We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Configuration Manager to Intune
Configuration Manager to Intune, UAE

You do not have to switch anything to start getting value from Intune.

Co-management runs Configuration Manager and Intune on the same Windows device at once. Microsoft is explicit that you do not have to move any workload, and that enrolling existing clients delivers Conditional Access with device compliance, remote actions and Autopilot provisioning immediately. The seven workloads move later, one at a time, piloted first.

Book a co-management reviewSee the seven workloads
Configuration Manager to Intune co-management for UAE organisations
  • Seven workloadsMoved individually, when you are ready
  • Zero requiredImmediate value without switching any
  • Pilot firstTest each workload on a subset of devices
  • Both at onceConfigMgr keeps everything you do not move
The framing that unblocks these projects

This is not a migration with a cutover date.

The reason Configuration Manager estates sit unmigrated for years is that everybody imagines a single move. Microsoft has designed the opposite.

  • Enrolling existing Configuration Manager clients delivers immediate capability without switching any workload: Conditional Access with device compliance, remote actions including restart, remote control and factory reset, centralised device health visibility, and Autopilot provisioning. That alone is frequently enough to justify the first phase.
  • Each of the seven workloads moves on its own schedule, and Configuration Manager keeps managing everything you have not moved. There is no point at which you have to commit to the whole thing, and no point at which the old platform stops working because the new one started.
  • Every workload can be piloted on a separate collection of devices before switching a larger group. So each step is tested on people who will tell you it went wrong, and each step is reversible in practice as well as in principle.
  • The consequence is that this can be run as a sequence of contained changes over quarters, fitted around whatever else the team is doing, rather than as a project that needs a window, a freeze and a rollback plan nobody believes in.
Ask us to sequence the workloads for your estate
How it works

Eight things about co-management that change how the project should run.

Microsoft describes co-management as concurrently managing Windows devices using both Configuration Manager and Intune, letting you cloud-attach your existing investment by adding new functionality while keeping the flexibility to use whichever technology works best.

You get value before moving a single workload

Microsoft lists what enrolling existing Configuration Manager clients delivers immediately: Conditional Access with device compliance, Intune-based remote actions including restart, remote control and factory reset, centralised visibility of device health, linking users, devices and applications with Microsoft Entra ID, and modern provisioning with Windows Autopilot. None of that requires switching any workload authority.

Seven workloads, moved individually

Compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run apps and client apps. Microsoft states you do not have to switch them, or you can do them individually when ready, and that Configuration Manager continues to manage everything you do not move plus everything co-management does not cover.

Pilot each workload on a subset before committing

Microsoft describes piloting a workload with a separate collection of devices, so the Intune functionality is tested on a subset before switching a larger group. That per-workload pilot capability is what makes this a series of reversible steps rather than a migration with a single terrifying cutover, and it is the reason these projects can be run without a change freeze.

Two paths in, depending on where the device came from

For existing Configuration Manager clients you set up hybrid Microsoft Entra ID and enrol them into Intune. For new internet-based devices, they join Microsoft Entra ID, automatically enrol to Intune, and you install the Configuration Manager client to reach a co-management state. Most organisations use both simultaneously, which is fine and worth planning for explicitly.

Co-management is not the same as hybrid join, and Microsoft says so

Microsoft calls this confusion out directly, stating that co-management is a management option while Microsoft Entra ID is an identity option, and noting that many customers conflate the two. They interact and they are not the same decision. Sorting out which question is being asked usually resolves half the confusion in the first workshop.

The device identity requirement, which excludes one common state

Devices must be connected to Microsoft Entra ID, either Microsoft Entra hybrid joined or Microsoft Entra joined. Microsoft states plainly that devices only registered with Microsoft Entra ID, sometimes called workplace joined, are not supported with co-management. Finding those devices before you start is considerably better than finding them during a pilot.

Co-management does not solve remote Configuration Manager clients

Microsoft is direct about this: co-management by itself is not a solution for managing remotely connected Windows systems, because the Configuration Manager client still needs to communicate with its assigned site. A cloud management gateway addresses that, and Microsoft notes a gateway is not required for co-management and co-management is not required for a gateway, though they work together.

Co-management, not coexistence, and the difference matters

Microsoft distinguishes them: managing devices with Configuration Manager while enrolled in a third-party mobile device management service is coexistence, and because Configuration Manager and Intune balance workloads to avoid conflicts while third-party services do not, coexistence has real management limitations. If you have a non-Microsoft platform in play, that is the constraint to understand first.

How we approach it

Four things that turn a stalled migration into a sequence that finishes.

Almost every Configuration Manager estate we are asked to look at has been three years away from migrating for the last five years. The obstacle is nearly always framing rather than technology.

We take the immediate value first and prove the model

Enrolling existing clients gives Conditional Access with device compliance, Intune remote actions, centralised device health and Autopilot provisioning without switching any workload. Delivering that first demonstrates that co-management is safe, gives the business something visible, and buys the credibility that the later workload moves need.

We find the unsupported device states before the pilot

Devices only registered with Microsoft Entra ID, described as workplace joined, are not supported with co-management. Every estate has some. Identifying them in advance turns a confusing pilot failure into a known remediation task, and it is a query rather than an investigation.

We sequence workloads by benefit rather than by list order

Compliance policies usually first, because Conditional Access consumes the result. Windows Update next, because it opens the path to Autopatch. Device configuration and client apps later, because they carry the most existing investment and the most packaging work. The published list is not a running order and treating it as one is why these projects stall on the hard one.

We answer the remote device question honestly

Microsoft states plainly that co-management by itself does not solve managing remotely connected Windows systems, because the Configuration Manager client still needs to reach its assigned site. If a meaningful part of your estate rarely touches the corporate network, that is a cloud management gateway conversation or an argument for moving the relevant workloads sooner, and it should be raised at the start.

Where this matters most

Six UAE situations where co-management is the right next step.

The common factor is a working Configuration Manager estate, a genuine reason to modernise, and no appetite for a big-bang migration.

An estate that works, run by people who like it

Configuration Manager is doing its job, the team knows it well, and there is no operational crisis forcing change. Co-management is exactly right here, because it adds cloud capability without asking anybody to abandon a platform that works, and the workloads move when the team is ready rather than when a project plan says so.

An organisation that needs Conditional Access on Windows devices

The most common trigger. Somebody wants only compliant devices to reach company resources, and Configuration Manager alone cannot supply device compliance to Conditional Access. Enrolling existing clients into co-management delivers that immediately, before any workload moves, which makes it a small change with a large security outcome.

A workforce that stopped coming to the office

Configuration Manager clients need to reach their assigned site, and a hybrid workforce means many of them rarely do. That is either a cloud management gateway or an argument for moving update and configuration workloads to Intune sooner. Either way it is the situation where the status quo is actively degrading rather than merely dated.

A regulated firm needing modern device evidence

Where compliance status, device health and update currency need to be demonstrable, centralised visibility of device health plus Intune compliance reporting gives a cleaner answer than a Configuration Manager report a reviewer has never seen. Moving the compliance workload first is what puts that evidence in the place people expect to find it.

An organisation buying new devices and wanting Autopilot

Modern provisioning with Windows Autopilot is listed among the immediate benefits of co-management. For anybody currently imaging devices, the ability to ship a machine directly to a user and have it configure itself is usually the change that makes the case for the whole programme without any further argument.

A group with more than one Configuration Manager environment

Multiple instances from acquisitions or from historical regional splits. Microsoft states that multiple Configuration Manager instances can connect to a single Intune tenant, which means co-management can give you one consistent cloud management plane across them long before anybody attempts to consolidate the on-premises estates.

Three positions

Where UAE organisations with Configuration Manager currently are.

The right column is common and it is rarely a decision. It is what happens when a migration is imagined as one large move that never finds a quarter with room for it.
Conditional Access with device compliance
Co-managed and progressingYes
Co-management enabled, nothing movedYes
Configuration Manager onlyNo
Intune remote actions available
Co-managed and progressingYes
Co-management enabled, nothing movedYes
Configuration Manager onlyNo
Autopilot provisioning available
Co-managed and progressingYes
Co-management enabled, nothing movedYes
Configuration Manager onlyNo
Centralised device health visibility
Co-managed and progressingYes
Co-management enabled, nothing movedYes
Configuration Manager onlyPartly
Update management modernised
Co-managed and progressingYes
Co-management enabled, nothing movedNo
Configuration Manager onlyNo
Path to Windows Autopatch open
Co-managed and progressingYes
Co-management enabled, nothing movedNo
Configuration Manager onlyNo
Configuration delivered without site connectivity
Co-managed and progressingYes
Co-management enabled, nothing movedNo
Configuration Manager onlyNo
Dependency on on-premises infrastructure reducing
Co-managed and progressingYes
Co-management enabled, nothing movedNo
Configuration Manager onlyNo
Remote devices manageable without a gateway
Co-managed and progressingIncreasingly
Co-management enabled, nothing movedNo
Configuration Manager onlyNo
Frequency in the UAE market
Co-managed and progressingUncommon
Co-management enabled, nothing movedCommon
Configuration Manager onlyCommon
Feature
Co-managed and progressing
Co-management enabled, nothing moved
Configuration Manager only
Conditional Access with device compliance
YesYesNo
Intune remote actions available
YesYesNo
Autopilot provisioning available
YesYesNo
Centralised device health visibility
YesYesPartly
Update management modernised
YesNoNo
Path to Windows Autopatch open
YesNoNo
Configuration delivered without site connectivity
YesNoNo
Dependency on on-premises infrastructure reducing
YesNoNo
Remote devices manageable without a gateway
IncreasinglyNoNo
Frequency in the UAE market
UncommonCommonCommon
The seven workloads

What each one moves, and where we usually start.

Reproduced from the published workload list. The ordering is ours, based on which moves deliver the most benefit for the least disruption in the estates we have worked on.
WorkloadWhat moving it changes
Compliance policiesDevice compliance evaluated by Intune, which is what Conditional Access consumes. Usually first.
Windows Update policiesUpdate management moves to Intune, and opens the door to Windows Autopatch.
Endpoint ProtectionDefender policy managed from Intune rather than Configuration Manager.
Device configurationSettings and configuration profiles. The largest workload and usually the last of the core ones.
Resource access policiesCertificate, Wi-Fi, VPN and email profiles delivered from Intune.
Office Click-to-Run appsMicrosoft 365 Apps deployment and update management moves.
Client appsApplication deployment. Frequently the one with the most packaging work behind it.
Everything elseStays with Configuration Manager, including features co-management does not cover.
How an engagement runs

Five steps, spread over quarters rather than weeks.

The first phase is typically four to eight weeks. The workload moves that follow run at whatever pace your team and your change process support, which is the point.
  1. 1

    Assess prerequisites and device state

    Configuration Manager version, Entra ID licensing, Windows automatic enrolment, and crucially the device identity position, since devices only registered with Entra ID are not supported and need identifying before anything else. Also whether devices reliably reach their assigned site, which decides the gateway conversation.

  2. 2

    Enable co-management and take the immediate value

    Enrolling existing clients, with no workload switched, to deliver Conditional Access with device compliance, Intune remote actions, centralised device health visibility and Autopilot provisioning. This phase proves the model is safe and produces something visible before anybody is asked to move anything.

  3. 3

    Pilot the first workload

    Usually compliance policies, on a separate collection of devices, so the Intune behaviour is tested on a subset before a larger group is switched. Piloting is a first-class capability here rather than an improvisation, and using it properly is what keeps each step reversible.

  4. 4

    Move workloads on your own schedule

    Windows Update next in most estates, since it opens the path to Windows Autopatch. Then endpoint protection, resource access, Office Click-to-Run, device configuration and client apps in whatever order suits your existing investment. Configuration Manager keeps managing everything not yet moved.

  5. 5

    Decide the end state deliberately

    Cloud-only, or a stable long-term hybrid where Configuration Manager retains the things it does uniquely well for you. Both are legitimate. What causes problems is drifting into a half-finished state that nobody chose, which is why we ask the question at the start and again once the first workloads have moved.

Straight answers

What organisations ask about moving from Configuration Manager to Intune.

No, and this is the fact that unblocks most of these projects. Microsoft states you do not have to switch the workloads, or you can do them individually when you are ready, and that Configuration Manager continues to manage all other workloads plus all the features co-management does not support. There is no forced cutover and no point at which the old platform stops working.

More than most people expect. Microsoft lists the immediate value of enrolling existing Configuration Manager clients as Conditional Access with device compliance, Intune-based remote actions including restart, remote control and factory reset, centralised visibility of device health, linking users, devices and applications with Microsoft Entra ID, and modern provisioning with Windows Autopilot. For many organisations that first phase is the business case on its own.

Seven: compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run apps and client apps. Each can be switched from Configuration Manager authority to Intune independently, and each can be piloted on a separate collection of devices before a larger group is switched.

Compliance policies, in most estates, because Conditional Access consumes device compliance and that is usually why the organisation started this conversation. Windows Update generally comes next, since moving it opens the path to Windows Autopatch. Device configuration and client apps carry the most existing investment and the most packaging work, so they belong later rather than first.

Yes, and per workload rather than as a whole. Microsoft describes piloting a workload with a separate collection of devices, so the Intune functionality is tested on a subset before switching a larger group. That is what makes each step a contained, observable change rather than an act of faith with a rollback plan nobody has rehearsed.

No, and Microsoft addresses this confusion directly, stating that co-management is a management option while Microsoft Entra ID is an identity option, and noting that many customers conflate them. They interact, since devices must be Entra joined or hybrid joined for co-management, but they are separate decisions with separate work behind them.

Not necessarily, and this is worth checking first. Devices must be connected to Microsoft Entra ID, either hybrid joined or Entra joined. Microsoft states that devices only registered with Microsoft Entra ID, sometimes called workplace joined, are not supported with co-management. Most estates have some of those, and finding them before a pilot is much cheaper than finding them during one.

Only partly, and Microsoft is honest about it. Co-management by itself is not a solution for managing remotely connected Windows systems, because the Configuration Manager client still needs to communicate with its assigned site. A cloud management gateway addresses that, and Microsoft notes it is not required for co-management and co-management is not required for it, though they are commonly used together.

Microsoft lists Microsoft Entra ID P1 or P2, noting that an Enterprise Mobility and Security subscription includes both that and Intune, and at least one Intune licence for the administrator to access the Intune admin center. Microsoft also points to its product and licensing guidance on whether individual user licences are needed, which is worth reading rather than assuming in either direction.

No, and the distinction matters if you have a non-Microsoft device management platform. Managing devices with Configuration Manager while they are enrolled in a third-party mobile device management service is coexistence. Microsoft states that with co-management, Configuration Manager and Intune balance workloads so there are no conflicts, that this interaction does not exist with third-party services, and that coexistence therefore has management limitations.

Yes, and for some organisations that is the right answer. Co-management is explicitly designed so you use whichever technology works best for a given workload, and Configuration Manager retains capabilities co-management does not cover. What we would push back on is drifting into a half-migrated state nobody chose, rather than deciding deliberately that a stable hybrid is the destination.

Yes. Microsoft states that multiple Configuration Manager instances can connect to a single Intune tenant. For groups that acquired companies or that historically split environments by region, this means co-management can deliver one consistent cloud management plane across all of them well before anybody attempts the much larger job of consolidating the on-premises estates.

There is a co-management dashboard that lets you review the machines co-managed in your environment, with graphs that help identify devices needing attention. It is worth watching during the early phases, because the gap between devices you believe are co-managed and devices that actually are is usually where the interesting problems live.

The first phase, enabling co-management and taking the immediate value, is typically four to eight weeks. After that the pace is yours. Some organisations move a workload a quarter, some move three in a month. Because Configuration Manager keeps managing everything not yet switched, there is no penalty for going slowly and no cliff if a workload takes longer than planned.

We scope per organisation, driven by estate size, how many workloads are in scope and whether a cloud management gateway is needed. What we will tell you free in the first conversation is which of your devices are in a state that co-management does not support, because that number determines what the first phase actually involves.
Before starting

Fifteen questions worth answering first.

The first group is prerequisites, several of which stop a project before it starts. The second is sequencing. The third is what happens to Configuration Manager, which needs an honest answer rather than a vague intention.

Prerequisites

  • Are devices Entra joined or hybrid joined?
    Registered-only devices are not supported.
  • Do you have Entra ID P1 or P2?
    A stated licensing prerequisite.
  • Is your Configuration Manager version supported?
    A supported current branch version is required.
  • Is Windows automatic enrolment enabled?
    Part of the Intune setup prerequisites.
  • Do you have devices that never reach the site?
    That is a cloud management gateway question.

Sequencing

  • Which workload delivers most for least disruption?
    Usually compliance policies.
  • Which collection would you pilot with?
    Piloting is per workload and per collection.
  • Is Windows Autopatch in the plan?
    It follows the Windows Update workload moving.
  • How much application packaging sits behind client apps?
    Usually the largest single piece of work.
  • Are there workloads you never intend to move?
    A legitimate answer, and worth recording.

The end state

  • Is the goal cloud-only, or a stable hybrid?
    Both are valid. Deciding matters.
  • What does Configuration Manager still do uniquely for you?
    Frequently more than people expect.
  • Who has Configuration Manager full administrator rights?
    Required to enable co-management.
  • Do you have more than one Configuration Manager instance?
    Multiple can connect to one Intune tenant.
  • Who reviews the co-management dashboard?
    It shows which machines are actually co-managed.
Related reading

The pages around this one.

Microsoft Intune

The destination platform, covering enrolment, configuration profiles, compliance and application deployment.

Learn more

Windows Autopilot

Modern provisioning, listed among the immediate benefits of co-management and usually the most visible one.

Learn more

Windows Autopatch

Where update management goes once the Windows Update workload has moved to Intune.

Learn more
Next step

Start with the phase that requires you to move nothing.

Enrolling existing Configuration Manager clients delivers Conditional Access with device compliance, remote actions and Autopilot provisioning without switching a single workload. It proves the model is safe and it is usually the business case for everything that follows.

Book a co-management reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft Intune

Device management and endpoint security

Learn more

Windows Autopilot Dubai

Zero-touch laptop deployment, supplier registration onward

Learn more

Windows Autopatch

Security updates without a restart, and Business Premium has it

Learn more

Intune Compliance Policies

The default that lets unassessed devices through Conditional Access

Learn more

Entra Conditional Access

The control that decides who reaches your data

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

Intune Suite

Eight advanced capabilities, and one trial each per tenant

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy