JJC SystemsBook a Consultation
Microsoft Intune · Intermediate

Configuring Intune for devices that live in vehicles

Compliance policy, app protection and provisioning designed for crews who work where there is no signal and no patience.

Who this is for

Two summaries, because two audiences read this

If you own the outcome

Field device policy that assumes an office breaks in the field, and crews route around it within a fortnight. This guide covers the configuration that survives real conditions, plus the provisioning change that removes most of the skilled hours from every device replacement.

If you have to build it

Compliance policy grace periods, Autopilot profiles for remote delivery, app protection for unmanaged devices, cellular considerations, and the update ring structure for a workforce that is rarely on the corporate network.

Why it matters

The problem this solves

Field devices fail differently from desk devices. They are used with gloves in sunlight, they spend hours with no connectivity, they are left in vehicles overnight, and they are operated by somebody who wants to be back in the truck.

Policy written for a corporate estate arrives on those devices and quietly stops being followed. The result is not a policy violation you can see — it is a workaround you cannot.

Before you start

Prerequisites

Check these before beginning. Most stalled implementations stall on one of them.

Licensing

Microsoft Intune Plan 1 at minimum, included in Microsoft 365 Business Premium and the E3/E5 tiers.

Roles

Intune Administrator and, for conditional access, a Conditional Access Administrator or Security Administrator.

Hardware

Device models registered for Autopilot with your supplier. This is a purchasing-process change as much as a technical one.

Pilot group

One real crew including your most sceptical technician. A pilot of office staff proves nothing relevant.

How it works

The concepts worth understanding first

Configuration is straightforward once these are clear. Skipping them is why most first attempts produce something that works and cannot be maintained.

Compliance evaluation tolerates delay, if you configure it to

A device that has not checked in is not necessarily non-compliant; it may be in a basement. Grace periods let a device retain compliant status for a defined window after its last successful check-in, which prevents a signal gap from locking a technician out mid-job.

App protection works without managing the device

For personal phones, app protection policies control corporate data inside the application — PIN, encryption, copy restrictions, selective wipe — without enrolling the device. This is the difference between a policy technicians accept and one they resist.

Autopilot removes the depot visit

A device registered with your supplier ships directly to the technician. They sign in and receive a configured machine. For a distributed field workforce this is usually the single largest operational saving available.

Configuration

Step by step

Settings shown are the ones that matter, not every field on the form. Values are starting points to validate against your own environment.

01

Set compliance policy with realistic grace

The default grace period is zero, which means a device that misses a check-in loses access immediately. For field work that is wrong.

Set a grace period long enough to cover a realistic connectivity gap. A day is usually sensible; a week is too generous for a lost device.

Mark device noncompliant
After 1 day for field devices; the default of Immediately is unsuitable
Require BitLocker
Yes — devices left in vehicles need encryption verified, not assumed
Minimum OS version
Set and maintain, but allow a wider window than office devices
Defender for Endpoint risk
Medium or below, if you have the integration
02

Build an Autopilot profile for remote delivery

User-driven mode with Entra join. The critical settings are the ones that reduce the time a technician stares at a screen.

Set the deployment to skip everything skippable and to allow the user to reach the desktop before all applications finish installing, with the essential ones marked as blocking.

Deployment mode
User-driven
Join type
Microsoft Entra joined
Enrollment Status Page
Block until essential apps only — not the full catalogue
Privacy settings
Hide, to shorten the out-of-box experience
Device name template
Include a site or region prefix for asset tracking
03

Apply app protection to personal devices

Technicians who use their own phone for job updates and photographs should not be asked to enrol it. App protection covers the corporate data without touching anything personal.

Keep the PIN requirement proportionate. A complex PIN required every thirty minutes on a device used with gloves will be worked around.

Access requirement
PIN or biometric, with a sensible timeout
Data transfer
Restrict to policy-managed apps
Save copies
Block save to personal cloud storage
Selective wipe
Enabled — the departure scenario is why this exists
04

Structure update rings around the working day

Field crews start early. Updates that install at nine in the morning cost billable time.

Configure active hours generously and set deadlines rather than forced restarts, with a pilot ring covering a small number of devices a week ahead of the main group.

Active hours
05:00–19:00 for field devices
Quality update deferral
2–7 days, with a pilot ring at 0
Deadline
Set, with a grace period, rather than forcing restarts
Delivery optimisation
Enable peer caching for depot locations
05

Pilot with a real crew, including the sceptic

Deploy to one crew and watch for a fortnight. Time a provisioning end to end. Ask the technician who least wanted this what broke.

Fix what they find before extending. The friction they encounter is the friction that would have killed the wider rollout.

Verify it worked

  1. Time a device from sealed box to productive, in the field rather than in the office.
  2. Take a device out of coverage for a working day and confirm it retains access when it returns.
  3. Confirm encryption status is reported for every enrolled device, not merely required by policy.
  4. Trigger a selective wipe on a test personal device and confirm only corporate data is removed.
  5. Check that no updates installed during the crew's working hours over a two-week window.
Best practice

What we do on every engagement of this type

  • Set compliance grace periods that match real connectivity gaps
  • Ship Autopilot-registered devices directly to technicians, never via a depot
  • Use app protection rather than enrolment for personal phones
  • Set active hours around crew hours, not office hours
  • Include your most difficult case in the pilot group
  • Match support hours to crew start times or accept a daily exposure window
Pitfalls

What catches most first attempts

Every one of these is avoidable, and every one of them is common enough that we check for it by default.

!Zero grace period on compliance

The default locks out a technician whose device has been in a basement. This generates a support call at the worst moment and teaches the crew that the system works against them.

!Enrollment Status Page blocking on every app

A new starter watching a progress bar for forty minutes is a bad first day. Mark only the genuinely essential applications as blocking.

!Requiring enrolment of personal devices

Technicians will refuse, or will comply and resent it. App protection achieves the security outcome without the fight.

!Piloting with cooperative office staff

It proves the configuration works under ideal conditions, which is not the question. The pilot has to include poor connectivity, gloves and impatience.

Completion checklist

  • Compliance policy grace periods set to realistic field values
  • Autopilot registration agreed with your hardware supplier as a standing process
  • App protection policy deployed for unmanaged personal devices
  • Update rings configured around actual crew working hours
  • Pilot completed with a real crew and findings addressed
  • Provisioning time measured end to end and recorded as a baseline

Want a second pair of eyes?

Give us one hardware model and your application list and we will build the Autopilot profile, then run the pilot with one of your crews and report what they found.

Request a consultation See our Microsoft Intune page We reply to every message within one business day.
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.