Intune Application transfer from MaaS360

Anjelica Mayorga 0 Reputation points
2026-05-11T15:50:22.7733333+00:00

Hi,

We will be moving all our phones from MaaS360 to Intune. What will be the best way to do the transfer?

Thank you,

Anjelica

Microsoft Security | Intune | Enrollment
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-11T15:50:33.2866667+00:00

    For moving phones from MaaS360 to Intune, the supported approach is a phased migration rather than a direct “in-place” transfer. Devices must be unenrolled from MaaS360 and then enrolled into Intune, and only one MDM must manage a device at a time.

    Recommended high-level process:

    1. Prepare and set up Intune
      • Set the MDM authority to Intune and complete initial setup.
      • See: Get started and Step 1 guidance in the migration article.
    2. Deploy apps and app protection policies first
      • Configure and deploy the apps that users need in Intune.
      • Create Intune App Protection Policies (APP) so corporate data in apps is protected during and after migration.
      • See: “Step 2 - Add, configure, and protect apps with Intune”.
    3. Plan a phased migration
      • Start with a small pilot group of users/devices.
      • Validate for the pilot:
        • Enrollment success/failure rates.
        • User productivity (VPN, Wi‑Fi, email, certificates, and app access).
        • Data security (compliance reports, mobile app protections applied).
      • Monitor helpdesk load and success metrics before expanding to more groups.
      • Repeat the cycle until all users are migrated.
    4. Unenroll devices from MaaS360
      • Provide users with clear MaaS360 unenrollment instructions (per MaaS360 documentation).
      • When devices are unenrolled, they no longer receive MaaS360 policies and are vulnerable until enrolled in Intune, so minimize the gap between unenrollment and Intune enrollment.
    5. (Optional but recommended) Use Conditional Access
      • If Microsoft Entra ID P1/P2 is available, configure Conditional Access to block access to corporate resources until devices are enrolled in Intune and compliant.
    6. Define baseline compliance and configuration
      • Create compliance policies and device configuration profiles that define minimum security and configuration baselines.
      • Plan to deploy these as devices enroll into Intune.
    7. Enroll devices into Intune
      • Provide platform-specific enrollment instructions to users (Android, iOS/iPadOS, etc.).
      • Use the Intune enrollment deployment guide and Step 5 – Enroll devices in Microsoft Intune.
    8. Avoid dual MDM access control
      • Do not configure MaaS360 and Intune at the same time to enforce access controls (for example, to Exchange or SharePoint). Ensure the cutover for access control is coordinated with the migration phases.
    9. Scale up after successful pilot
      • Once the pilot is stable and helpdesk is ready, expand to more groups.
      • Avoid hard enrollment deadlines until support capacity is confirmed.

    This approach ensures a controlled, secure migration from MaaS360 to Intune with minimal disruption to users.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.