Central device management for your company with Microsoft Intune
Device management, app policies and compliance checks for all endpoints. Centrally controlled, fully automated, operated as a managed service.

Why companies entrust us with their endpoint management.
Ongoing operation instead of a one-off rollout
We don't just configure Intune, we operate it for the long term: with monitoring, policy updates and proactive optimisation.
01
Part of an end-to-end architecture
With us, Intune is not an isolated project but seamlessly interlinked with Entra, Defender and Conditional Access.
02
Right-sized for SMEs
We set up Intune the way it makes sense for 50 to 500 devices: pragmatically, without enterprise overhead.
03
Unser Microsoft Intune Portfolio auf einen Blick.
Windows Autopilot & Zero-Touch-Deployment
New devices self-configure on first power-up. The employee opens the laptop, logs in, and starts working. No manual imaging, no IT preparation.
Configuration Profiles & Compliance Policies
Security policies, device configurations, and compliance checks are centrally defined and automatically applied to all endpoints. Non-compliant devices are detected and isolated. Endpoint Analytics shows the status of your fleet in real-time.
App Management (MAM & MDM)
Enterprise apps are automatically distributed, updated, and removed as needed. Separate policies apply to company-owned and personal devices for maximum flexibility.
Patch Management & Windows Updates
Update rings control when and which devices receive updates. Critical patches are prioritized, and rollouts are delivered in a controlled manner. Remote actions such as restart or reset are possible at any time.
BYOD & Mobile Device Management
Personal smartphones and tablets are securely integrated into the company. Business data remains protected, and personal data remains private.
With the migration to the latest Windows operating system, we want to take an important step towards greater mobility. The ambitious rollout schedule, the many field offices and various logistical details were some of the challenges in this project. The Baggenstos team mastered them successfully.
Baggenstos is a Microsoft Solutions Partner for Modern Work and Security with expertise in endpoint management and Intune. Audited and confirmed by Microsoft every year.

Microsoft Solutions Partner for Modern Work
Certified for Microsoft 365, Teams, and Collaboration. Evidenced by successful client projects, usage metrics, and current team certifications.

Microsoft Solutions Partner for Security
Certified for Identity, Endpoint, and Cloud Security, including the «Cloud Security» specialization. Proven on real-world projects across the Microsoft security stack.

Microsoft Solutions Partner
Highest Microsoft Partner designation, re-certified annually. Baggenstos holds several Solutions Partner Designations.

Why Baggenstos Should Be Your Partner
60,000+
Microsoft 365 users in the Managed Service Program
1'000+
Cloud projects successfully implemented
Since 1925
100 years of continuity in family ownership

Holistic consulting
Endpoint management is more than managing devices. We design policies that balance security, compliance and usability.
Certified Microsoft excellence
As a Solutions Partner for Modern Work, we operate Intune for thousands of devices. Every configuration, every app policy, every compliance check is proven.
Focus on security & compliance
Every device is a potential point of attack. Intune ensures that only compliant devices access your corporate resources, automatically and without manual checks.
Guiding the change (change management)
Introducing Intune changes how IT teams manage devices. We guide the transition and train your team so that Autopilot and compliance policies work day to day.
Frequently Asked Questions, Honest Answers
What does Microsoft Intune cost as a managed service?
The pricing model is based on a monthly amount per device that covers operations, policy management and support. The Intune license is already included in most Microsoft 365 Business and Enterprise plans. In the initial consultation we record your number of devices and requirements and prepare a transparent quote. Many customers realize savings because manual processes and third-party tools are eliminated.
Are the licenses for Microsoft Intune already included in our existing Microsoft 365 packages?
Intune is already included in Microsoft 365 Business Premium as well as in the E3 and E5 plans. With Business Standard or Basic you need an additional license. As a CSP partner, we review your tenant situation and add missing licenses directly through us, without extra cost.
Does Baggenstos also offer ongoing support for our Microsoft Intune environment after a successful rollout?
Yes. In ongoing operations we take over compliance policies, app distribution, patch management and Autopilot provisioning. Your service desk has a dedicated contact, and we continuously develop your Intune environment further, in line with Entra, Defender and Conditional Access.
Besides Windows laptops, is Microsoft Intune also suitable for the professional management of Apple devices such as MacBooks and iPads?
Yes. Intune manages Windows, macOS, iOS and Android from a single console. MacBooks and iPads receive the same compliance checks and app policies as your Windows devices. For SMEs with mixed fleets of 50 to 500 endpoints, this is the major advantage in practice over older MDM solutions.
Can our IT department securely wipe company data remotely via Microsoft Intune in the event of device theft?
Yes. Using remote wipe, you remove all company data from the device. For BYOD, app protection policies apply: only the business apps are reset, while private photos and messages remain untouched. Via Conditional Access you additionally block the device from accessing Microsoft 365.
How does the migration from an older MDM solution or an on-premises server to Microsoft Intune work in practice?
We start with an inventory of your devices, apps and policies. We then build up Intune in parallel, transfer compliance policies and run a pilot rollout. The migration proceeds device group by device group so that operations never come to a standstill. Autopilot handles the reprovisioning of Windows devices.
Can we keep using our existing device management tool?
During the transition phase, yes. We support the parallel use of existing tools such as SCCM or third-party MDM during the migration. The goal is consolidation onto Intune, because it lets you manage devices, apps and policies in a single console. We plan the migration so that no device remains unmanaged and the transition is invisible to your employees.












