Without Microsoft Intune, you cannot centrally enforce detailed device configuration or security baselines in Entra ID alone — Entra ID is an identity management service, not a device management platform. However, there are a few cost-effective alternatives and hybrid approaches depending on your requirements.
Option A — Use Microsoft Intune Plan 1 Add-on
If full E3/E5 licensing is too expensive, consider Intune Plan 1 ($4 per user/month).
Gives all the policy and compliance management you need, at a fraction of the full M365 E3 cost.
Option B — Use Group Policy via Hybrid Join
Set up a lightweight on-prem Active Directory for Group Policy (GPO) management.
Devices become Hybrid Entra ID Joined, so you can:
Manage them via GPO locally, and
Still use Entra ID for SSO, Conditional Access, and MFA.
Pros: No Intune cost.
Cons: Requires AD servers, VPN or LAN connectivity, and ongoing maintenance.
Option C — Use Local scripts or 3rd-party MDM
Tools like ManageEngine Endpoint Central, JumpCloud, or Microsoft Configuration Manager (SCCM) (if already licensed) can handle policy enforcement.
- You can also use PowerShell or DSC scripts deployed manually or via scheduled tasks, but that’s not scalable for 1000 devices Option A — Use Microsoft Intune Plan 1 Add-on
- If full E3/E5 licensing is too expensive, consider Intune Plan 1 ($4 per user/month).
- Gives all the policy and compliance management you need, at a fraction of the full M365 E3 cost.
- Set up a lightweight on-prem Active Directory for Group Policy (GPO) management.
- Devices become Hybrid Entra ID Joined, so you can:
- Manage them via GPO locally, and
- Still use Entra ID for SSO, Conditional Access, and MFA.
- Pros: No Intune cost.
- Cons: Requires AD servers, VPN or LAN connectivity, and ongoing maintenance.
- Tools like ManageEngine Endpoint Central, JumpCloud, or Microsoft Configuration Manager (SCCM) (if already licensed) can handle policy enforcement.
- You can also use PowerShell or DSC scripts deployed manually or via scheduled tasks, but that’s not scalable for 1000 devices