Microsoft Intune - Initial Setup
Microsoft Intune - Initial Setup is a 2-week IT Partner service for organizations that want to configure Microsoft Intune to manage and secure corporate devices.
Password-less Authentication is a service for organizations that want to implement multi-factor, password-less PC authentication using Microsoft Windows Hello and Microsoft Intune. IT Partner discusses authentication requirements, selects the appropriate authentication solution, configures Microsoft Intune profiles, devices, and authentication policy, provides user self-setup instructions, and includes break-fix support for the solution within two (2) weeks.
Traditional password policies that rely on stronger complexity rules and frequent password changes can make work harder for employees while still falling short of current cybersecurity needs. This service helps the client implement a multi-factor, password-less authentication approach based on Microsoft Windows Hello and Microsoft Intune, so employees can use two-factor PC authentication without needing to use a password.
Discussion of the requirements for the user authentication process with the client
Choosing the appropriate authentication solution
Configuration of user profiles and devices in Microsoft Intune
Configuration of authentication policy in Microsoft Intune for a test group
Testing on a limited number of devices
Implementation of the solution for all employees
Technical support
Password-less Authentication is a $900 implementation service that helps organizations deploy multi-factor, password-less PC sign-in using Microsoft Windows Hello and Microsoft Intune. IT Partner reviews authentication requirements, selects an appropriate authentication approach, configures Intune profiles, devices, and authentication policy, and provides user self-setup instructions.
This service helps reduce reliance on traditional passwords, because stronger complexity rules and frequent password changes can make work harder without fully addressing modern security needs. The goal is to allow employees to use two-factor PC authentication without needing to use a password.
The service includes a requirements discussion, selection of the appropriate authentication solution, configuration of user profiles and devices in Microsoft Intune, and configuration of authentication policy in Intune. It also includes user self-setup instructions for workstation interaction with the authentication device and break-fix support for the solution within two weeks.
The service does not include the initial setup of Microsoft Intune, purchasing licenses, user training, or Entra ID configuration if the company uses only on-premises Active Directory. If your organization does not already use Microsoft Intune, its configuration can be ordered separately.
The stated duration for this service is one week. The engagement includes requirements review, solution selection, Intune configuration, test group policy configuration, limited device testing, employee-wide implementation, and technical support.
This price applies to the defined service scope, so any work outside that scope, such as initial Microsoft Intune setup or license purchasing, should be confirmed separately with IT Partner.
The prerequisites include a Microsoft Enterprise Mobility + Security subscription, Microsoft Entra ID or a hybrid identity environment, and devices added to Microsoft Intune. These prerequisites matter because the service configures password-less authentication through Microsoft Intune and depends on the identity and device management environment being in place.
Yes, all configured devices must be added to Microsoft Intune before they can be included in this service. This is required because IT Partner configures user profiles, devices, and authentication policy in Microsoft Intune.
Not as a complete in-scope implementation, because the prerequisites require Microsoft Entra ID or a hybrid environment. Entra ID configuration is specifically not included if the company uses only on-premises Active Directory, so that requirement should be addressed separately before or alongside the project.
IT Partner first discusses authentication requirements with the client and chooses the appropriate authentication solution. The team then configures Microsoft Intune profiles, devices, and authentication policy, applies policy to a test group, performs limited device testing, and proceeds to employee-wide implementation.
Yes, the implementation plan includes authentication policy configuration for a test group and testing on a limited number of devices. This staged approach helps validate the configuration before employee-wide implementation.
The service is considered successful when Microsoft Intune is configured to allow employees to use two-factor PC authentication without requiring a password. A second success criterion is that employees have successfully applied and are using the new authentication method.
IT Partner handles the authentication requirements discussion, authentication solution selection, Microsoft Intune profile and device configuration, Intune authentication policy configuration, user self-setup instructions, and two weeks of break-fix support. These responsibilities are limited to the service scope and assume the required Microsoft environment is already available.
The client is responsible for informing users about the changes, providing access to Azure management, and providing remote access to workstations if needed. The client is also responsible for the final configuration of each device, which must be completed by the employee-owner of the workstation.
Formal user training is not included in this service. IT Partner does provide self-setup instructions for users, but broader training or change-management activities would need to be handled by the client or scoped separately.
The service content does not specify expected downtime. Because the implementation includes test group configuration, limited device testing, and employee-wide rollout, the business impact should be reviewed with IT Partner based on the number of devices, user readiness, and remote access requirements.
IT Partner includes break-fix support for the password-less authentication solution within two weeks. This support is for issues related to the implemented solution and does not expand the scope to items such as new Intune deployment, license procurement, or formal user training.
The final configuration of each device must be done by the employee-owner of the workstation. IT Partner provides self-setup instructions so users can complete the workstation interaction with the specific authentication device.