Can I use Intune without Entra ID P1?
Yes for basic Intune device management, no for the enforcement mechanism most deployments actually rely on. Intune enrollment and configuration profiles work with the free Entra ID tier that ships with any Microsoft 365 subscription, but Conditional Access — which is how Intune compliance signals gate access to Microsoft 365 — needs Entra ID P1.
Where the free tier is enough
- Enrolling Windows, macOS, iOS, and Android devices.
- Deploying configuration profiles, apps, and updates.
- Reporting on compliance state.
Where P1 becomes the point
- Conditional Access blocks unmanaged devices from Microsoft 365 sign-in.
- App Protection Policies for BYOD scenarios rely on CA to require MAM-managed apps.
- Dynamic groups by device attribute (ownership, model, OS) simplify Intune assignment.
In practice, Intune is almost always deployed alongside Entra ID P1 — via Microsoft 365 E3, Business Premium, or the standalone Intune Plan 1 SKU that bundles the two.
Read next
- Microsoft Intune and device management— Microsoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365.
- Intune compliance policies and Conditional Access— Combining Intune compliance with Conditional Access gives you device-aware access control — the heart of zero trust.
- Business Premium vs Microsoft 365 E3— Business Premium vs Microsoft 365 E3: Premium wins on security for less money, E3 wins on mailboxes, Windows, and scale. How to choose, and how to mix them.