We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Intune Suite
Microsoft Intune Suite and advanced capabilities

Microsoft gives each tenant a single trial of each capability. Plan it like something you cannot get back.

Eight advanced capabilities sit above base Intune: least-privilege elevation, audited remote support, a managed certificate authority, a curated Win32 catalog, endpoint experience analytics, and three more. The published trial terms are strict: 90 days, up to 250 users, exactly one trial of each capability per tenant, and a 30-day grace period once it ends. Much of the value we add is turning that one attempt into a defensible yes-or-no decision.

Plan a capability evaluationJump to the capability list
Microsoft Intune Suite advanced capabilities for US organizations
  • EightAdd-on capabilities above base Intune
  • 90 daysPublished trial length
  • 250 usersCeiling on any one trial
  • One trialEach capability, ever, per tenant
Read the trial terms before anyone clicks

The published trial terms, and why they demand planning.

These four terms come straight from Microsoft's documentation. Read together, they turn a trial from a casual experiment into a one-shot evaluation that deserves design.

  • 90 days and a 250-user ceiling per tenant. Larger organizations cannot trial broadly, so the population has to be chosen to represent the estate, and that selection is itself design work.
  • A single trial of each capability per tenant, which is the term with teeth. Once a trial is consumed, whether it produced a decision or not, that capability cannot be trialed again in the tenant.
  • A 30-day grace period follows day 90; when it lapses, Microsoft states the capability disappears from the admin center. Whatever was configured inside the trial needs a keep-or-drop call before that date.
  • Only a Global or Billing administrator can start a trial, and Microsoft notes the add-ons tab is hidden entirely from other roles, while the capabilities tab still lists eligibility. Confirm who holds those roles before scheduling anything.
Have us design the trial before it starts
The eight capabilities

The capability list, and the problem each one exists to solve.

Microsoft makes these available through Intune Plan 2, the Intune Suite, and select Microsoft 365 bundles, and its published advice is to check your licensing first so you do not buy functionality twice. Entitlement varies between organizations, and sometimes inside one.

Endpoint Privilege Management

Microsoft's mechanism for standard-user computing that still permits approved elevations. Users run without local admin rights; the specific tasks that genuinely need elevation get individually approved paths, and each elevation is recorded with the file, the requester, and the stated justification. Insurance carriers, SOC 2 auditors, and NIST 800-171 and CMMC assessors all probe least privilege, so this is usually the add-on with the fastest compliance return.

Remote Help

Help desk sessions to user devices, delivered from the cloud and gated by role-based access controls. Where a generic remote-control product gives whoever connects free rein, here the connecting technician operates inside a defined role and the session trail is attributable. HIPAA security officials and examiners working under GLBA and the FTC Safeguards Rule ask who touched a machine and on what authority; this produces that answer as an export.

Cloud PKI

A certificate authority run as a managed service, handling issuance, renewal, and revocation across the platforms Intune manages. Many organizations keep an aging on-premises CA alive for exactly one job, device and Wi-Fi certificates, with its care sitting on whoever inherited it. Retiring that server, its connectors, and its expiry surprises is the business case.

Enterprise App Management

A Microsoft-hosted catalog of prepared Win32 applications, added with install settings already filled in. Packaging Win32 apps is among the heaviest recurring chores in Intune administration, so a library of ready-made packages changes the weekly workload materially. It is deep enough that we maintain a dedicated page for it.

Advanced Endpoint Analytics

Telemetry-driven insight into how endpoints actually perform for the people using them. When leadership asks why machines feel slow, this replaces anecdote with measurements, and it doubles as the evidence base when a hardware refresh has to be argued for.

Microsoft Tunnel for mobile application management

Extends the Microsoft Tunnel VPN to Android and iOS devices that are not enrolled in Intune. That covers contractors and personal phones, populations that will never accept enrollment, where the previous choice was enrollment or exclusion. The gateway itself carries hard design constraints, documented on our Microsoft Tunnel page.

Specialty device management

Covers AR and VR headsets, large smart-screen devices, and conference room meeting devices. A narrower capability than its siblings, but the hardware it covers consists of corporate assets that typically sit outside every management tool, noticed only when a meeting room fails at the wrong moment.

Android firmware over the air

Delivers firmware updates to Android devices over the air with no user action required. On shared and rugged fleets, scanners, kiosks, field tablets, there is no individual owner to tap accept, so updates that need consent simply never install. Removing the human step is what keeps those fleets patched.

How we approach it

How we keep an add-on evaluation honest.

These capabilities layer onto a platform you already pay for. Whether they are good is not in dispute; whether they address a problem you actually have, and displace spend you already carry, is the real question.

Entitlement first, recommendations second

Before proposing anything, we map what your subscriptions already grant, since Microsoft itself advises reviewing licensing to see what is included and to avoid overlap, and warns that entitlement can differ across one organization. It is common to find a capability already owned through a bundle, sitting beside a paid third-party tool doing the same work. As a Microsoft CSP and Solutions Partner, reading entitlement is routine work for us.

A trial is designed, then started

The published limits, 90 days, 250 users, one attempt per capability, leave no room for wandering evaluations. Population, pass criteria, and an accountable owner are settled in writing before anyone clicks start, so day 90 arrives with a verdict instead of a shrug.

Privilege management usually goes first

No other endpoint change removes as much risk as taking local admin away, and no control comes up more often on insurance questionnaires and NIST 800-171 or CMMC assessments. The historical blocker, the few tasks that truly need elevation, is precisely what Endpoint Privilege Management was built to handle, and its trial reliably reaches a clear verdict within the window.

Replacement beats addition in every business case

Cloud PKI can decommission a certificate authority. Enterprise App Management absorbs packaging labor. Remote Help can displace a paid remote-access subscription. When an add-on retires an existing cost, the case argues itself, and in most environments we assess, that is the honest framing.

Where this matters most

Six patterns we keep meeting, and the capability that fits each.

Every one of these is a gap an organization has worked around for years, because base Intune never had the fix.

Admin rights everywhere, and a renewal questionnaire due

The same standoff repeats each year: certain tasks need elevation, nobody will own breaking them, so local admin stays universal. Then the insurance renewal or a CMMC gap analysis asks about least privilege. Endpoint Privilege Management dissolves the standoff by giving those specific tasks approved elevation paths while everyone runs standard.

A server room CA with one remaining purpose

Somewhere there is a certificate authority whose entire modern role is Wi-Fi and device certificates, plus an annual outage when something expires unnoticed. A managed CA covering issuance, renewal, and revocation across Intune platforms lets that machine finally be switched off.

Packaging eating the IT calendar

Applications update continuously, so Win32 packaging never reaches done. With install settings prefilled by the catalog, the work collapses from engineering into selection, and a lean team gets meaningful hours back every week.

An examiner asking who accessed that endpoint

Regulated firms get asked for the access record: which technician, which device, when, under what role. A generic remote tool rarely has one worth showing. Remote Help generates a role-scoped, attributable record simply by being used.

Rugged Android that nobody updates

Distribution centers, clinics, and field crews run shared Android hardware with no owner to approve updates, so firmware ages in place. Over-the-air delivery with no user action is the only pattern that has ever kept such fleets current.

The unmanaged corporate screen problem

Meeting room panels, signage, and training headsets are company property that no tool watches, remembered when one dies mid-presentation. Specialty device management pulls AR and VR headsets, large smart screens, and meeting room devices into the same estate as the laptops.

Three positions

How organizations are handling the advanced capabilities.

Plenty of tenants sit in the right column while paying outside vendors for remote support, privilege management, or certificates. Nobody has put the entitlement list next to the invoice list, which is the quiet cost.
Entitlement mapped before any purchase
Evaluated deliberatelyYes
Trialed casuallyPartly
Never lookedNo
Trial population chosen to represent the estate
Evaluated deliberatelyYes
Trialed casuallyNo
Never lookedNot applicable
Day-90 success test written before launch
Evaluated deliberatelyYes
Trialed casuallyNo
Never lookedNot applicable
The important capability still has its trial available
Evaluated deliberatelyYes
Trialed casuallyPossibly not
Never lookedYes
Duplicate third-party spend surfaced
Evaluated deliberatelyYes
Trialed casuallyNo
Never lookedNo
Local admin rights gone from daily accounts
Evaluated deliberatelyYes
Trialed casuallyNo
Never lookedNo
On-premises CA retirement evaluated
Evaluated deliberatelyConsidered
Trialed casuallyNo
Never lookedNo
Win32 packaging load reduced
Evaluated deliberatelyYes
Trialed casuallyNo
Never lookedNo
Keep-or-drop decided inside the grace window
Evaluated deliberatelyYes
Trialed casuallySometimes
Never lookedNot applicable
Least-privilege insurance question answerable in writing
Evaluated deliberatelyYes
Trialed casuallyPartly
Never lookedNo
Feature
Evaluated deliberately
Trialed casually
Never looked
Entitlement mapped before any purchase
YesPartlyNo
Trial population chosen to represent the estate
YesNoNot applicable
Day-90 success test written before launch
YesNoNot applicable
The important capability still has its trial available
YesPossibly notYes
Duplicate third-party spend surfaced
YesNoNo
Local admin rights gone from daily accounts
YesNoNo
On-premises CA retirement evaluated
ConsideredNoNo
Win32 packaging load reduced
YesNoNo
Keep-or-drop decided inside the grace window
YesSometimesNot applicable
Least-privilege insurance question answerable in writing
YesPartlyNo
Which one first

The eight capabilities, ranked by the problem each one solves.

This ranking is ours rather than Microsoft's, based on which problems actually generate risk and spend in the environments we review, and which trials tend to reach a verdict inside 90 days.

Capability

Endpoint Privilege Management

The problem it solves
Standing local admin rights, and the insurance and assessment questions they trigger

Capability

Cloud PKI

The problem it solves
An aging on-premises CA whose only remaining job is device certificates

Capability

Enterprise App Management

The problem it solves
Win32 packaging as a permanent tax on the IT week

Capability

Remote Help

The problem it solves
Remote support sessions with no role limits and no audit trail

Capability

Advanced Endpoint Analytics

The problem it solves
Slow devices with no data to explain or fix them

Capability

Microsoft Tunnel for MAM

The problem it solves
Internal access for phones that will never be enrolled

Capability

Specialty device management

The problem it solves
Meeting room and headset hardware outside every management tool

Capability

Android firmware over the air

The problem it solves
Shared Android fleets running old firmware indefinitely
CapabilityThe problem it solves
Endpoint Privilege ManagementStanding local admin rights, and the insurance and assessment questions they trigger
Cloud PKIAn aging on-premises CA whose only remaining job is device certificates
Enterprise App ManagementWin32 packaging as a permanent tax on the IT week
Remote HelpRemote support sessions with no role limits and no audit trail
Advanced Endpoint AnalyticsSlow devices with no data to explain or fix them
Microsoft Tunnel for MAMInternal access for phones that will never be enrolled
Specialty device managementMeeting room and headset hardware outside every management tool
Android firmware over the airShared Android fleets running old firmware indefinitely
How an evaluation runs

The sequence, with two steps in front of any trial.

Typically 4-8 weeks including a scoped trial, all delivered remotely. Order matters here because the thing being protected, the single trial, cannot be bought back once spent.
  1. 1

    Map current entitlement

    Plan 1 versus Plan 2, which bundles the tenant holds, and whether different user populations carry different licensing, a variation Microsoft explicitly flags. This step alone often redraws the shopping list, because something on it turns out to be owned already.

  2. 2

    Inventory overlapping third-party spend

    Remote access tools, elevation agents, PKI infrastructure, packaging subscriptions. Where a capability would replace an existing invoice rather than join it, the case strengthens, and Microsoft's own guidance says to avoid duplicated functionality.

  3. 3

    Design the evaluation

    Capability chosen, 250-user sample selected, pass criteria written, owner named. This is what stands between the tenant's only trial and an inconclusive experiment nobody was answerable for.

  4. 4

    Run to a decision date

    The calendar is set against the 90-day term and the 30-day grace period behind it, so the verdict lands while the capability is still live, not after it has vanished from the admin center taking its configuration with it.

  5. 5

    Adopt, or document the no

    A yes rolls out on the configuration the trial proved. A no gets written down with reasons, so the same question is not relitigated in two quarters by someone who missed the evaluation. Both outcomes are wins; only one usually leaves a record.

Straight answers

The questions that come up before buying.

Eight capabilities, per Microsoft's list: Endpoint Privilege Management, Remote Help, Cloud PKI, Enterprise App Management, Advanced Endpoint Analytics, Microsoft Tunnel for mobile application management, specialty device management covering AR and VR headsets, smart screens and meeting room hardware, and over-the-air Android firmware updates that install without user action.

Structurally there are several doors to the same capabilities: Microsoft Intune Plan 2, the Intune Suite as a bundle, individual standalone add-ons on a qualifying Intune plan, and select Microsoft 365 bundles that include capabilities outright. The right door depends on how many of the eight you would genuinely use and what your existing agreements already contain. We scope our own work per engagement; Microsoft's license charges come from Microsoft under your agreement.

Yes, under specific published terms: a 90-day duration, at most 250 users per tenant, exactly one trial of each capability per tenant, and a 30-day grace period at the end, after which Microsoft states the capability is no longer available in the admin center. Of those terms, the single-trial limit deserves the most respect.

After the grace period the capability drops out of the admin center, and the tenant's one trial of it is spent, so there is no starting over. Configuration built during the trial needs its decision before that point. This is the entire argument for planning trials instead of wandering into them.

Usually Endpoint Privilege Management. Stripping local admin rights is the biggest single reduction in endpoint risk available, least privilege is the recurring question on insurance forms and in NIST 800-171 and CMMC practice sets, and the classic obstacle, tasks that legitimately need elevation, is the exact scenario the capability addresses. It also tends to produce an unambiguous verdict inside 90 days.

Possibly your whole on-premises certificate authority, if its surviving purpose is device and network certificates. Microsoft's description is a managed certificate authority handling issuance, renewal, and revocation across Intune platforms. Whether full retirement is realistic depends on what else the current CA issues, so that inventory is where we start.

Two properties: role-based access controls, and residence inside the same management stack as the devices. The typical incumbent is a general remote-control product with broad access and thin logging, which holds up poorly the first time an auditor, an examiner, or an incident review wants to know who connected to a machine and with what authority.

No, and that is its reason to exist: Microsoft describes it as extending the Tunnel VPN to Android and iOS devices not enrolled in Intune, the contractor and BYOD population. Note that the underlying gateway carries strict documented constraints, including a hard incompatibility with TLS break and inspect, covered in depth on our Microsoft Tunnel page.

Several capabilities line up directly with what those processes probe. Endpoint Privilege Management speaks to the least-privilege items on nearly every insurance form and in NIST 800-171 and CMMC. Remote Help speaks to access-control expectations under HIPAA and the FTC Safeguards Rule. The division of labor: your compliance advisors interpret the requirements, we implement and evidence the controls. We are an IT services firm, not auditors or attorneys.

It happens often, and Microsoft warns about it directly, telling customers to review licensing to see what is included and avoid overlapping functionality. A bundle purchased for one reason quietly grants a capability, while a separate vendor invoice keeps arriving for the equivalent tool.

Global or Billing administrators only. Per Microsoft, other roles cannot see the add-ons tab at all, although the capabilities tab still displays what the tenant is eligible for. Confirm role holders first, or someone will spend an afternoon searching for a page their account cannot render.

Scoped per engagement, sized by how many capabilities are in play and whether we run the evaluation, the deployment, or both. Microsoft bills its own licensing separately. The free part is the first conversation, where we establish which of the eight your tenant already holds, an answer that frequently reshapes the request.
Before you buy or trial

Fifteen things to settle before anything gets clicked.

Entitlement first, exactly as Microsoft advises. Then fit, meaning which capability would actually change something. Then the design of the trial itself, since each capability gets one attempt per tenant.

Entitlement

  • Intune Plan 1 or Plan 2?
    Plan 2 and the Suite carry the advanced capabilities.
  • Which Microsoft 365 bundles are in place?
    Some bundles already include capabilities.
  • Is entitlement uniform across the company?
    Microsoft warns it often is not.
  • What third-party tools overlap?
    Microsoft's advice is to avoid duplicate functionality.
  • Who is a Global or Billing administrator?
    Only those roles can see and start trials.

Fit

  • Do users hold local admin rights today?
    The Endpoint Privilege Management question.
  • Is an on-premises CA still running?
    Cloud PKI may retire it.
  • What does Win32 packaging cost you weekly?
    Enterprise App Management removes most of it.
  • Can support sessions be audited by role?
    Remote Help is built that way.
  • Is there data behind device performance complaints?
    Endpoint Analytics supplies it.

Designing the one trial

  • Which 250 users mirror the estate?
    The cap forces a representative sample.
  • What is the day-90 success test?
    Write it down before starting.
  • Who is accountable for the verdict?
    Trials without owners expire unused, permanently.
  • What happens to trial-built configuration?
    It needs a decision inside the grace window.
  • One capability at a time, or several?
    Concurrent trials muddy attribution.
Related reading

The pages around this one.

Microsoft Intune

Enrollment, policy, compliance, and app deployment: the platform layer underneath every add-on here.

Learn more

Enterprise App Management

The Win32 catalog capability in full, including the auto-update limitations Microsoft publishes.

Learn more

Microsoft Tunnel

The mobile VPN gateway in depth: network constraints, the Sites model, and the MAM licensing split.

Learn more
Next step

Before any trial: learn what your tenant already includes.

Microsoft's own guidance says to check entitlement first, and notes it can differ across one organization. Since every capability carries exactly one trial per tenant, that check is the cheapest insurance available against wasting an attempt on something you already own.

Plan a capability evaluationSee Microsoft Intune services

Related Services

Explore more solutions that work great with this service

Microsoft Intune

Device management and endpoint security

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA