Microsoft gives each tenant a single trial of each capability. Plan it like something you cannot get back.
Eight advanced capabilities sit above base Intune: least-privilege elevation, audited remote support, a managed certificate authority, a curated Win32 catalog, endpoint experience analytics, and three more. The published trial terms are strict: 90 days, up to 250 users, exactly one trial of each capability per tenant, and a 30-day grace period once it ends. Much of the value we add is turning that one attempt into a defensible yes-or-no decision.

- EightAdd-on capabilities above base Intune
- 90 daysPublished trial length
- 250 usersCeiling on any one trial
- One trialEach capability, ever, per tenant
The published trial terms, and why they demand planning.
These four terms come straight from Microsoft's documentation. Read together, they turn a trial from a casual experiment into a one-shot evaluation that deserves design.
- 90 days and a 250-user ceiling per tenant. Larger organizations cannot trial broadly, so the population has to be chosen to represent the estate, and that selection is itself design work.
- A single trial of each capability per tenant, which is the term with teeth. Once a trial is consumed, whether it produced a decision or not, that capability cannot be trialed again in the tenant.
- A 30-day grace period follows day 90; when it lapses, Microsoft states the capability disappears from the admin center. Whatever was configured inside the trial needs a keep-or-drop call before that date.
- Only a Global or Billing administrator can start a trial, and Microsoft notes the add-ons tab is hidden entirely from other roles, while the capabilities tab still lists eligibility. Confirm who holds those roles before scheduling anything.
The capability list, and the problem each one exists to solve.
Endpoint Privilege Management
Microsoft's mechanism for standard-user computing that still permits approved elevations. Users run without local admin rights; the specific tasks that genuinely need elevation get individually approved paths, and each elevation is recorded with the file, the requester, and the stated justification. Insurance carriers, SOC 2 auditors, and NIST 800-171 and CMMC assessors all probe least privilege, so this is usually the add-on with the fastest compliance return.
Remote Help
Help desk sessions to user devices, delivered from the cloud and gated by role-based access controls. Where a generic remote-control product gives whoever connects free rein, here the connecting technician operates inside a defined role and the session trail is attributable. HIPAA security officials and examiners working under GLBA and the FTC Safeguards Rule ask who touched a machine and on what authority; this produces that answer as an export.
Cloud PKI
A certificate authority run as a managed service, handling issuance, renewal, and revocation across the platforms Intune manages. Many organizations keep an aging on-premises CA alive for exactly one job, device and Wi-Fi certificates, with its care sitting on whoever inherited it. Retiring that server, its connectors, and its expiry surprises is the business case.
Enterprise App Management
A Microsoft-hosted catalog of prepared Win32 applications, added with install settings already filled in. Packaging Win32 apps is among the heaviest recurring chores in Intune administration, so a library of ready-made packages changes the weekly workload materially. It is deep enough that we maintain a dedicated page for it.
Advanced Endpoint Analytics
Telemetry-driven insight into how endpoints actually perform for the people using them. When leadership asks why machines feel slow, this replaces anecdote with measurements, and it doubles as the evidence base when a hardware refresh has to be argued for.
Microsoft Tunnel for mobile application management
Extends the Microsoft Tunnel VPN to Android and iOS devices that are not enrolled in Intune. That covers contractors and personal phones, populations that will never accept enrollment, where the previous choice was enrollment or exclusion. The gateway itself carries hard design constraints, documented on our Microsoft Tunnel page.
Specialty device management
Covers AR and VR headsets, large smart-screen devices, and conference room meeting devices. A narrower capability than its siblings, but the hardware it covers consists of corporate assets that typically sit outside every management tool, noticed only when a meeting room fails at the wrong moment.
Android firmware over the air
Delivers firmware updates to Android devices over the air with no user action required. On shared and rugged fleets, scanners, kiosks, field tablets, there is no individual owner to tap accept, so updates that need consent simply never install. Removing the human step is what keeps those fleets patched.
How we keep an add-on evaluation honest.
Entitlement first, recommendations second
Before proposing anything, we map what your subscriptions already grant, since Microsoft itself advises reviewing licensing to see what is included and to avoid overlap, and warns that entitlement can differ across one organization. It is common to find a capability already owned through a bundle, sitting beside a paid third-party tool doing the same work. As a Microsoft CSP and Solutions Partner, reading entitlement is routine work for us.
A trial is designed, then started
The published limits, 90 days, 250 users, one attempt per capability, leave no room for wandering evaluations. Population, pass criteria, and an accountable owner are settled in writing before anyone clicks start, so day 90 arrives with a verdict instead of a shrug.
Privilege management usually goes first
No other endpoint change removes as much risk as taking local admin away, and no control comes up more often on insurance questionnaires and NIST 800-171 or CMMC assessments. The historical blocker, the few tasks that truly need elevation, is precisely what Endpoint Privilege Management was built to handle, and its trial reliably reaches a clear verdict within the window.
Replacement beats addition in every business case
Cloud PKI can decommission a certificate authority. Enterprise App Management absorbs packaging labor. Remote Help can displace a paid remote-access subscription. When an add-on retires an existing cost, the case argues itself, and in most environments we assess, that is the honest framing.
Six patterns we keep meeting, and the capability that fits each.
Admin rights everywhere, and a renewal questionnaire due
The same standoff repeats each year: certain tasks need elevation, nobody will own breaking them, so local admin stays universal. Then the insurance renewal or a CMMC gap analysis asks about least privilege. Endpoint Privilege Management dissolves the standoff by giving those specific tasks approved elevation paths while everyone runs standard.
A server room CA with one remaining purpose
Somewhere there is a certificate authority whose entire modern role is Wi-Fi and device certificates, plus an annual outage when something expires unnoticed. A managed CA covering issuance, renewal, and revocation across Intune platforms lets that machine finally be switched off.
Packaging eating the IT calendar
Applications update continuously, so Win32 packaging never reaches done. With install settings prefilled by the catalog, the work collapses from engineering into selection, and a lean team gets meaningful hours back every week.
An examiner asking who accessed that endpoint
Regulated firms get asked for the access record: which technician, which device, when, under what role. A generic remote tool rarely has one worth showing. Remote Help generates a role-scoped, attributable record simply by being used.
Rugged Android that nobody updates
Distribution centers, clinics, and field crews run shared Android hardware with no owner to approve updates, so firmware ages in place. Over-the-air delivery with no user action is the only pattern that has ever kept such fleets current.
The unmanaged corporate screen problem
Meeting room panels, signage, and training headsets are company property that no tool watches, remembered when one dies mid-presentation. Specialty device management pulls AR and VR headsets, large smart screens, and meeting room devices into the same estate as the laptops.
How organizations are handling the advanced capabilities.
| Feature | Evaluated deliberately | Trialed casually | Never looked |
|---|---|---|---|
Entitlement mapped before any purchase | Yes | Partly | No |
Trial population chosen to represent the estate | Yes | No | Not applicable |
Day-90 success test written before launch | Yes | No | Not applicable |
The important capability still has its trial available | Yes | Possibly not | Yes |
Duplicate third-party spend surfaced | Yes | No | No |
Local admin rights gone from daily accounts | Yes | No | No |
On-premises CA retirement evaluated | Considered | No | No |
Win32 packaging load reduced | Yes | No | No |
Keep-or-drop decided inside the grace window | Yes | Sometimes | Not applicable |
Least-privilege insurance question answerable in writing | Yes | Partly | No |
The eight capabilities, ranked by the problem each one solves.
Capability
Endpoint Privilege Management
- The problem it solves
- Standing local admin rights, and the insurance and assessment questions they trigger
Capability
Cloud PKI
- The problem it solves
- An aging on-premises CA whose only remaining job is device certificates
Capability
Enterprise App Management
- The problem it solves
- Win32 packaging as a permanent tax on the IT week
Capability
Remote Help
- The problem it solves
- Remote support sessions with no role limits and no audit trail
Capability
Advanced Endpoint Analytics
- The problem it solves
- Slow devices with no data to explain or fix them
Capability
Microsoft Tunnel for MAM
- The problem it solves
- Internal access for phones that will never be enrolled
Capability
Specialty device management
- The problem it solves
- Meeting room and headset hardware outside every management tool
Capability
Android firmware over the air
- The problem it solves
- Shared Android fleets running old firmware indefinitely
The sequence, with two steps in front of any trial.
- 1
Map current entitlement
Plan 1 versus Plan 2, which bundles the tenant holds, and whether different user populations carry different licensing, a variation Microsoft explicitly flags. This step alone often redraws the shopping list, because something on it turns out to be owned already.
- 2
Inventory overlapping third-party spend
Remote access tools, elevation agents, PKI infrastructure, packaging subscriptions. Where a capability would replace an existing invoice rather than join it, the case strengthens, and Microsoft's own guidance says to avoid duplicated functionality.
- 3
Design the evaluation
Capability chosen, 250-user sample selected, pass criteria written, owner named. This is what stands between the tenant's only trial and an inconclusive experiment nobody was answerable for.
- 4
Run to a decision date
The calendar is set against the 90-day term and the 30-day grace period behind it, so the verdict lands while the capability is still live, not after it has vanished from the admin center taking its configuration with it.
- 5
Adopt, or document the no
A yes rolls out on the configuration the trial proved. A no gets written down with reasons, so the same question is not relitigated in two quarters by someone who missed the evaluation. Both outcomes are wins; only one usually leaves a record.
The questions that come up before buying.
Fifteen things to settle before anything gets clicked.
Entitlement
- Intune Plan 1 or Plan 2?Plan 2 and the Suite carry the advanced capabilities.
- Which Microsoft 365 bundles are in place?Some bundles already include capabilities.
- Is entitlement uniform across the company?Microsoft warns it often is not.
- What third-party tools overlap?Microsoft's advice is to avoid duplicate functionality.
- Who is a Global or Billing administrator?Only those roles can see and start trials.
Fit
- Do users hold local admin rights today?The Endpoint Privilege Management question.
- Is an on-premises CA still running?Cloud PKI may retire it.
- What does Win32 packaging cost you weekly?Enterprise App Management removes most of it.
- Can support sessions be audited by role?Remote Help is built that way.
- Is there data behind device performance complaints?Endpoint Analytics supplies it.
Designing the one trial
- Which 250 users mirror the estate?The cap forces a representative sample.
- What is the day-90 success test?Write it down before starting.
- Who is accountable for the verdict?Trials without owners expire unused, permanently.
- What happens to trial-built configuration?It needs a decision inside the grace window.
- One capability at a time, or several?Concurrent trials muddy attribution.
The pages around this one.
Microsoft Intune
Enrollment, policy, compliance, and app deployment: the platform layer underneath every add-on here.
Enterprise App Management
The Win32 catalog capability in full, including the auto-update limitations Microsoft publishes.
Microsoft Tunnel
The mobile VPN gateway in depth: network constraints, the Sites model, and the MAM licensing split.
Before any trial: learn what your tenant already includes.
Microsoft's own guidance says to check entitlement first, and notes it can differ across one organization. Since every capability carries exactly one trial per tenant, that check is the cheapest insurance available against wasting an attempt on something you already own.
Related Services
Explore more solutions that work great with this service