We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and endpoint management
  2. Co-management
Configuration Manager co-management, UAE

Co-management is not a way to manage remote devices. The Configuration Manager client still has to reach its site.

Microsoft states that directly, and it is the assumption that derails most co-management projects started for remote working reasons. Co-management adds cloud capability to an existing Configuration Manager estate. Reaching devices over the internet is a separate piece of work.

Book a co-management assessmentSee what can move
Configuration Manager and Intune co-management for UAE organisations
  • 7 workloadsCan be switched from ConfigMgr to Intune
  • Pilot firstAny workload, on a separate collection
  • Both, not eitherConfigMgr keeps everything not switched
  • Not workplace joinedRegistered-only devices are unsupported
The confusion to clear first

Co-management is a management option. Microsoft Entra ID is an identity option.

Microsoft says this explicitly, and notes that many customers confuse the two. Separating them is the first thing worth doing in any co-management conversation.

  • Co-management enables you to concurrently manage Windows devices using both Configuration Manager and Microsoft Intune, with the two balancing workloads so there are no conflicts. It is a statement about which authority owns which workload.
  • The identity question is separate and it is a prerequisite. Devices must be Microsoft Entra hybrid joined or Microsoft Entra joined. Devices only registered with Microsoft Entra ID, sometimes called workplace joined, are not supported with co-management.
  • Third party management alongside Configuration Manager is coexistence rather than co-management, and Microsoft is clear that the workload balancing interaction does not exist there, which is why coexistence carries management capability limitations that co-management does not.
  • Getting these three distinctions straight at the start prevents a project that is nominally about device management from stalling on an identity problem nobody scoped, which is the most common way this work runs long.
What co-management gives you

Eight things to establish before enabling it.

Co-management is the pragmatic middle path between keeping Configuration Manager and replacing it. It delivers real capability on day one and it carries prerequisites and boundaries that decide whether the project is straightforward or not.

Both authorities, deliberately

Windows devices carry the Configuration Manager client and are enrolled in Intune, and you control which workloads move. Configuration Manager continues managing everything not switched, plus all its features that co-management does not cover, so nothing is lost by enabling it.

What you gain immediately

Conditional Access with device compliance, Intune remote actions including restart, remote control and factory reset, centralised visibility of device health, users, devices and applications linked in Entra ID, and modern provisioning with Windows Autopilot. All of that before any workload moves.

Seven workloads that can move

Compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run applications and client applications. Each moves independently, and there is no requirement to move any of them for co-management to be worthwhile.

Piloting per workload

A workload can be piloted against a separate collection of devices, which lets you test Intune functionality with a subset before switching a larger group. That per-workload, per-collection granularity is what makes a staged migration genuinely low risk rather than nominally so.

It does not solve remote connectivity

Microsoft states co-management by itself is not a solution for managing remotely connected Windows systems, because the Configuration Manager client still needs to communicate with its assigned site. A cloud management gateway addresses that, and it is a separate decision.

Join state requirements that exclude a common case

Devices must be Entra hybrid joined or Entra joined. Devices only registered with Entra ID, sometimes called workplace joined, are not supported with co-management. In estates where personal devices were registered rather than joined, those machines are outside the model.

Two routes in, depending where you start

Existing Configuration Manager clients reach co-management by setting up hybrid Entra ID and enrolling into Intune. New internet-based devices join Entra ID, automatically enrol into Intune, and reach co-management when the Configuration Manager client is installed.

A dashboard that shows the real state

The co-management dashboard reviews which machines are co-managed and its graphs help identify devices needing attention. In a migration that runs over months, that view is what distinguishes progress from the assumption of progress.

Two things people conflate

Co-management is a management option. Entra join is an identity option.

Microsoft addresses this confusion directly in its own documentation, because it comes up constantly and it produces plans that do not work.

  • Microsoft states plainly that co-management is a management option while Microsoft Entra ID is an identity option, and that many customers confuse the two topics. A project scoped as moving to co-management is not the same as a project scoped as moving to Entra join, and treating them as one produces a plan that satisfies neither.
  • The join requirement is real though. Devices must be Entra hybrid joined or Entra joined, and devices only registered with Entra ID, sometimes described as workplace joined, are not supported with co-management. That is a genuine identity prerequisite rather than the same conversation.
  • The second conflation is remote connectivity. Co-management by itself is not a solution for managing remotely connected Windows systems, because the Configuration Manager client still needs to communicate with its assigned site. A cloud management gateway solves that, and it is neither required by nor requires co-management.
  • So a project driven by hybrid working needs both pieces scoped separately: co-management for the cloud capability, and a cloud management gateway for the connectivity. Discovering the second requirement after the first is complete is a common and avoidable sequencing problem.
Ask us to scope both pieces
How we approach it

Four things that keep a co-management project honest.

Co-management projects fail in a specific way: they are started for a reason co-management does not address, and the mismatch is not noticed until the capability is enabled and the original problem remains.

We check the driver against what co-management does

If the driver is managing devices that rarely connect to the corporate network, co-management alone does not solve it, because the Configuration Manager client still needs to reach its assigned site. That needs a cloud management gateway, which is neither required by nor requires co-management.

We audit join state before anything else

Devices must be Entra joined or Entra hybrid joined. Devices only registered with Entra ID, sometimes called workplace joined, are not supported. In estates where registration happened organically, that population needs an identity decision before a management one.

We move workloads one at a time, piloted

Each workload can be piloted against a separate collection before switching a wider group. Moving several at once removes the ability to attribute a problem to a specific change, which is the main thing that turns a controlled migration into a difficult month.

We take the immediate value before moving anything

Enabling co-management alone delivers Conditional Access with device compliance, Intune remote actions, centralised device health visibility and Autopilot provisioning. Proving that first gives the organisation something concrete while the workload discussion is still happening.

How an engagement runs

Four phases across roughly eight to twelve weeks.

Longer than most Intune work because workloads move one at a time with a pilot collection each. That pace is the point rather than an inefficiency.
  1. 01
    Weeks 1 to 2

    Establish prerequisites and the real starting point

    Configuration Manager version, device join states across the estate, Entra ID licensing, and an Intune licence on the administrator account. Devices registered rather than joined identified separately, since they are not supported and need an identity decision first.

    • Configuration Manager version and health confirmed
    • Device join state inventory across the estate
    • Registered-only devices identified as out of scope
    • Licensing and administrator account verified
  2. 02
    Weeks 3 to 4

    Enable co-management and take the immediate value

    Co-management enabled with no workloads switched, which already delivers Conditional Access with device compliance, Intune remote actions, centralised device health visibility and Autopilot provisioning. Proving that before moving anything builds confidence cheaply.

    • Co-management enabled with no workloads switched
    • Automatic enrolment confirmed working
    • Conditional Access with device compliance in place
    • Co-management dashboard reviewed for real coverage
  3. 03
    Weeks 5 to 9

    Move workloads one at a time, piloted first

    Each of the seven workloads piloted against a separate collection before switching a wider group. The order matters: compliance policies and Windows Update policies are usually the safest starting points, and client applications the most disruptive.

    • Workload order agreed with reasoning
    • Pilot collection defined per workload
    • Each workload validated before wider switching
    • Rollback path confirmed per workload
  4. 04
    Weeks 10 to 12

    Decide the connectivity question and the destination

    Whether a cloud management gateway is needed for remotely connected devices, since co-management alone does not address that. Then the longer term question of whether this is a permanent hybrid or a staging post toward full Intune management.

    • Cloud management gateway decision recorded
    • Long term target state agreed
    • Remaining Configuration Manager dependencies documented
    • Operational handover with the dashboard as the measure
Where this fits

Six situations where co-management is the right answer.

The common feature is a working Configuration Manager estate that needs cloud capability without a disruptive replacement project.

An organisation that needs Conditional Access on Windows

Device compliance as a Conditional Access signal is one of the immediate benefits, available as soon as co-management is enabled and before any workload moves. For an estate that has everything except that, it is the shortest route to closing the gap.

An operator with deep Configuration Manager investment

Where operating system deployment, complex application packaging and site infrastructure represent years of work, replacing it wholesale is disproportionate. Co-management keeps that investment while adding what Configuration Manager cannot do on its own.

A business planning an eventual migration

Co-management is a legitimate staging post. Workloads move one at a time with pilots, and Configuration Manager continues managing everything not switched, so the transition happens over quarters with the ability to pause or step back at any point.

A regulated firm that cannot accept a big-bang change

Per-workload switching with per-collection piloting produces a change record that is granular and reversible, which is a far easier proposition to put through a change advisory board than a single migration with one cutover date.

A company adopting Windows Autopilot

Modern provisioning with Autopilot is listed among the immediate benefits of co-management. For an estate still building machines with task sequences, that alone can justify enabling it while the wider workload question remains open.

A group with more than one Configuration Manager site

Multiple Configuration Manager instances can connect to a single Intune tenant, which suits organisations that grew through acquisition and now run several sites. It gives one cloud view across them without consolidating the on-premises infrastructure first.

Three positions

How UAE organisations manage a Configuration Manager estate.

The middle column is where most estates should be for a period, and the mistake is treating it as a failure to commit rather than as a deliberate architecture.
Conditional Access with device compliance
Co-management, stagedYes
Configuration Manager onlyNo
Full Intune migrationYes
Intune remote actions
Co-management, stagedYes
Configuration Manager onlyNo
Full Intune migrationYes
Windows Autopilot provisioning
Co-management, stagedYes
Configuration Manager onlyNo
Full Intune migrationYes
Existing ConfigMgr investment retained
Co-management, stagedYes
Configuration Manager onlyYes
Full Intune migrationNo
Workloads move independently
Co-management, stagedYes
Configuration Manager onlyNot applicable
Full Intune migrationAll at once
Pilot per workload possible
Co-management, stagedYes
Configuration Manager onlyNot applicable
Full Intune migrationLimited
Remote device management
Co-management, stagedNeeds a CMG
Configuration Manager onlyNeeds a CMG
Full Intune migrationNative
Two consoles to operate
Co-management, stagedYes
Configuration Manager onlyOne
Full Intune migrationOne
Rollback available
Co-management, stagedPer workload
Configuration Manager onlyNot applicable
Full Intune migrationDifficult
Suits a long transition
Co-management, stagedYes
Configuration Manager onlyNot a transition
Full Intune migrationNo
Feature
Co-management, staged
Configuration Manager only
Full Intune migration
Conditional Access with device compliance
YesNoYes
Intune remote actions
YesNoYes
Windows Autopilot provisioning
YesNoYes
Existing ConfigMgr investment retained
YesYesNo
Workloads move independently
YesNot applicableAll at once
Pilot per workload possible
YesNot applicableLimited
Remote device management
Needs a CMGNeeds a CMGNative
Two consoles to operate
YesOneOne
Rollback available
Per workloadNot applicableDifficult
Suits a long transition
YesNot a transitionNo
Prerequisites

Ten things to have in place before enabling co-management.

Each of these is published, and the licensing and permissions rows are the ones that most often stall an otherwise well-planned first attempt.
RequirementDetail
Entra ID licensingMicrosoft Entra ID P1 or P2, included in Enterprise Mobility and Security
Administrator licensingAt least one Intune licence on the account signing into the admin centre
Symptom if that is missingSign in fails with an unanticipated error occurred
Configuration Manager versionA supported version of the current branch
Multiple sitesMultiple Configuration Manager instances can connect to one Intune tenant
Device join stateEntra hybrid joined or Entra joined, not registered only
Intune setupIntune configured with Windows automatic enrolment enabled
Enabling co-managementAn Entra user plus Configuration Manager Full Administrator with All scope
Creating Entra apps from ConfigMgrEntra ID Global Administrator
Setting up a cloud management gatewayAzure Subscription Manager role
How an engagement runs

Five steps, and the first tests whether this is the right project.

Co-management is genuinely valuable and it is not the answer to every Configuration Manager problem. Confirming the fit takes a conversation and saves a quarter.
  1. 1

    Test the driver against what co-management delivers

    Conditional Access with device compliance, Intune remote actions, device health visibility and Autopilot provisioning are what enabling it gives you. Managing remotely connected devices is not, because the Configuration Manager client still needs to reach its assigned site.

  2. 2

    Confirm prerequisites and join state

    A supported Configuration Manager current branch version, Entra ID P1 or P2, an Intune licence on the administrator account, Windows automatic enrolment enabled, and devices Entra joined or hybrid joined rather than registered only, which is unsupported.

  3. 3

    Enable co-management without switching workloads

    The immediate benefits arrive at this point, before any workload moves. That gives the organisation something demonstrable early, and it separates the question of enabling co-management from the longer discussion about which workloads should move and when.

  4. 4

    Move workloads individually, each piloted

    Compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run applications and client applications, in an agreed order, each piloted against a separate collection before a wider switch.

  5. 5

    Resolve connectivity and agree the destination

    Whether a cloud management gateway is needed for internet-based devices, and whether co-management is a permanent architecture or a staging post toward full Intune management. Both are legitimate answers, and deciding explicitly prevents drift.

Straight answers

What organisations ask about co-management.

Not on its own. Microsoft states co-management by itself is not a solution to manage remotely connected Windows systems, because the Configuration Manager client still needs to communicate with its assigned site. A cloud management gateway addresses that, and the two are independent of each other.

No. Enabling co-management delivers Conditional Access with device compliance, Intune remote actions, centralised device health visibility and Autopilot provisioning without switching anything. Configuration Manager continues managing all workloads you do not move, plus everything co-management does not support.

Seven: compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run applications and client applications. Each moves independently, and you can pilot any of them against a separate collection before switching a wider group.

They need to be Entra joined or Entra hybrid joined. Devices only registered with Entra ID, sometimes described as workplace joined, are not supported with co-management. In estates where registration happened organically, that population needs addressing before enabling.

No, and Microsoft addresses this confusion explicitly. Co-management is a management option while Microsoft Entra ID is an identity option. They interact, since co-management has a join state requirement, but they are different decisions with different scopes.

Microsoft Entra ID P1 or P2, which is included in an Enterprise Mobility and Security subscription along with Intune, and at least one Intune licence for the administrator accessing the Intune admin centre. That last one catches people out more often than it should.

Most likely the account lacks an Intune licence. Microsoft notes specifically that without one assigned to the account used to sign in to the tenant, sign in fails with an unanticipated error occurred, which is not a message that points anybody toward licensing.

Yes. Multiple Configuration Manager instances can connect to a single Intune tenant, which is useful for organisations that grew through acquisition and run several sites. It gives a single cloud view without consolidating on-premises infrastructure first.

Coexistence is Configuration Manager alongside a third-party MDM service. With co-management, Configuration Manager and Intune balance the workloads so there are no conflicts. Microsoft notes that interaction does not exist with third-party services, so coexistence carries management capability limitations.

A Microsoft Entra user with Configuration Manager Full Administrator holding All scope rights. Creating Entra applications from Configuration Manager needs Entra ID Global Administrator, importing Azure applications needs Configuration Manager Full Administrator only, and a cloud management gateway needs the Azure Subscription Manager role.

In most engagements compliance policies, because the value is immediate through Conditional Access and the blast radius is contained. Windows Update policies frequently follow. Client applications tend to be last, because that is where the deepest Configuration Manager investment usually sits.

Workloads are switched deliberately and piloted against a separate collection first specifically so that a wider switch is an informed decision. Planning the rollback path per workload before switching is part of a properly run migration rather than an afterthought.

The co-management dashboard reviews machines that are co-managed in the environment, with graphs to help identify devices that might need attention. Over a migration measured in months, that view is what separates real progress from the assumption of it.

Both are legitimate, and deciding which explicitly is worth doing. Some organisations retain Configuration Manager indefinitely for operating system deployment and complex packaging. Others use co-management as a controlled staging post. What causes problems is never deciding.

We scope by device count, number of Configuration Manager sites and how many workloads are moving. The free first step: check the join state of your Windows devices. Any that are registered rather than joined are outside co-management, and that count shapes the whole plan.

No. Microsoft states a CMG is not required for co-management and co-management is not required with a CMG, but they can be used together. The relevant limitation is that the Configuration Manager client still needs to communicate with its assigned site.

Yes. Microsoft confirms you can connect multiple Configuration Manager instances to a single Intune tenant, which matters for groups that grew by acquisition and now run more than one site hierarchy.

No, and you should not. Microsoft documents piloting a workload with a separate collection of devices, which lets you test the Intune behaviour with a subset before switching a larger group. That pilot collection is the safest way to move.

Most often a licensing gap. At least one Intune licence is required for the administrator to access the Microsoft Intune admin center, and without it sign in fails with the message that an unanticipated error occurred, which is not an obvious clue.

Microsoft lists Conditional Access with device compliance, Intune based remote actions such as restart, remote control or factory reset, centralised visibility of device health, linking users, devices and apps with Entra ID, and modern provisioning with Windows Autopilot.
Readiness check

Fifteen questions to answer before enabling it.

The first group blocks the project if unanswered. The third is the one that determines whether co-management actually solves the problem you started with.

Prerequisites

  • Are we on a supported Configuration Manager version?
    Current branch.
  • Do we have Entra ID P1 or P2?
    Included in EMS.
  • Does the admin account have an Intune licence?
    Sign in fails without one.
  • Is Windows automatic enrolment enabled?
    An Intune prerequisite.
  • Do we have the required roles?
    ConfigMgr Full Administrator, All scope.

Devices

  • Are devices Entra joined or hybrid joined?
    Registered only is unsupported.
  • How many are registered rather than joined?
    They need an identity decision.
  • Do we run more than one ConfigMgr site?
    Multiple can connect to one tenant.
  • Which devices are internet based?
    They may need a CMG.
  • Are devices on a supported Windows version?
    Intune supported platforms.

Intent

  • Why are we doing this?
    Cloud capability or migration staging.
  • Is remote management the real driver?
    That needs a CMG, not co-management.
  • Which workload moves first?
    Compliance is usually safest.
  • Do we have a pilot collection per workload?
    Piloting is supported per workload.
  • Is this permanent or transitional?
    Both are legitimate.
Related reading

The pages around this one.

Configuration Manager to Intune migration

The full migration, for when co-management is a staging post.

Learn more

Intune compliance policies

Usually the first workload to move, and the fastest value.

Learn more

Device enrolment

The enrolment paths co-management depends on.

Learn more
Next step

Check the join state of your Windows devices.

Entra joined and hybrid joined devices can be co-managed. Devices only registered with Entra ID cannot. That count is the first constraint on any co-management plan and it takes minutes to establish.

Book a co-management assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

SCCM to Intune

Co-management, where you get value without moving any workload

Learn more

Intune Compliance Policies

The default that lets unassessed devices through Conditional Access

Learn more

Device Enrolment

Which path, which reset, and what you can enforce after

Learn more

Windows Autopilot Dubai

Zero-touch laptop deployment, supplier registration onward

Learn more

Entra Conditional Access

The control that decides who reaches your data

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Windows Autopatch

Security updates without a restart, and Business Premium has it

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy