DEVICE ENROLLMENT
✓Enroll Windows, iOS, Android, macOS — Autopilot for Windows, ADE for Apple
✓Assign enrollment profiles
✓Set enrollment restrictions by platform
✓Bulk enroll devices via CSV — Requires pre-staging
✓View enrollment status for all devices
✓Retire a device from enrollment
✓Delete a device record
DEVICE ACTIONS
✓Remote lock a device
✓Remote wipe — full factory reset — Irreversible
✓Corporate wipe — remove company data only
✓Force device sync
✓Restart a device remotely — Windows only
✓Locate a device (GPS) — iOS and Android
✓Reset passcode remotely — iOS only
✓Enable or disable Activation Lock
✓Rotate local admin password (LAPS) — Windows and macOS corrected
✓Send custom notification to device
✓Rename a device
COMPLIANCE & POLICIES
✓Assign compliance policies
✓Check compliance status of any device
✓View all non-compliant devices
✓Assign configuration profiles
✓Remove a policy from a device
✓Set conditional access policies — Requires Azure AD P1/P2
APP MANAGEMENT
✓Assign an app to device or user group
✓Remove an app from a device
✓View installed apps
✓Configure app protection policies (MAM)
✓Deploy app updates
⚠ LIMITATIONS
✗Push iOS system updates — Apple does not allow programmatic OS updates
✗Access device screen remotely — Requires TeamViewer or similar
✗Access files on a device — Intune is management only — not file access