirements.

Everything in Professional
Multi-tenant deployment
Custom policy templates
Dedicated account manager
Full ongoing managed service
SLA-backed support
Contact Us

Automated Deployment

Deploy Your Baseline

Enter your tenant details below. We connect via Graph API and deploy your chosen baseline configuration directly into Intune.

Connect Your Tenant

You’ll need an App Registration in Entra ID with the required Graph API permissions. See required permissions ↓

Found in Entra ID → Overview → Tenant ID
Your App Registration’s Application (client) ID
Create a client secret in Certificates & Secrets. Used once then discarded.

Your credentials are used for a single API session and are never stored, logged, or transmitted beyond the Graph API call. A consultation call is recommended before running an automated deployment on a live tenant.

Required Graph API Permissions

Grant these Application permissions on your App Registration:

DeviceManagementConfiguration.ReadWrite.All
DeviceManagementManagedDevices.ReadWrite.All
DeviceManagementApps.ReadWrite.All
Policy.ReadWrite.ConditionalAccess
Directory.Read.All

What Gets Deployed

  • Windows 10/11 compliance policy
  • iOS & Android compliance policies
  • Windows Update rings (Current Branch)
  • BitLocker encryption profile
  • Defender Antivirus & Firewall config
  • App protection policies (MAM)
  • Conditional access rules (Zero Trust)
  • Device enrolment restrictions

Prefer a Consultation?

Not ready for automated deployment? Book a call with an InfraKit engineer. We’ll review your current Intune setup and recommend a deployment plan tailored to your organisation.

Book a call

Ready?

Get your Intune sorted today.

Book a free 30-minute consultation and we’ll assess your current setup, identify gaps, and recommend the right baseline for your organisation.