PotentEngineer

Intune, ConfigMgr, PowerShell and more...

7 minute read

Intune missing capabilities for the ConfigMgr administrator

Even if you haven’t been paying attention to recent development for, or lack thereof, Microsoft Configuration Manager, or to any of the threads on Twitter/X, Reddit, or any other major social media platforms, you still probably know the writing is on the wall for ConfigMgr. Nearly all focus in Contosoland has been devoted to Intune.

This post outlines my personal running list of gaps that Intune doesn’t quite cover for the seasoned ConfigMgr administrator.

My friend and banter extraordinaire, Bryan Dam, posted recently a quote that makes sense in describing this list.

#ConfigMgr gave you 250% of what you need. #Intune gives you 90%, we’ll get it to 100% … eventually.

Much of this list may be in the last 150%, but that doesn’t change a lot of organizations’ dependency on these capabilities. Make your own determination how critical these capabilities are for your organization.

Kim Oppalfens has the best write up I have seen to date of these gaps.

My list includes a few more technical gaps ranging from critical to minor technical details.

Software installation

For the majority of your software installations, Intune should cover your needs. But the following requirements may pose an issue.

Shared device scenarios

Real time capabilities

Maximum of 200 Remediation scripts

If you are a large organization, you may hit the 200 maximum remediations limit. Our organization has well over 200 ConfigMgr baselines, so we are keeping this workload in ConfigMgr for now.

Targeting

We all know that for modern endpoint management you generally want to target users, not devices. There is a lot of value targeting users, especially as Intune is designed to work better this way. However, you lose out on certain deployment abilities that ConfigMgr delivers beautifully with collections today. Good news though, coming soon to Intune is device inventory! This seems to be the first step in opening up more targeting capabilities besides Entra ID groups and virtual groups + filters.

Ironically, if you do need some of these dynamic capabilities for targeting you can use ConfigMgr to get them in Intune. Check out collection sync. Thanks Cristopher Alaya for the mention!

Closing

This is a lengthy list, and I have been keeping this list since we co-managed all our devices at the start of the pandemic in 2020. The good news is even just a year ago, this last had 5 more items. Many of these items are dropping off with every monthly Intune release and eventually Microsoft will get that last 10%. I personally expect co-management will still be necessary for the next 5 years though, we shall see.