How to stop a lost phone or a fired employee from taking your company data with them

· by IDE Solutions

A sales rep leaves her phone in the back of a taxi on the way to the airport. It has her email, her contacts, and an open connection to three years of customer quotes. Or: a developer resigns on a Friday afternoon, and by Monday nobody in the office remembers what was on his laptop, only that it still has client files, saved passwords, and a live login to your file server. Neither of these is a hypothetical. Both happen to companies your size every month, and in a business without a plan for it, the first sign of trouble is realizing nobody can even say what was on that device, let alone lock it down from a distance.

The tool most companies eventually reach for is a piece of Microsoft technology called Intune, part of a broader category Microsoft calls endpoint management. In plain terms: a way to see every laptop and phone that touches your company data, and to enforce a few basic rules on them, require a passcode, encrypt the disk, wipe it remotely, without anyone walking around the office with a screwdriver. If your company already runs Microsoft 365, you may already be paying for part of what Intune needs. Whether you should switch it on is a real decision, not a default, and this guide lays out what it does well, where it falls short, and the parts that never make it into the brochure.

What Microsoft Intune does, in plain terms

Strip away the marketing language and Intune does four things a small company genuinely cares about.

  • It sets minimum rules on every device. No PIN, no company email. Unencrypted disk, no access to SharePoint. The device either meets the bar or it is quietly locked out, no manual checking required.
  • It keeps devices patched without anyone chasing people. Updates and required apps push out on a schedule instead of depending on an employee clicking "install later" for six months straight.
  • It separates company data from personal data on a phone someone owns themselves. A well-configured policy can wipe the company email and files off a personal iPhone without touching a single family photo, which matters enormously once you try to enforce it on real people's phones.
  • It can lock or erase a device remotely. Report a laptop stolen, and admin action removes company access. This is the feature that gets used the day something goes wrong; the rest is prevention.

The catch: what it costs, and who is even allowed to use it

Here is the detail that trips up most small businesses before they get anywhere near a policy screen: Intune is not included in Microsoft 365 Business Standard, the plan most SMBs already run for email and Office apps. It is bundled into Business Premium, which costs a meaningful amount more per user per month, or it can be bought as a standalone add-on. If your company is on Standard today, the first real decision is not a technical one, it is whether the upgrade is worth it, and for how many of your users.

A practical middle ground many of our clients land on: upgrade only the people who handle sensitive data or work off-site, sales, finance, management, and leave a purely on-site production or warehouse team on the cheaper plan with lighter controls. Intune does not need to be all-or-nothing, and pretending it does is how projects stall before they start.

What Intune does not solve, and where people get burned

None of this is a reason to skip it, but going in with the wrong expectations is exactly how a rollout turns into a mess.

  • It is not antivirus. Intune enforces rules and pushes configuration; the actual malware scanning is a separate Microsoft product, Defender, that works alongside it. Turning on Intune alone leaves the threat detection question exactly where it was.
  • A misconfigured policy protects nothing while looking like it does. A rule that is supposed to require encryption but is scoped to the wrong device group gives you a dashboard that says "compliant" and a laptop that is not. This is the single most common finding in the Microsoft 365 security assessments we run: policies that exist on paper and do nothing in practice.
  • Personal devices bring real friction, not just technical setup. Employees are, reasonably, wary of a company tool that can wipe their own phone. You need a clear, written policy on what gets touched and what does not before you roll BYOD enrollment out, or you will spend more time in HR conversations than in the admin console.
  • A remote wipe is not instant if the device is offline. A stolen laptop that never reconnects to the internet never receives the wipe command. Encryption, not the wipe, is what actually protects the data on a device that is never seen again.

Is Microsoft Intune worth it for a small business with 10 to 50 people?

The honest answer depends on how your team actually works, not on your headcount alone.

It is clearly worth the cost and the setup effort if any of the following is true: employees check company email on personal phones, staff work from home, client sites or while travelling, you handle customer data that would be expensive to lose or explain to an auditor, or you have had even one incident already, a lost phone, a departed employee whose access nobody remembered to remove.

It is a lower priority, worth putting on hold rather than rushing, if your whole team works from company-owned desktops in a single locked office, nobody accesses email from a personal phone, and your existing setup already enforces disk encryption through simpler, built-in Windows tools. In that narrower case, the administrative overhead of Intune may cost more in staff time than the risk it removes, at least for now.

Setup itself is not a big project for a company this size. A properly scoped rollout, device groups, compliance policies, app deployment, and a tested wipe on a spare device, typically takes one to three days of focused work, plus a short period of monitoring while real devices enroll and any conflicting old settings get sorted out.

Four scenarios, and what Intune changes in each

  • The lost phone. Without Intune: you hope the lock screen holds and start resetting every password the phone had access to, quietly, for weeks. With it: one click locks or wipes the company data specifically, and you know within minutes what the device could and could not reach.
  • The employee who resigns. Without Intune: the laptop gets collected, maybe, and what was copied off it beforehand is anyone's guess. With it: company access is revoked the moment the account is disabled, regardless of whether the laptop itself is ever returned.
  • The personal phone with company email. Without Intune: company data sits in the same unmanaged phone as everything else the employee owns, with no separation and no policy. With it: a work profile keeps company mail and files inside a container that can be wiped independently of the person's own data.
  • The unmanaged laptop that gets ransomware. Without Intune: nobody notices the device is unpatched and unencrypted until it is already spreading damage into shared drives. With it: the device would have been blocked from company resources the moment it fell out of compliance, before the infection had somewhere useful to go.

What it costs, against what it prevents

The price difference between Business Standard and Business Premium runs to a modest amount per user per month, and for a 20-person company that upgrade, applied only to the staff who need it, typically adds up to a low four-figure sum per year. Add a day or two of setup time and the first year's total cost is easy to put a number on.

Set against that: the average cost of a lost or stolen device incident for a small company, staff time, password resets, client notification, sometimes legal advice, regularly runs into the low thousands of euros even when no data was misused, purely from the hours spent finding out. A departed employee whose access was never revoked and who later causes a data incident is a considerably larger, and considerably more embarrassing, bill. Intune does not prevent every incident. It reliably turns "we have no idea what that device could access" into a documented answer, which is most of what matters the day something goes wrong.

Quick answers

We already use BitLocker and Windows Hello manually. Do we still need Intune? Manual configuration works until someone skips a step or a new laptop ships without it. Intune's value is not the individual setting, it is enforcing it automatically and telling you the moment a device drifts out of compliance.

Does it work on Macs and personal Android or iPhone devices? Yes, Intune supports Windows, macOS, iOS and Android, with lighter, privacy-respecting controls available specifically for personal (BYOD) devices.

Can we start with just phones and add laptops later? Yes, and it is often the sensible order. Phones are usually the higher-risk, higher-loss category, and a phased rollout avoids overwhelming a small team with policy changes all at once.

Is Intune enough on its own for NIS2 or similar compliance duties? It covers device-level controls, which auditors do look for, but compliance frameworks also expect documented policy, access reviews and incident response. Device management is one piece of the picture our IT governance and compliance service covers, not the whole of it.

We scope, roll out and manage Intune so it protects something

We review which of your users genuinely need Business Premium, design compliance policies that match how your team works, and roll them out with a tested remote wipe before a real incident is the first time anyone finds out whether it works.

Then we keep it running: monitoring compliance drift, onboarding new devices, and folding it into the wider Microsoft 365 security picture rather than leaving it as an isolated setting nobody revisits.

More Articles