July 17, 2026

SCCM vs Intune - Simply Explained

SCCM vs Intune - Simply Explained
SCCM vs Intune - Simply Explained
M365 FM Podcast
SCCM vs Intune - Simply Explained

Should you choose SCCM or Microsoft Intune for endpoint management? The answer isn't as simple as picking one over the other. While SCCM has been the enterprise standard for years, Intune represents Microsoft's cloud-first approach to managing modern devices. In reality, many organizations use both together during their transition to the cloud.

In this episode of Microsoft Knowledge Nuggets, Mirko Peters explains the differences between SCCM and Intune in plain English. You'll learn where each solution excels, how they complement each other, and which platform is the better fit depending on your organization's infrastructure, workforce, and cloud strategy.

The episode covers key topics including software deployment, operating system management, patching, compliance, device provisioning, remote management, Windows Autopilot, co-management, and cloud versus on-premises administration. It also explains why Microsoft continues to invest in Intune while Configuration Manager remains an important solution for many enterprise environments.

Whether you're an IT administrator, endpoint manager, Microsoft consultant, or cloud architect, this episode will help you understand the strengths, limitations, and future of both platforms. By the end, you'll know when to choose SCCM, when Intune is the better option, and why many organizations benefit from combining both as part of their modern endpoint management strategy.

Quick answer: SCCM vs Intune is covered in this M365 FM episode with a practical focus on what it is, how it works, and the decisions that matter for architecture, adoption, security, governance, or day-to-day operations.

In today's fast-paced IT world, knowing the differences between SCCM vs Intune can make a big difference in how you manage your organization's devices. Each solution offers unique benefits that cater to different needs. For instance, if you're managing a remote workforce, you might lean toward Intune for its cloud capabilities. On the other hand, SCCM provides robust control for Windows devices in complex environments. Understanding these differences helps you choose the right tool for your specific situation, ensuring effective IT management.

Key Takeaways

  • SCCM is ideal for managing large groups of Windows devices in complex environments.
  • Intune offers cloud-based management, making it perfect for remote work and diverse operating systems.
  • SCCM automates software distribution and patch management, enhancing operational efficiency.
  • Intune supports a Bring Your Own Device (BYOD) policy, allowing management of various devices.
  • Consider your organization's infrastructure needs when choosing between SCCM and Intune.
  • Both SCCM and Intune can be used together in a co-management setup for flexibility.
  • Evaluate your organization's specific needs to select the best solution for IT management.
  • Intune's cloud-native approach can lead to lower costs and easier scalability for smaller businesses.

SCCM vs Intune Overview

What is SCCM?

SCCM, or System Center Configuration Manager, is a powerful tool from Microsoft designed for managing large groups of computers. It excels in environments where you need centralized control over Windows devices. With SCCM, you can automate software distribution, manage updates, and enforce security policies. This on-premises configuration manager has been a staple in IT management for over two decades.

Here are some key functions and capabilities of SCCM:

Function/Capability Description
Centralised Management Simplifies management across platforms while decreasing complexity and administrative expenses.
Automated Software Distribution Automates the deployment process for software, apps, and operating systems, improving efficiency.
Patch Management Controls software updates and patches, reducing security vulnerabilities and risks.
Hardware and Software Inventory Tracks assets, identifies potential issues, and maximizes licensing agreements.
Remote Control Capabilities Enables IT administrators to resolve problems and offer support remotely.
Security Enforces security policies and ensures compliance with organizational standards.
Reporting Provides robust reporting features for monitoring device health and performance.

What is Microsoft Intune?

Microsoft Intune is a cloud-based service that helps you manage devices and applications from anywhere. It supports a wide range of operating systems, including Windows, macOS, iOS, and Android. Intune simplifies device enrollment and management, making it an excellent choice for organizations embracing remote work and hybrid environments.

Intune integrates seamlessly with other Microsoft 365 services, enhancing its functionality. Here’s how it connects with key components:

Integration Component Functionality
Azure Active Directory (Azure AD) Manages identity and access, enabling Conditional Access policies for resource access.
Microsoft Defender for Endpoint Provides security and threat protection for devices managed by Intune.
Microsoft 365 Integrates with Intune for a comprehensive endpoint management solution within the cloud ecosystem.

In modern IT management, both SCCM and Microsoft Intune play crucial roles. SCCM is ideal for organizations with complex environments that require deep control over Windows devices. In contrast, Intune offers flexibility and ease of use, making it perfect for businesses that prioritize cloud-based solutions. Understanding these tools helps you make informed decisions about your IT management strategy.

SCCM vs Intune: Key Differences

Infrastructure Requirements

When it comes to infrastructure, SCCM and Microsoft Intune take different approaches. SCCM, or Microsoft Configuration Manager, requires a robust on-premises setup. Here are some key infrastructure requirements for deploying SCCM in a large organization:

  • Choose one primary site for central management with normal WAN connectivity.
  • Opt for multiple sites when scale, geography, or network costs make a single site inefficient.
  • Add secondary sites only when local distribution and management benefits outweigh added complexity.
  • Design for growth from day one, allowing for increases in client count and content libraries.
  • Plan for fault tolerance, ensuring distribution points do not rely on a single server.
  • Properly size SQL storage and backups for performance and recovery.
  • Conduct capacity planning for server CPU, memory, SQL performance, disk I/O, content storage, endpoint count, and bandwidth.

On the other hand, Microsoft Intune operates in the cloud, which simplifies many of these requirements. Here’s a quick comparison of the infrastructure needs for both solutions:

Component Intune SCCM
Primary Server Microsoft-hosted (Azure) On-premises site server(s)
Database Azure SQL (managed) SQL Server (self-managed)
Content Distribution Azure CDN / Microsoft Graph Distribution Points (DPs)
Network Requirements Internet access required LAN/WAN, can be isolated
Administration Intune admin center (web) ConfigMgr console (Windows app)

Device Support

Device support is another area where SCCM and Intune differ significantly. SCCM primarily focuses on Windows devices, including servers. It traditionally manages domain-joined on-premises Windows devices but can extend to cloud-joined devices through co-management and a Cloud Management Gateway (CMG). Here’s a breakdown of device support:

Platform Supported Devices
Intune Windows Client OS, iPadOS, Android, iOS, MacOS, Server OS
SCCM Windows devices (including servers)

With Intune, you get broader support for various operating systems, making it a great choice for organizations adopting a Bring Your Own Device (BYOD) policy. This flexibility allows you to manage a diverse range of devices, enhancing your mobile device management (MDM) capabilities.

Deployment Models

Deployment models also set SCCM and Intune apart. SCCM requires additional servers and distribution points as you scale, which can complicate management. In contrast, Intune offers unlimited device support with auto-scaling cloud infrastructure. Here’s a quick look at the deployment models:

Deployment Model Microsoft Intune SCCM (Configuration Manager)
Scalability Unlimited devices, auto-scaling cloud infrastructure Requires additional servers and DPs as you scale

Organizations often deploy SCCM and Intune in hybrid or cloud environments. Co-management allows Windows devices managed by SCCM to also enroll in Intune. This strategy lets you split management workloads and migrate them in controlled phases. It reduces the risk of a hard cutover and allows you to validate Intune policy enforcement before decommissioning on-premises infrastructure.

By integrating both SCCM and Intune, you can create a unified device management strategy that meets your organization's unique needs.

Use Cases

When it comes to choosing between SCCM and Intune, understanding their use cases can help you make an informed decision. Each solution shines in different scenarios, so let’s break it down.

SCCM Use Cases

SCCM is a powerhouse for organizations that need to manage a large number of Windows devices. Here are some common use cases:

  • Rolling out software updates
  • Implementing endpoint protection
  • Determining endpoint inventory and status (device health)
  • Enforcing compliance settings
  • Distributing software to endpoint devices
  • Handling Windows 10 upgrades
  • Supporting traditional Windows Workgroup client devices

These capabilities make SCCM ideal for enterprises with complex IT environments that require detailed control over their devices.

Intune Use Cases

On the other hand, Intune caters to modern device management needs, especially in organizations that embrace remote work and BYOD policies. Here’s a quick look at some of its key use cases:

Use Case Description
App Deployment Install a new mobile app on all employees’ devices.
Compliance Policy Enforcement Enforce a policy that requires all devices to be encrypted.
Remote Actions Remotely wipe a lost or stolen device, monitor compliance with security policies, etc.

Intune’s flexibility allows you to manage a diverse range of devices, making it a great choice for businesses that prioritize cloud-based solutions.

Licensing and Costs

Licensing and costs can significantly impact your decision between SCCM and Intune. Here’s how they compare:

Cost Category Intune SCCM
Licensing Included in M365 E3/E5 Windows Server CALs, System Center licenses, SQL Server licenses
Infrastructure None (cloud-hosted) Servers, SQL, storage, network
IT Staff Lower overhead Higher (infrastructure management)

With Intune, you benefit from a cloud-hosted model that eliminates the need for extensive on-premises infrastructure. This can lead to lower overall costs, especially for smaller organizations.

However, SCCM may involve higher upfront costs due to its licensing requirements and the need for physical servers. You should also consider indirect costs associated with both solutions, such as administrative overhead and network bandwidth consumption during deployments.

Features Comparison

Both SCCM and Intune come with unique features that cater to different organizational needs. Here’s a comparison of their key features:

Feature SCCM Intune
Architecture On-premises architecture, suitable for large enterprises. Cloud-based solution, ideal for smaller to medium-sized businesses.
Automation and Scripting Extensive automation capabilities, advanced scripting requirements. Supports automation and scripting for streamlined management tasks.
Update Management Excels in software update management for diverse devices. Efficiently manages updates for mobile devices and applications.
Community Support Well-established community and extensive documentation. Supportive community with comprehensive documentation.
Compliance and Reporting Robust capabilities for compliance and reporting. Essential features for compliance and reporting.

By understanding these features, you can better assess which solution aligns with your organization’s endpoint management strategy.

Security Features

When it comes to security, both SCCM and Intune offer robust features, but they approach security management differently. Understanding these differences can help you choose the right tool for your organization's needs.

SCCM Security Features

SCCM provides a strong foundation for managing security in on-premises environments. Here are some key security features:

  • Endpoint Protection: SCCM integrates with Microsoft Defender to protect devices from malware and other threats.
  • BitLocker Management: You can manage BitLocker encryption for Windows devices, ensuring that sensitive data remains secure.
  • Compliance Monitoring: SCCM uses SQL-based queries and built-in reporting to help you monitor compliance across your devices.

While SCCM is effective for environments with strict compliance needs, such as healthcare and finance, it requires skilled administrators to manage its infrastructure.

Intune Security Features

On the other hand, Intune takes a cloud-based approach to security, which offers several advantages:

  • Conditional Access: This feature ensures that only compliant devices can access corporate resources. This is crucial for maintaining compliance in regulated industries.
  • Real-time Compliance Monitoring: Intune provides immediate insights into device compliance, allowing you to respond quickly to any issues.
  • Integration with Microsoft Defender: Intune enhances data protection by integrating with Microsoft Defender for endpoint protection, providing threat detection and remediation capabilities.

Here’s a quick comparison of the security features of both solutions:

Feature SCCM Intune
Management Type On-premises Cloud-based
Compliance Monitoring SQL-based queries and built-in reporting Real-time compliance monitoring
Device Support Primarily Windows Windows, macOS, iOS, Android
Conditional Access Not natively supported Supported, crucial for Zero Trust architecture
Security Features Endpoint Protection, BitLocker Management Conditional Access, Compliance Policies
User Self-Service N/A Company Portal app for app installation
Operational Overhead High, requires infrastructure and skilled admins Low, no site server maintenance needed

Intune's flexibility makes it ideal for organizations that support Bring Your Own Device (BYOD) policies. You can securely manage personal devices accessing corporate resources, which is increasingly important in today's remote work environment.

Pros and Cons of SCCM

Advantages of SCCM

SCCM offers several advantages, especially for organizations with complex IT infrastructures. Here are some key benefits:

Advantage Description
Enhanced Operational Efficiency SCCM automates software distribution and patch management, reducing manual processes and human error.
Improved Security Posture SCCM ensures consistent updates and compliance with security policies, mitigating cyber threats.
Centralized Management You can manage diverse devices and applications from a single platform, streamlining operations.

With SCCM, you can also demonstrate your capability in streamlining IT operations. Many employers value SCCM-certified professionals for their ability to optimize software deployment. This certification shows that you can handle automated patching and asset inventory management effectively.

Additionally, SCCM provides tools for compliance management and auditing. These tools help you adhere to regulatory standards, ensuring accurate reporting and proactive monitoring. You’ll maintain visibility into system health and compliance status, which is crucial for any organization.

Disadvantages of SCCM

While SCCM has its strengths, it also comes with some challenges. Here are a few disadvantages to consider:

  1. Managing patches on a hybrid network with non-Windows operating systems can be complex.
  2. Patch deployment is time-consuming, requiring activities like selecting updates and creating update lists.
  3. Cleaning up expired patches can be challenging, necessitating manual edits and re-replication.
  4. Conflicts between WSUS and SCCM Group Policy settings often lead to common SCAN errors, complicating troubleshooting.
  5. Real-time patch failure reports are not available, requiring additional configurations for compliance scanning.
  6. Third-party application patching is not well-supported, which means you might need to do manual work and have expertise for integration with SCUP.
  7. Some third-party vendors do not provide compatible CAB files, necessitating custom packaging efforts.
  8. Additional configurations are needed for third-party application patching, such as Group Policy Settings.
  9. Uninstallation of patches is not natively supported, requiring manual methods.
  10. There is no native method to suppress restart notifications in the latest version.

To address these challenges, organizations should implement aggressive automation and centralization. Using tools like SCCM and Windows Server Update Services (WSUS) can significantly streamline the patch management process. This approach reduces the manual workload and minimizes errors, making your job easier.

Pros and Cons of Intune

Advantages of Intune

Intune offers several advantages that make it a strong choice for organizations, especially those adopting cloud-first strategies. Here are some key benefits:

  • Cloud-Native Scalability: You can manage devices globally without the need for on-premises servers. This flexibility allows your organization to grow without worrying about infrastructure limitations.
  • Cross-Platform Coverage: Intune supports various operating systems, including Windows, macOS, iOS, and Android. This means you can manage all your devices from a single platform, simplifying your IT management.
  • Policy-Driven Automation: Intune automates compliance and security enforcement. You can set policies that ensure devices meet your organization’s standards without manual intervention.
  • Enhanced Security Features: With real-time compliance policies and remote wipe capabilities, Intune helps protect your data. If a device is lost or stolen, you can quickly remove access to sensitive information.
  • Improved Talent Acquisition: Embracing a cloud-first approach allows for better talent acquisition by supporting flexible work arrangements. This can enhance employee satisfaction and productivity.

Intune simplifies device management for remote and mobile workforces. Here’s how:

Feature Description
Device Enrollment Streamlines the process of registering devices for management by automatically installing applications.
Configuration Management Remotely configures settings and restrictions on devices to ensure compliance with company policies.
Security Policies Enforces security measures remotely to protect devices and data.
Monitoring and Reporting Provides visibility into device compliance, usage, and security issues.
Remote Support Facilitates troubleshooting and assistance, reducing downtime for users in a remote work environment.

Disadvantages of Intune

While Intune has many strengths, it also comes with some challenges. Here are a few disadvantages to consider:

  • Policy and App Sync Delays: Sometimes, you might experience delays in policy and app synchronization. This can hinder real-time visibility and quick remediation.
  • Limited Reporting Capabilities: Intune's reporting features may not meet all your needs. You might need to rely on external tools for comprehensive reporting, adding complexity to your management tasks.
  • Challenges with Non-Microsoft Store Apps: Deploying non-Microsoft Store apps can lead to delays and complications. This can be frustrating if you rely on specific applications for your operations.
  • Recurring Licensing Costs: The ongoing licensing fees may be burdensome for smaller businesses. You’ll want to factor this into your budget planning.
  • Integration Challenges: Integrating Intune with other tools, like SCCM, isn’t always seamless. This can create management issues if you’re trying to use both solutions together.

Despite these challenges, many organizations find ways to overcome limitations in Intune. For example, they can utilize Advanced Analytics for better data visualization and streamline application deployment through Enterprise App Management.

By weighing the pros and cons of Intune, you can make an informed decision about whether it’s the right fit for your organization’s needs.

Choosing Between SCCM and Intune

Factors to Consider

When deciding between SCCM and Intune, you should evaluate several key factors. Each solution has its strengths, and understanding these can help you make the right choice for your organization. Here’s a quick comparison of important factors:

Factor SCCM Intune
Deployment Architecture On-premises Cloud-based
Management Capabilities Windows-centric, complex environments Mobile-focused, integrates with Azure
Operating System Support Primarily Windows Supports various operating systems
Update Management Manual updates, slower feature updates Semi-annual updates, focuses on security and stability
Application Deployment More complex Streamlined for mobile devices
Security Features Focus on on-premises security Future innovations in cloud security

This table highlights how SCCM is more suited for organizations with complex IT environments, while Intune shines in mobile and cloud-focused scenarios.


Choosing between SCCM and Intune can feel overwhelming, but understanding their differences makes it easier. SCCM excels in complex, on-premises environments, while Intune shines in cloud-based, flexible settings.

Here are some tips to guide your decision:

  • Evaluate Your Environment: If you manage a large number of Windows devices, SCCM might be your best bet.
  • Consider Remote Work Needs: For a remote workforce, Intune offers seamless management across various devices.
  • Look at Real-World Examples: Many organizations have successfully transitioned to Intune, cleaning up unnecessary GPOs and establishing security baselines.
Step Description
1 Delivered a modern SCCM and Intune infrastructure for a major enterprise client.
2 Designed a new SCCM hierarchy to transition from legacy systems.
3 Configured Microsoft Intune in the new Microsoft 365 tenant for hybrid device management.
4 Migrated and validated key OS deployment task sequences and business-critical application packages.

Ultimately, the right choice depends on your specific needs and goals. By assessing your organization's requirements, you can confidently select the solution that best fits your IT management strategy.

FAQ

What is the main difference between SCCM and Intune?

SCCM is an on-premises solution focused on managing Windows devices, while Intune is a cloud-based service that supports multiple operating systems, including mobile devices.

Can I use SCCM and Intune together?

Yes! You can use both solutions in a co-management setup. This allows you to manage Windows devices with SCCM while also leveraging Intune for cloud-based management.

Is Intune suitable for small businesses?

Absolutely! Intune's cloud-based model makes it ideal for small businesses. You can manage devices without needing extensive on-premises infrastructure.

How does Intune enhance security?

Intune offers features like Conditional Access and real-time compliance monitoring. These help ensure that only secure and compliant devices access your organization's resources.

What types of devices can I manage with Intune?

You can manage a wide range of devices with Intune, including Windows PCs, macOS, iOS, and Android devices. This flexibility supports diverse work environments.

Are there any training resources for SCCM and Intune?

Yes! Microsoft provides extensive documentation, tutorials, and community forums for both SCCM and Intune. These resources can help you get started and troubleshoot issues.

How often does Microsoft update Intune?

Microsoft regularly updates Intune, typically every month. These updates include new features, security enhancements, and performance improvements.

Can I automate tasks in SCCM?

Yes! SCCM supports automation for various tasks, such as software deployment and patch management. This helps streamline your IT operations and reduce manual work.


🎧 Listen to this episode

Want a practical explanation of SCCM vs Intune? This episode breaks down the topic in clear language and shows why it matters for Microsoft 365, Azure, Power Platform, security, AI, and modern work.

Listen to this episode if you want to:

  • Understand the key concepts behind SCCM vs Intune
  • See how it fits into the wider Microsoft technology ecosystem
  • Learn where it can create practical value for your organization

You may also enjoy these related M365 FM episodes:

Discover more practical Microsoft conversations on M365 FM.


Last reviewed: July 2026.

Who Should Listen

This episode is for Microsoft 365 administrators, architects, IT leaders, and practitioners who need a practical understanding of SCCM vs Intune before planning, implementing, or supporting it.

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

1
00:00:00,000 --> 00:00:02,560
Today's topic is one that almost everyone has heard of,

2
00:00:02,560 --> 00:00:03,880
but most people get wrong.

3
00:00:03,880 --> 00:00:05,800
I'm talking about SCCM and Intune.

4
00:00:05,800 --> 00:00:07,440
You've probably heard both names thrown around,

5
00:00:07,440 --> 00:00:08,960
and it's easy to assume they're basically

6
00:00:08,960 --> 00:00:10,640
the same tool with different names,

7
00:00:10,640 --> 00:00:13,320
two Microsoft products that both manage devices, right?

8
00:00:13,320 --> 00:00:14,720
Well, not exactly, actually,

9
00:00:14,720 --> 00:00:16,320
they're two very different tools

10
00:00:16,320 --> 00:00:18,160
with different strengths, different philosophies

11
00:00:18,160 --> 00:00:20,200
and different infrastructure requirements.

12
00:00:20,200 --> 00:00:22,200
And picking the wrong one means you could waste time

13
00:00:22,200 --> 00:00:24,440
and money on infrastructure you don't need

14
00:00:24,440 --> 00:00:26,480
or miss the control you actually want.

15
00:00:26,480 --> 00:00:27,480
By the end of this episode,

16
00:00:27,480 --> 00:00:29,680
you'll understand what each tool actually does,

17
00:00:29,680 --> 00:00:31,400
how they compare side by side

18
00:00:31,400 --> 00:00:33,640
and which one makes sense for your organization.

19
00:00:33,640 --> 00:00:35,880
So grab your coffee and let's dive in.

20
00:00:35,880 --> 00:00:38,600
The core problem, managing devices at scale.

21
00:00:38,600 --> 00:00:41,560
Let's start with the problem, both tools are trying to solve.

22
00:00:41,560 --> 00:00:43,240
If you only have five computers in your office,

23
00:00:43,240 --> 00:00:44,200
you don't need either one.

24
00:00:44,200 --> 00:00:46,560
You can walk over and install software, run updates

25
00:00:46,560 --> 00:00:48,720
and fix things yourself and that works fine.

26
00:00:48,720 --> 00:00:51,880
But what happens with 500 computers or 5,000 or 50,000?

27
00:00:51,880 --> 00:00:53,760
The manual approach stops working very quickly.

28
00:00:53,760 --> 00:00:55,800
You can't have IT staff walking to every desk

29
00:00:55,800 --> 00:00:57,280
to install a security patch

30
00:00:57,280 --> 00:00:59,040
and you can't check each machine one by one

31
00:00:59,040 --> 00:01:00,120
for the right antivirus.

32
00:01:00,120 --> 00:01:01,400
It just doesn't scale.

33
00:01:01,400 --> 00:01:04,640
20 years ago, this was a huge problem for large organizations.

34
00:01:04,640 --> 00:01:06,720
IT teams had to physically visit machines,

35
00:01:06,720 --> 00:01:10,080
install software from CDs and run updates one at a time.

36
00:01:10,080 --> 00:01:12,160
That was slow, expensive and error prone.

37
00:01:12,160 --> 00:01:14,920
Microsoft looked at this problem and built two solutions,

38
00:01:14,920 --> 00:01:16,720
one for the old world where everything lived

39
00:01:16,720 --> 00:01:18,960
in your own building on your own servers

40
00:01:18,960 --> 00:01:22,240
and one for the new world, where devices are everywhere,

41
00:01:22,240 --> 00:01:25,400
users work remotely and the cloud handles the heavy lifting

42
00:01:25,400 --> 00:01:27,760
the first is SCCM and the second is in tune.

43
00:01:27,760 --> 00:01:30,480
They solve the same core problem, but in completely different ways.

44
00:01:30,480 --> 00:01:32,160
So before we compare them head to head,

45
00:01:32,160 --> 00:01:35,240
we need to understand what each one actually is.

46
00:01:35,240 --> 00:01:37,680
What is SCCM, the on-premises powerhouse?

47
00:01:37,680 --> 00:01:41,000
SCCM stands for System Center Configuration Manager.

48
00:01:41,000 --> 00:01:42,200
Though you might also hear it called

49
00:01:42,200 --> 00:01:45,520
Microsoft Endpoint Configuration Manager or MECM for short.

50
00:01:45,520 --> 00:01:48,480
That's the new name, but most people still call it SCCM.

51
00:01:48,480 --> 00:01:49,920
Here's the simplest definition.

52
00:01:49,920 --> 00:01:53,240
SCCM is an on-premises tool that you run on your own servers

53
00:01:53,240 --> 00:01:55,280
inside your own building on your own network.

54
00:01:55,280 --> 00:01:57,720
It's software you install and maintain yourself

55
00:01:57,720 --> 00:01:59,560
and it's been the go-to for large enterprises

56
00:01:59,560 --> 00:02:00,880
for over two decades.

57
00:02:00,880 --> 00:02:03,960
SCCM works using what's called an agent-based model.

58
00:02:03,960 --> 00:02:05,640
A small piece of software gets installed

59
00:02:05,640 --> 00:02:07,520
on every device you want to manage

60
00:02:07,520 --> 00:02:11,400
and that agent reports back to the SCCM server receives commands

61
00:02:11,400 --> 00:02:12,640
and carries out tasks.

62
00:02:12,640 --> 00:02:15,760
It's like having a tiny IT assistant living on each computer,

63
00:02:15,760 --> 00:02:16,920
waiting for instructions.

64
00:02:16,920 --> 00:02:18,800
So what can SCCM actually do?

65
00:02:18,800 --> 00:02:19,800
A lot.

66
00:02:19,800 --> 00:02:21,720
First, operating system deployment.

67
00:02:21,720 --> 00:02:24,440
You can push out windows to hundreds of new machines at once,

68
00:02:24,440 --> 00:02:27,440
saving days of manual effort, then software distribution.

69
00:02:27,440 --> 00:02:29,440
Install applications like Office or Chrome

70
00:02:29,440 --> 00:02:32,600
across your entire organization from one central console.

71
00:02:32,600 --> 00:02:34,000
It also handles patch management

72
00:02:34,000 --> 00:02:35,920
so you can roll out security updates

73
00:02:35,920 --> 00:02:37,760
on a schedule during maintenance windows

74
00:02:37,760 --> 00:02:40,200
with full control over timing and targeting.

75
00:02:40,200 --> 00:02:41,840
Compliance reporting shows which machines

76
00:02:41,840 --> 00:02:44,000
meet your security standards and which don't.

77
00:02:44,000 --> 00:02:45,680
An inventory gives you a complete picture

78
00:02:45,680 --> 00:02:48,160
of hardware and software across your environment.

79
00:02:48,160 --> 00:02:49,960
Large enterprises have relied on this tool

80
00:02:49,960 --> 00:02:51,040
for more than 20 years.

81
00:02:51,040 --> 00:02:53,160
It's mature, powerful, and gives IT teams

82
00:02:53,160 --> 00:02:55,600
deep granular control over Windows devices.

83
00:02:55,600 --> 00:02:57,240
Need to deploy a complex application

84
00:02:57,240 --> 00:02:59,200
with dependencies and custom scripts?

85
00:02:59,200 --> 00:03:00,680
SCCM can handle it.

86
00:03:00,680 --> 00:03:02,320
Need to image a hundred new laptops

87
00:03:02,320 --> 00:03:04,240
with a custom operating system build?

88
00:03:04,240 --> 00:03:04,920
That too.

89
00:03:04,920 --> 00:03:05,760
But here's the thing.

90
00:03:05,760 --> 00:03:08,160
SCCM requires serious infrastructure.

91
00:03:08,160 --> 00:03:11,320
You need domain controllers, SQL servers, site servers,

92
00:03:11,320 --> 00:03:12,880
distribution points, management points,

93
00:03:12,880 --> 00:03:14,320
and people who know how to set it all up

94
00:03:14,320 --> 00:03:16,480
and keep it running is not something you just turn on

95
00:03:16,480 --> 00:03:17,560
and forget about.

96
00:03:17,560 --> 00:03:19,240
And that's where it sibling comes in.

97
00:03:19,240 --> 00:03:22,120
A tool from Microsoft that takes a completely different approach.

98
00:03:22,120 --> 00:03:25,040
One that doesn't need any of that infrastructure at all.

99
00:03:25,040 --> 00:03:25,880
What is Intune?

100
00:03:25,880 --> 00:03:27,600
The Cloud Native Modern Tool.

101
00:03:27,600 --> 00:03:29,680
Now let's talk about the other option, Intune.

102
00:03:29,680 --> 00:03:31,120
Here's the simplest definition.

103
00:03:31,120 --> 00:03:32,480
It's a cloud-based service.

104
00:03:32,480 --> 00:03:33,520
No service to buy.

105
00:03:33,520 --> 00:03:34,960
No infrastructure to maintain.

106
00:03:34,960 --> 00:03:36,600
No SQL databases to manage.

107
00:03:36,600 --> 00:03:39,120
Everything runs inside Microsoft's Azure Data Centers.

108
00:03:39,120 --> 00:03:41,840
You sign in through a web browser, configure your policies,

109
00:03:41,840 --> 00:03:42,640
and you're done.

110
00:03:42,640 --> 00:03:44,600
Instead of the agent-based model, Intune

111
00:03:44,600 --> 00:03:46,000
uses a profile-based model.

112
00:03:46,000 --> 00:03:47,880
Devices enroll directly with the service

113
00:03:47,880 --> 00:03:50,720
over the internet, receive policies and configurations,

114
00:03:50,720 --> 00:03:53,280
and check in periodically to report their status.

115
00:03:53,280 --> 00:03:54,920
No agent software to install.

116
00:03:54,920 --> 00:03:56,760
No management points to configure.

117
00:03:56,760 --> 00:03:58,840
The device talks directly to the cloud.

118
00:03:58,840 --> 00:04:00,280
That's a big difference in scope.

119
00:04:00,280 --> 00:04:02,360
SCCM is primarily a Windows tool.

120
00:04:02,360 --> 00:04:03,840
It can manage some other platforms,

121
00:04:03,840 --> 00:04:05,480
but it's hard and soul is Windows.

122
00:04:05,480 --> 00:04:08,120
Intune, on the other hand, supports Windows, Mac OS, iOS,

123
00:04:08,120 --> 00:04:08,960
and Android.

124
00:04:08,960 --> 00:04:10,920
So if you have a mixed environment with iPhones

125
00:04:10,920 --> 00:04:13,200
for executives, Android tablets for field workers,

126
00:04:13,200 --> 00:04:14,720
and MacBooks for the design team,

127
00:04:14,720 --> 00:04:17,400
Intune can manage all of them from the same console.

128
00:04:17,400 --> 00:04:18,960
So what can Intune actually do?

129
00:04:18,960 --> 00:04:20,760
It handles device enrollment, uses

130
00:04:20,760 --> 00:04:23,640
can join their own devices, or IT can pre-configure them.

131
00:04:23,640 --> 00:04:26,360
It handles application deployment to Windows, Mac, iOS,

132
00:04:26,360 --> 00:04:27,240
and Android.

133
00:04:27,240 --> 00:04:29,400
Conditional access policies require devices

134
00:04:29,400 --> 00:04:32,520
to be compliant before they can access company data.

135
00:04:32,520 --> 00:04:35,280
Compliance policies define what a healthy device looks like

136
00:04:35,280 --> 00:04:36,600
and generate reports.

137
00:04:36,600 --> 00:04:38,680
And Windows update rings, let patches roll out

138
00:04:38,680 --> 00:04:41,920
in a controlled way, without needing WS/US or on-premises

139
00:04:41,920 --> 00:04:42,800
infrastructure.

140
00:04:42,800 --> 00:04:45,800
This is the direction Microsoft is investing in for the future.

141
00:04:45,800 --> 00:04:48,000
Almost every new feature in endpoint management

142
00:04:48,000 --> 00:04:49,680
is being built for Intune first.

143
00:04:49,680 --> 00:04:52,080
The cloud native approach is where development resources are

144
00:04:52,080 --> 00:04:52,400
going.

145
00:04:52,400 --> 00:04:55,240
So we've got two tools that both manage devices, one runs

146
00:04:55,240 --> 00:04:57,360
on your servers with agents, the other runs in the cloud

147
00:04:57,360 --> 00:04:58,360
with profiles.

148
00:04:58,360 --> 00:05:00,160
They're fundamentally different under the hood,

149
00:05:00,160 --> 00:05:02,560
and we're going to dig into what that actually means.

150
00:05:02,560 --> 00:05:05,120
On-premises versus cloud, the big difference.

151
00:05:05,120 --> 00:05:07,440
Actually, the big difference between SCCM and Intune

152
00:05:07,440 --> 00:05:08,680
comes down to just one thing--

153
00:05:08,680 --> 00:05:09,480
infrastructure.

154
00:05:09,480 --> 00:05:10,800
SCCM needs a lot of it.

155
00:05:10,800 --> 00:05:13,040
You need domain controllers for authentication,

156
00:05:13,040 --> 00:05:15,800
SQL servers to host the site database, site servers

157
00:05:15,800 --> 00:05:18,320
to run the core management role, distribution points

158
00:05:18,320 --> 00:05:20,400
to host content that devices download,

159
00:05:20,400 --> 00:05:23,000
and management points for client communication.

160
00:05:23,000 --> 00:05:24,960
Each of these is a separate server--

161
00:05:24,960 --> 00:05:27,720
or multiple servers, or running Windows server,

162
00:05:27,720 --> 00:05:31,000
consuming licenses requiring patches, needing backups.

163
00:05:31,000 --> 00:05:33,840
Intune needs one thing, an internet connection.

164
00:05:33,840 --> 00:05:34,360
That's it.

165
00:05:34,360 --> 00:05:37,000
No servers, no SQL databases, no distribution points,

166
00:05:37,000 --> 00:05:38,120
no management points.

167
00:05:38,120 --> 00:05:40,720
The infrastructure is Microsoft's problem, not yours.

168
00:05:40,720 --> 00:05:43,640
This difference shows up in every part of how these tools work.

169
00:05:43,640 --> 00:05:45,200
Take deployment methods.

170
00:05:45,200 --> 00:05:47,440
In SCCM, deploying a new operating system

171
00:05:47,440 --> 00:05:49,800
to a computer typically involves PXC boot.

172
00:05:49,800 --> 00:05:51,320
The device boots from the network,

173
00:05:51,320 --> 00:05:52,800
connects to a distribution point,

174
00:05:52,800 --> 00:05:55,320
and runs a task sequence that partitions the drive,

175
00:05:55,320 --> 00:05:58,560
installs Windows, applies settings, and installs applications.

176
00:05:58,560 --> 00:06:00,280
It's powerful, but it requires the device

177
00:06:00,280 --> 00:06:02,040
to be on the corporate network connected

178
00:06:02,040 --> 00:06:03,200
to the right infrastructure.

179
00:06:03,200 --> 00:06:04,960
Intune takes a completely different approach

180
00:06:04,960 --> 00:06:06,440
with Windows autopilot.

181
00:06:06,440 --> 00:06:08,360
A new laptop arrives from the manufacturer,

182
00:06:08,360 --> 00:06:10,240
already registered in your tenant.

183
00:06:10,240 --> 00:06:12,600
The user turns it on, connects to Wi-Fi,

184
00:06:12,600 --> 00:06:14,840
and signs in with their work credentials.

185
00:06:14,840 --> 00:06:17,600
From there, Windows configures itself automatically,

186
00:06:17,600 --> 00:06:20,600
applications install from the cloud, and policies apply.

187
00:06:20,600 --> 00:06:22,960
The device is ready to use in minutes, no imaging,

188
00:06:22,960 --> 00:06:25,880
no PXC boot, and no IT staff needed.

189
00:06:25,880 --> 00:06:27,920
Update management follows the same pattern.

190
00:06:27,920 --> 00:06:32,360
SCCM integrates with WSUS, Windows Server Update Services,

191
00:06:32,360 --> 00:06:34,280
to download and approve patches.

192
00:06:34,280 --> 00:06:35,520
You configure maintenance Windows,

193
00:06:35,520 --> 00:06:37,520
create deployment packages, target collections,

194
00:06:37,520 --> 00:06:38,560
and monitor compliance.

195
00:06:38,560 --> 00:06:41,920
It gives you deep control, but there are a lot of moving parts.

196
00:06:41,920 --> 00:06:44,320
Intune uses Windows Update for business.

197
00:06:44,320 --> 00:06:46,600
You create update rings, groups of devices

198
00:06:46,600 --> 00:06:48,600
with the same update settings, and decide

199
00:06:48,600 --> 00:06:51,360
how fast updates roll out when deadlines happen,

200
00:06:51,360 --> 00:06:53,440
and what features to defer.

201
00:06:53,440 --> 00:06:55,920
Devices check directly with Microsoft's update servers,

202
00:06:55,920 --> 00:06:58,520
no WSUS, no distribution points, no maintenance

203
00:06:58,520 --> 00:07:00,800
windows to configure, and security integration

204
00:07:00,800 --> 00:07:02,320
follows the same split.

205
00:07:02,320 --> 00:07:04,640
Intune connects natively with Azure Active Directory

206
00:07:04,640 --> 00:07:06,000
and conditional access.

207
00:07:06,000 --> 00:07:07,720
The device reports its compliance status.

208
00:07:07,720 --> 00:07:09,800
If it's not compliant, missing an update,

209
00:07:09,800 --> 00:07:11,960
no encryption, outdated antivirus,

210
00:07:11,960 --> 00:07:14,520
conditional access can block it from accessing email teams

211
00:07:14,520 --> 00:07:15,680
or SharePoint.

212
00:07:15,680 --> 00:07:17,560
It happens automatically in real time,

213
00:07:17,560 --> 00:07:20,000
without any on-premises infrastructure.

214
00:07:20,000 --> 00:07:22,080
SCCM has its own compliance engine.

215
00:07:22,080 --> 00:07:25,400
It can evaluate policies, generate reports, and remediate issues,

216
00:07:25,400 --> 00:07:27,280
but it doesn't integrate as seamlessly

217
00:07:27,280 --> 00:07:29,520
with cloud identity and access controls.

218
00:07:29,520 --> 00:07:32,160
You can make it work, but it takes more effort and more pieces.

219
00:07:32,160 --> 00:07:33,680
These differences aren't abstract.

220
00:07:33,680 --> 00:07:36,280
They matter depending on what you're actually trying to do.

221
00:07:36,280 --> 00:07:38,320
If your workforce is in one building,

222
00:07:38,320 --> 00:07:41,160
on the corporate network, with standardized Windows Desktops,

223
00:07:41,160 --> 00:07:43,680
SCCM's depth might be exactly what you need.

224
00:07:43,680 --> 00:07:46,080
But if your workforce is spread across the country,

225
00:07:46,080 --> 00:07:48,120
working from home on a mix of devices,

226
00:07:48,120 --> 00:07:50,320
Intune's cloud native approach starts to look

227
00:07:50,320 --> 00:07:51,960
a lot more practical.

228
00:07:51,960 --> 00:07:54,880
What each tool does best feature comparison.

229
00:07:54,880 --> 00:07:56,800
So let's put them side by side on the tasks

230
00:07:56,800 --> 00:07:58,120
I teams do every day.

231
00:07:58,120 --> 00:08:00,200
This is where the differences really show up.

232
00:08:00,200 --> 00:08:01,880
Start with application deployment.

233
00:08:01,880 --> 00:08:03,600
In SCCM, you have full control.

234
00:08:03,600 --> 00:08:06,120
You can create complex deployments with dependencies.

235
00:08:06,120 --> 00:08:08,600
Install this, then that, then check for a registry key

236
00:08:08,600 --> 00:08:09,680
before proceeding.

237
00:08:09,680 --> 00:08:12,040
You can schedule deployments for specific times,

238
00:08:12,040 --> 00:08:15,120
target specific collections, and configure superceedings

239
00:08:15,120 --> 00:08:17,840
so old versions get replaced automatically.

240
00:08:17,840 --> 00:08:19,880
If you need to deploy a line of business application

241
00:08:19,880 --> 00:08:23,880
with custom scripts and multiple MSI files, SCCM handles it,

242
00:08:23,880 --> 00:08:25,640
Intune can deploy applications too.

243
00:08:25,640 --> 00:08:29,240
Win32 apps, Microsoft Store Apps, line of business apps.

244
00:08:29,240 --> 00:08:29,920
But it's simpler.

245
00:08:29,920 --> 00:08:32,080
You upload the installer, configure detection rules,

246
00:08:32,080 --> 00:08:33,400
and assign it to a group.

247
00:08:33,400 --> 00:08:35,200
It works well for most common scenarios.

248
00:08:35,200 --> 00:08:39,440
But if you need deep orchestration and sequencing, SCCM still wins.

249
00:08:39,440 --> 00:08:42,640
Now OS deployment, this is where SCCM really shines.

250
00:08:42,640 --> 00:08:45,160
Task sequences let you do bare metal deployments.

251
00:08:45,160 --> 00:08:47,520
A blank hard drive becomes a fully configured Windows machine

252
00:08:47,520 --> 00:08:49,960
with applications, settings, and security policies.

253
00:08:49,960 --> 00:08:53,280
You can do in place upgrades from Windows 10 to Windows 11

254
00:08:53,280 --> 00:08:55,280
and customize every step of the process.

255
00:08:55,280 --> 00:08:58,200
Intune takes a different approach with Windows autopilot.

256
00:08:58,200 --> 00:09:00,240
The device arrives, the user signs in,

257
00:09:00,240 --> 00:09:01,400
and the cloud does the rest.

258
00:09:01,400 --> 00:09:04,200
It's faster, simpler, and works great for modern hardware.

259
00:09:04,200 --> 00:09:06,360
But if you need to re-image existing machines,

260
00:09:06,360 --> 00:09:08,120
handle complex upgrade scenarios

261
00:09:08,120 --> 00:09:11,480
or deploy custom Windows images, SCCM's task sequences

262
00:09:11,480 --> 00:09:12,640
are still the gold standard.

263
00:09:12,640 --> 00:09:14,320
Compliance in reporting is another area

264
00:09:14,320 --> 00:09:15,800
where the tools diverge.

265
00:09:15,800 --> 00:09:18,280
SCCM has SQL Server Reporting Services,

266
00:09:18,280 --> 00:09:20,640
so you can build custom reports on almost anything,

267
00:09:20,640 --> 00:09:22,360
which machines have a specific software,

268
00:09:22,360 --> 00:09:24,040
which are missing a critical update,

269
00:09:24,040 --> 00:09:26,840
what hardware configurations exist across your fleet.

270
00:09:26,840 --> 00:09:28,400
The reporting is deep and customizable,

271
00:09:28,400 --> 00:09:29,600
but it takes work to set up.

272
00:09:29,600 --> 00:09:31,240
Intune has cloud-based dashboards

273
00:09:31,240 --> 00:09:33,000
that are much easier to use.

274
00:09:33,000 --> 00:09:35,160
You can see compliance status at a glance,

275
00:09:35,160 --> 00:09:38,040
drill into specific devices and export reports.

276
00:09:38,040 --> 00:09:40,040
It's less customizable than SCCM,

277
00:09:40,040 --> 00:09:42,120
but for most organizations, it's enough.

278
00:09:42,120 --> 00:09:44,400
Mobile Device Management is Intune's territory.

279
00:09:44,400 --> 00:09:46,880
SCCM doesn't manage phones or tablets, period.

280
00:09:46,880 --> 00:09:51,080
If you have iPhones, Android devices, or iPads in your organization,

281
00:09:51,080 --> 00:09:52,760
Intune is the tool you need.

282
00:09:52,760 --> 00:09:55,520
It handles enrollment, app deployment, compliance policies,

283
00:09:55,520 --> 00:09:57,520
and remote wipe for mobile devices.

284
00:09:57,520 --> 00:09:59,160
SCCM simply can't do that.

285
00:09:59,160 --> 00:10:00,880
And Server Management goes the other way.

286
00:10:00,880 --> 00:10:04,000
SCCM handles servers, patching, monitoring, inventory,

287
00:10:04,000 --> 00:10:05,080
software deployment.

288
00:10:05,080 --> 00:10:06,200
It's built for it.

289
00:10:06,200 --> 00:10:08,560
Intune has some server support through Azure Arc,

290
00:10:08,560 --> 00:10:09,600
but it's limited.

291
00:10:09,600 --> 00:10:11,600
If you're managing Windows Server infrastructure,

292
00:10:11,600 --> 00:10:13,280
SCCM is still the right tool.

293
00:10:13,280 --> 00:10:14,800
So you can see the pattern.

294
00:10:14,800 --> 00:10:16,560
SCCM gives you depth and control

295
00:10:16,560 --> 00:10:18,720
for complex Windows and server scenarios.

296
00:10:18,720 --> 00:10:21,120
Intune gives you simplicity and cross-platform support

297
00:10:21,120 --> 00:10:22,360
for modern endpoints.

298
00:10:22,360 --> 00:10:24,040
But what if you need both?

299
00:10:24,040 --> 00:10:26,320
Co-management, running both at once.

300
00:10:26,320 --> 00:10:27,560
That's where Co-management comes in.

301
00:10:27,560 --> 00:10:28,920
It's Microsoft's supported model,

302
00:10:28,920 --> 00:10:31,240
where a single device runs under both SCCM

303
00:10:31,240 --> 00:10:34,480
and Intune at the same time, not either or, but both.

304
00:10:34,480 --> 00:10:35,720
Let's break down how this works.

305
00:10:35,720 --> 00:10:38,520
You enable Co-management on your SCCM managed devices.

306
00:10:38,520 --> 00:10:40,480
They enroll in Intune and now both tools

307
00:10:40,480 --> 00:10:41,840
manage them simultaneously.

308
00:10:41,840 --> 00:10:43,800
But you decide which tool handles which task.

309
00:10:43,800 --> 00:10:45,720
Microsoft calls these workloads sliders,

310
00:10:45,720 --> 00:10:48,080
think of them like a control panel with switches.

311
00:10:48,080 --> 00:10:50,680
For each category of management, compliance policies,

312
00:10:50,680 --> 00:10:52,520
device configuration, Windows updates,

313
00:10:52,520 --> 00:10:54,720
endpoint protection, application deployment,

314
00:10:54,720 --> 00:10:57,640
you slide the switch to either SCCM or Intune.

315
00:10:57,640 --> 00:10:59,840
That tool becomes the authority for that workload

316
00:10:59,840 --> 00:11:01,120
and the other tool steps back.

317
00:11:01,120 --> 00:11:03,040
For example, you could keep application deployment

318
00:11:03,040 --> 00:11:05,440
in SCCM because your complex deployments

319
00:11:05,440 --> 00:11:08,080
still need the depth but slide compliance policies

320
00:11:08,080 --> 00:11:11,080
to Intune for cloud-native conditional access integration.

321
00:11:11,080 --> 00:11:12,920
You could keep Windows updates in SCCM

322
00:11:12,920 --> 00:11:14,720
with your existing maintenance windows

323
00:11:14,720 --> 00:11:16,680
but slide endpoint protection to Intune

324
00:11:16,680 --> 00:11:19,000
so Defender policies live in the cloud.

325
00:11:19,000 --> 00:11:21,400
You decide workload by workload at your own pace.

326
00:11:21,400 --> 00:11:23,400
There's also a feature called tenant attach

327
00:11:23,400 --> 00:11:26,160
which surfaces your SCCM managed devices

328
00:11:26,160 --> 00:11:27,800
inside the Intune console.

329
00:11:27,800 --> 00:11:29,640
So even if you're not ready to move workloads,

330
00:11:29,640 --> 00:11:31,680
you can see all your devices in one place,

331
00:11:31,680 --> 00:11:34,800
run reports, take actions, and get that unified view

332
00:11:34,800 --> 00:11:36,960
without changing how anything works.

333
00:11:36,960 --> 00:11:39,960
This makes co-management a gradual migration path.

334
00:11:39,960 --> 00:11:42,720
Most organizations use it for 12 to 18 months,

335
00:11:42,720 --> 00:11:44,880
starting with the easy workloads like compliance

336
00:11:44,880 --> 00:11:46,920
and endpoint protection, then moving updates,

337
00:11:46,920 --> 00:11:49,720
then applications step-by-step workload by workload

338
00:11:49,720 --> 00:11:51,520
until Intune handles most of the load

339
00:11:51,520 --> 00:11:53,760
and SCCM only does what it does best.

340
00:11:53,760 --> 00:11:56,360
And here's the thing that surprises a lot of people licensing.

341
00:11:56,360 --> 00:11:59,120
If you have Microsoft 365 e3 or e5,

342
00:11:59,120 --> 00:12:01,800
you usually already have rights to both SCCM and Intune

343
00:12:01,800 --> 00:12:03,440
so running both doesn't cost extra.

344
00:12:03,440 --> 00:12:05,080
The licensing is already covered.

345
00:12:05,080 --> 00:12:07,440
There's no financial reason not to use co-management

346
00:12:07,440 --> 00:12:09,160
if it makes sense for your environment.

347
00:12:09,160 --> 00:12:11,560
Co-management is the bridge letting you keep what works

348
00:12:11,560 --> 00:12:13,080
while moving towards what's next,

349
00:12:13,080 --> 00:12:16,680
but where you start depends entirely on your organization.

350
00:12:16,680 --> 00:12:19,320
Decision framework, which one should you use?

351
00:12:19,320 --> 00:12:22,120
So you've seen how both tools work, how they compare,

352
00:12:22,120 --> 00:12:24,240
and how co-management bridges the gap.

353
00:12:24,240 --> 00:12:27,000
The question now is simple, which one should you actually use?

354
00:12:27,000 --> 00:12:28,240
Let's break it down by scenario.

355
00:12:28,240 --> 00:12:31,840
Use SCCM if you have a large on-premises environment.

356
00:12:31,840 --> 00:12:34,080
If your organization has hundreds or thousands

357
00:12:34,080 --> 00:12:37,600
of Windows desktop's in offices connected to a corporate network

358
00:12:37,600 --> 00:12:40,280
with IT staff managing everything locally.

359
00:12:40,280 --> 00:12:42,880
If you need task sequences for OS deployment,

360
00:12:42,880 --> 00:12:45,080
imaging new machines, upgrading operating systems,

361
00:12:45,080 --> 00:12:46,560
handling complex build processes,

362
00:12:46,560 --> 00:12:49,200
or if you manage servers, patching, monitoring, inventory,

363
00:12:49,200 --> 00:12:50,680
if you require deep custom reporting

364
00:12:50,680 --> 00:12:52,800
that pulls data from SQL databases

365
00:12:52,800 --> 00:12:54,600
and generates detailed compliance audits,

366
00:12:54,600 --> 00:12:57,000
SCCM is built for these scenarios.

367
00:12:57,000 --> 00:13:00,120
It's mature, proven, and gives you the control you need.

368
00:13:00,120 --> 00:13:03,200
On the other hand, use Intune if you're cloud-first.

369
00:13:03,200 --> 00:13:06,320
If your organization has already moved most of its infrastructure

370
00:13:06,320 --> 00:13:08,520
to the cloud or you're planning to.

371
00:13:08,520 --> 00:13:10,520
If you have a remote workforce working from home,

372
00:13:10,520 --> 00:13:13,360
coffee shops anywhere, if you need to manage mobile devices

373
00:13:13,360 --> 00:13:15,920
like iPhones, Android phones, iPads,

374
00:13:15,920 --> 00:13:19,200
if you're a smaller organization without dedicated IT infrastructure

375
00:13:19,200 --> 00:13:21,080
or the budget for on-premises servers.

376
00:13:21,080 --> 00:13:23,800
Intune gives you everything you need without the overhead.

377
00:13:23,800 --> 00:13:26,240
And for large enterprises migrating to the cloud,

378
00:13:26,240 --> 00:13:27,760
co-management is the bridge.

379
00:13:27,760 --> 00:13:30,640
If you have existing SCCM infrastructure and expertise

380
00:13:30,640 --> 00:13:33,480
but know the future is cloud-based, use co-management.

381
00:13:33,480 --> 00:13:36,000
If you need the depth of SCCM for some workloads

382
00:13:36,000 --> 00:13:38,840
like complex app deployments or server management,

383
00:13:38,840 --> 00:13:41,200
but want cloud flexibility for compliance policies

384
00:13:41,200 --> 00:13:44,440
or mobile device management, co-management lets you have both.

385
00:13:44,440 --> 00:13:46,440
Shifting workloads at your own pace.

386
00:13:46,440 --> 00:13:47,760
Here's a reality check.

387
00:13:47,760 --> 00:13:50,000
Intune can handle roughly 80 to 85%

388
00:13:50,000 --> 00:13:51,720
of typical device management scenarios.

389
00:13:51,720 --> 00:13:52,560
That's a lot.

390
00:13:52,560 --> 00:13:54,560
And for most organizations, Intune alone is enough,

391
00:13:54,560 --> 00:13:57,120
but that 15 to 20% gap matters if you need it.

392
00:13:57,120 --> 00:13:59,680
If you're in that gap, needing task sequences,

393
00:13:59,680 --> 00:14:02,360
complex app dependencies, deep server management,

394
00:14:02,360 --> 00:14:05,160
then SCCM or co-management is the right call.

395
00:14:05,160 --> 00:14:07,480
A real example helps bring this to life.

396
00:14:07,480 --> 00:14:08,760
Real-world example.

397
00:14:08,760 --> 00:14:10,160
A company's migration.

398
00:14:10,160 --> 00:14:13,320
Picture a mid-sized company with 2,000 Windows desktops

399
00:14:13,320 --> 00:14:14,920
and 500 mobile devices.

400
00:14:14,920 --> 00:14:16,840
They started with SCCM for everything

401
00:14:16,840 --> 00:14:18,360
and for years it worked well.

402
00:14:18,360 --> 00:14:20,440
The IT team knew that tool inside and out,

403
00:14:20,440 --> 00:14:22,800
deployments were controlled, patching was predictable,

404
00:14:22,800 --> 00:14:23,760
and life was good.

405
00:14:23,760 --> 00:14:25,360
But then remote work happened.

406
00:14:25,360 --> 00:14:27,080
Suddenly half the workforce was at home

407
00:14:27,080 --> 00:14:29,520
and those on-premises patching cycles stopped working.

408
00:14:29,520 --> 00:14:30,920
Devices that never left the office

409
00:14:30,920 --> 00:14:32,720
were now scattered across the city.

410
00:14:32,720 --> 00:14:34,640
VPN connections were slow,

411
00:14:34,640 --> 00:14:36,160
and maintenance windows didn't apply

412
00:14:36,160 --> 00:14:37,960
when machines were turned off at night.

413
00:14:37,960 --> 00:14:39,400
The old model was breaking.

414
00:14:39,400 --> 00:14:41,240
They didn't rip out SCCM overnight.

415
00:14:41,240 --> 00:14:44,160
Instead, they spent 14 months implementing co-management.

416
00:14:44,160 --> 00:14:47,160
First, they moved mobile device management to Intune,

417
00:14:47,160 --> 00:14:49,320
all 500 iPhones and Android devices

418
00:14:49,320 --> 00:14:50,720
now managed from the cloud.

419
00:14:50,720 --> 00:14:52,480
Next came compliance policies.

420
00:14:52,480 --> 00:14:54,200
Devices had to meet security standards

421
00:14:54,200 --> 00:14:57,520
before accessing company data enforced through conditional access.

422
00:14:57,520 --> 00:14:59,280
Then they moved Windows updates.

423
00:14:59,280 --> 00:15:01,080
Update rings replaced maintenance windows

424
00:15:01,080 --> 00:15:03,760
and devices checked directly with Microsoft servers

425
00:15:03,760 --> 00:15:06,680
instead of the on-premises WSUs infrastructure.

426
00:15:06,680 --> 00:15:09,440
But they kept task sequences in SCCM for situations

427
00:15:09,440 --> 00:15:11,240
like deploying a custom operating system

428
00:15:11,240 --> 00:15:12,960
image to a lab full of machines.

429
00:15:12,960 --> 00:15:15,200
They also kept complex app deployments there.

430
00:15:15,200 --> 00:15:16,600
The line of business applications

431
00:15:16,600 --> 00:15:18,920
with custom scripts and multiple dependencies,

432
00:15:18,920 --> 00:15:20,720
those stayed where the depth was.

433
00:15:20,720 --> 00:15:21,680
By the time they finished,

434
00:15:21,680 --> 00:15:24,520
server infrastructure costs were down by 60%.

435
00:15:24,520 --> 00:15:26,200
They decommissioned distribution points,

436
00:15:26,200 --> 00:15:28,120
management points and SQL servers.

437
00:15:28,120 --> 00:15:30,520
The remote worker experience improved dramatically.

438
00:15:30,520 --> 00:15:33,400
Devices got updates and policies without needing a VPN

439
00:15:33,400 --> 00:15:34,720
and they still had deep control

440
00:15:34,720 --> 00:15:36,960
for the legacy applications that required it.

441
00:15:36,960 --> 00:15:38,960
That's the pattern more organizations are following.

442
00:15:38,960 --> 00:15:40,240
Not a sudden switch,

443
00:15:40,240 --> 00:15:42,640
but a gradual workload by workload migration.

444
00:15:42,640 --> 00:15:43,920
Co-management is the bridge

445
00:15:43,920 --> 00:15:46,040
and the destination is a modern cloud-connected

446
00:15:46,040 --> 00:15:47,920
endpoint management strategy.

447
00:15:47,920 --> 00:15:49,360
So here's what you need to remember.

448
00:15:49,360 --> 00:15:52,680
SCCM and Intune solve the same problem in very different ways

449
00:15:52,680 --> 00:15:55,360
on premises depth versus cloud simplicity.

450
00:15:55,360 --> 00:15:58,000
Agent-based control versus profile-based flexibility.

451
00:15:58,000 --> 00:15:59,600
One is a 20-year veteran.

452
00:15:59,600 --> 00:16:01,680
The other is the future Microsoft is building.

453
00:16:01,680 --> 00:16:03,560
Intune is the direction things are heading,

454
00:16:03,560 --> 00:16:05,240
but SCCM is in dead.

455
00:16:05,240 --> 00:16:08,000
It's still the right tool for complex Windows environments,

456
00:16:08,000 --> 00:16:09,760
server management and organizations

457
00:16:09,760 --> 00:16:11,160
that need deep control.

458
00:16:11,160 --> 00:16:12,920
And Co-management gives you both,

459
00:16:12,920 --> 00:16:16,200
a gradual path from one to the other at your own pace.

460
00:16:16,200 --> 00:16:17,280
Here's your homework.

461
00:16:17,280 --> 00:16:18,560
Look at your current environment

462
00:16:18,560 --> 00:16:21,760
and identify one workload you could move to Intune this month.

463
00:16:21,760 --> 00:16:23,160
Start with something simple.

464
00:16:23,160 --> 00:16:25,680
Compliance policies may be a mobile device management.

465
00:16:25,680 --> 00:16:26,520
Try it.

466
00:16:26,520 --> 00:16:27,360
See how it feels.

467
00:16:27,360 --> 00:16:28,800
You don't have to move everything at once.

468
00:16:28,800 --> 00:16:30,800
If this episode helped you understand the difference

469
00:16:30,800 --> 00:16:33,520
between SCCM and Intune, please subscribe to the channel.

470
00:16:33,520 --> 00:16:35,720
We break down Microsoft's endpoint management options

471
00:16:35,720 --> 00:16:38,280
in plain English, one knowledge nugget at a time.

Mirko Peters Profile Photo

Founder of m365.fm, m365.show and m365con.net

Mirko Peters is a Microsoft 365 expert, content creator, and founder of m365.fm, a platform dedicated to sharing practical insights on modern workplace technologies. His work focuses on Microsoft 365 governance, security, collaboration, and real-world implementation strategies.

Through his podcast and written content, Mirko provides hands-on guidance for IT professionals, architects, and business leaders navigating the complexities of Microsoft 365. He is known for translating complex topics into clear, actionable advice, often highlighting common mistakes and overlooked risks in real-world environments.

With a strong emphasis on community contribution and knowledge sharing, Mirko is actively building a platform that connects experts, shares experiences, and helps organizations get the most out of their Microsoft 365 investments.