Moving from Configuration Manager (SCCM) to Intune isn’t a cutover — it’s a gradual handover called co-management, where both tools manage the same device at once while you shift control one workload at a time. This guide covers the seven co-management workloads, the order Microsoft recommends switching them in, and how to pilot and validate each move without breaking anything for end users.
Quick Facts
- Co-management lets SCCM and Intune manage the same device simultaneously — you switch workloads individually, not all at once.
- There are seven co-management workloads: compliance policies, device configuration, endpoint protection, resource access, Windows Update policies, Office Click-to-Run apps, and client apps.
- The resource access policies workload (Wi-Fi, VPN, certificates) has been deprecated since ConfigMgr 2203 — don’t plan a migration path around it.
- Microsoft’s recommended sequencing starts with compliance policies and device configuration — low-risk, easy to validate.
- Migrate in waves of 50-100 devices, validating fully before moving to the next batch.
What Is Co-Management, Exactly?
Co-management is a state where a Windows device is enrolled in both Configuration Manager and Intune at the same time. The ConfigMgr client stays installed and keeps doing its job, but for each of the seven supported workloads you decide — independently — whether ConfigMgr or Intune is the “authority” for that workload. Nothing forces you to switch everything at once, and Microsoft explicitly designed it so you can move workloads individually, in groups, or all together, on your own schedule.
This matters because the alternative — a hard cutover from SCCM straight to Intune-only management — is high-risk for any estate with legacy applications, task sequences, or on-prem dependencies. Co-management de-risks the whole thing: if a workload misbehaves once it’s on Intune, you can switch it back to ConfigMgr authority while you investigate, without touching anything else.
The Seven Co-Management Workloads
Each workload can be set to ConfigMgr or Intune authority independently:
- Compliance policies — device health rules that feed Conditional Access.
- Device configuration — general settings management for devices.
- Endpoint Protection — Defender and related security settings.
- Resource access policies — Wi-Fi, VPN, email and certificate profiles. Deprecated since ConfigMgr 2203 — Microsoft no longer supports this workload, so plan resource access delivery through Intune directly rather than migrating it.
- Windows Update policies — update ring and deferral management.
- Office Click-to-Run apps — Microsoft 365 Apps update channel and configuration.
- Client apps — deploying required (not available/optional) applications, including Win32 apps like Chrome’s MSI installer.
Migration Sequencing: What to Move First
Recommended Workload Order
- Switch compliance policies and device configuration to Intune first — they’re well-supported, low-risk and straightforward to validate against a small pilot group.
- Move endpoint protection next, once compliance and configuration are stable and you trust the reporting in the Intune admin center.
- Migrate Windows Update policies and Office Click-to-Run apps — these affect end-user experience directly, so validate patch compliance and update-ring behavior carefully before wider rollout.
- Move client apps last, repackaging anything that needs it as Win32 (.intunewin) apps with accurate detection rules.
- Treat resource access as a separate Intune-native rebuild, not a workload migration — it isn’t supported for switching.
Running a Phased Pilot
Don’t switch a workload for your entire estate in one go. Create a pilot collection in ConfigMgr — 50 to 100 devices is a sensible batch size for most mid-sized environments — and switch the workload for that collection only. Watch for a full patch/update cycle (for Windows Update policies) or a few days of normal use (for compliance and configuration) before expanding to the next wave. If something breaks, you can flip the workload back to ConfigMgr authority for the affected collection without unwinding anything else.
Validating a Migrated Workload
After switching a workload, confirm in the Microsoft Intune admin center that each pilot device is enrolled, has checked in recently, and is associated with the expected user. The “Managed by” field and compliance status shown there should match the workload you just moved — if a device still shows ConfigMgr as the source of truth for a workload you switched, the client policy hasn’t refreshed yet and needs a machine policy retrieval cycle before you troubleshoot further.
Frequently Asked Questions
Do I have to migrate all seven workloads eventually?
No. Co-management is a legitimate permanent end state for many organizations, not just a migration step. Microsoft explicitly supports running a hybrid setup indefinitely for regulated or complex environments — you only need to switch the workloads that make sense for your organization.
What happened to the resource access policies workload?
It was deprecated starting in ConfigMgr version 2203 and is no longer supported. If you need Wi-Fi, VPN, email or certificate profiles delivered to co-managed devices, configure those directly in Intune rather than trying to migrate the ConfigMgr workload.
Can I switch a workload back to ConfigMgr if something goes wrong?
Yes. Workload authority can be switched back to ConfigMgr for a pilot collection (or the whole estate) at any time, which is exactly why phased pilots of 50-100 devices per wave are recommended over a big-bang switch.
How does this relate to Configuration Manager’s move to an annual release cadence?
Starting with version 2609 (expected September 2026), ConfigMgr moves to an annual release cadence, reinforcing Microsoft’s direction that Intune is the primary investment going forward. That doesn’t force an immediate migration, but it’s a signal to have a workload migration plan rather than assuming ConfigMgr feature updates will keep arriving as frequently as before.
This article is part of the TechyGeeksHome Intune series — see the Microsoft Intune: The Complete Guide for licensing, Autopilot, and compliance policy coverage.
Discover more from TechyGeeksHome
Subscribe to get the latest posts sent to your email.