Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Short answer: Microsoft 365 Basic Mobility and Security (often called “Office 365 MDM”) can be moved to Intune. You cannot select modern Configuration Manager (formerly SCCM) as the tenant’s MDM authority. For Configuration Manager-managed Windows devices, use co-management and move workloads gradually.
Understand the terminology
“Office 365 MDM” is now generally documented as Basic Mobility and Security for Microsoft 365. It is a limited device-management service, separate from Microsoft Intune. Configuration Manager is Microsoft’s current name for SCCM.
MDM authority identifies the service responsible for enrollment and mobile-device-management policy. It is different from workload authority: in co-management, Configuration Manager can remain in charge of workloads that have not moved, while Intune controls selected workloads.
Microsoft documents Intune standalone, Intune with Configuration Manager co-management, Basic Mobility and Security, and Basic Mobility and Security/Intune coexistence as supported arrangements. See Microsoft’s MDM-authority documentation.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Brilliant LCD Display – The 13" PixelSense touchscreen[1], with LCD and enriched HDR[2] tech, unveils crisper whites, darker blacks, and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
- Up to 15.5hours of battery life[3] - The new Surface Pro is designed for long days, late nights and everything in between.
- Productivity. All Day. Every Day. – Built with the latest Qualcomm Snapdragon X2 Plus (10 Core) processors, Surface Pro delivers fast, responsive performance with built-in AI acceleration—so you can handle everything from everyday tasks to demanding workloads with ease.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
Check the tenant’s current authority
- Open the Microsoft Intune admin center.
- Go to Tenant administration > Tenant status > Tenant details.
- Read the MDM authority value.
If the portal does not offer a “Configuration Manager MDM authority” choice, that is expected in current tenants; the old Configuration Manager MDM-authority model was deprecated.
Move Basic Mobility and Security users to Intune
Prepare policies before licensing users
Do not treat the authority action as a harmless toggle. Recreate the settings currently supplied by Basic Mobility and Security in Intune before moving a pilot group:
- Security and compliance policies
- Email profiles
- Wi-Fi, VPN, and certificate profiles
- Device-configuration profiles
- Applications and app-protection settings
Target replacement policies to the same users or groups, remove conflicting assignments, and record the original configuration. Microsoft warns that old settings—including managed email profiles—can be removed when a user moves, and users may have to authenticate email again. Confirm Apple APNs and Android Enterprise integrations before enrolling those platforms.
Enable Intune coexistence
- Sign in to the Intune admin center as a Microsoft Entra Global Administrator or Intune Service Administrator.
- Go to Devices and find the Add MDM Authority banner.
- Select Intune MDM Authority > Add and confirm coexistence.
- Assign an Intune-entitling license to each user whose devices should move.
- Deploy the replacement Intune policies to a small pilot group.
- Wait for the devices’ next MDM check-in, or have users initiate a Company Portal check-in or compliance check.
Enabling Intune does not migrate every device immediately. Users generally move when they have an Intune license and their devices check in. A user with only the relevant Microsoft 365 license can remain on Basic Mobility and Security.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #2
- Brilliant OLED Display – Incredible image quality – The 13" PixelSense touchscreen[1], with optional OLED and HDR[2] tech, gives you sharp detail, smooth scrolling, and colors so richly saturated bringing vivid life into every frame - perfect for work, school, streaming, and creative tasks.
- Up to 15.5 hours of battery life[3] - The new Surface Pro is designed for long days, late nights and everything in between.
- Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Pro delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
What happens during the transition?
Devices must connect to the new service before receiving Intune settings. Profiles from the previous authority—email, VPN, certificates, Wi-Fi, and configuration profiles—can remain for up to seven days or until the first connection to the new authority. Authority synchronization can take up to eight hours, depending on scheduled check-ins, and Intune compliance reporting can take up to a week to become accurate.
Devices without an associated user, including some Apple automated-device-enrollment or bulk-enrollment devices, may not migrate automatically and can require Microsoft Support assistance.
Validate an Intune migration
- Recheck Tenant administration > Tenant status > Tenant details and confirm the intended authority.
- Verify the pilot user has the required Intune license.
- Confirm the device checks in and appears in Intune.
- Test compliance, configuration, email, Wi-Fi, VPN, certificates, and applications.
- Use a harmless remote action, such as Remote lock, to verify management.
- Enroll a new test device and confirm that it lands in Intune.
- Review Microsoft Entra sign-in and compliance results before expanding the rollout.
If an individual device remains attached to the old service, Microsoft documents unenrollment and re-enrollment as a way to reconnect it more quickly.
Can Intune be changed to SCCM as the tenant MDM authority?
No—not through a supported modern tenant setting. Microsoft’s staff guidance says the former Configuration Manager MDM-authority model was deprecated and that switching from Intune to Configuration Manager authority is unsupported: Microsoft Q&A response. Do not rely on hidden portal options, registry edits, PowerShell tricks, or undocumented backend changes.
Rank #3
- [This is a Copilot+ PC] — The fastest, most intelligent Windows PC ever, with built-in AI tools that help you write, summarize, and multitask — all while keeping your data and privacy secure.
- [The Power of a Laptop, the Flexibility of a Tablet] — Surface Pro 12” is a 2-in-1 device that adapts to you. Use it as a tablet for on-the-go tasks, prop it up with the built-in kickstand, or attach the Surface Pro Keyboard (sold separately) to turn it into a full laptop.
- [Incredibly Fast and Intelligent] — Powered by the latest Snapdragon X Plus processor and an AI engine that delivers up to 45 trillion operations per second — for smooth, responsive, and smarter performance.
- [All Day Battery Life] — Up to 16 hours of battery life[1] means you can work, stream, and create wherever the day takes you — without reaching for a charger.
- [Brilliant 12” Touchscreen Display] — The PixelSense display delivers vibrant color and crisp detail in a sleek design — perfect for work, entertainment, or both.
If the goal is to keep Windows devices under Configuration Manager, either remain Configuration Manager-only or use co-management without moving workloads. A full Intune-to-Configuration Manager reversal depends on platform, enrollment state, licensing, and whether devices must be unenrolled and re-enrolled; escalate tenant-specific cases to Microsoft Support.
Move Configuration Manager-managed Windows devices with co-management
Co-management lets Configuration Manager and Intune manage the same supported Windows devices. You choose authority per workload instead of changing one tenant-wide MDM switch. Review the co-management overview for supported scenarios.
Prerequisites
- A supported current-branch Configuration Manager version
- Microsoft Entra integration and appropriate administrative permissions
- Intune and applicable Windows licensing
- Supported Windows devices with a healthy Configuration Manager client
- Automatic Intune enrollment configured
- Clean Microsoft Entra device records; remove duplicate or stale objects
Configuration Manager licensing can provide co-management rights for Windows PCs in applicable agreements, but it does not automatically license every Intune enrollment scenario. iOS, Android, and macOS management requires an appropriate Intune subscription through standalone Intune, Enterprise Mobility + Security, or Microsoft 365.
Enable co-management
- In the Configuration Manager console, open Administration > Cloud Services > Cloud Attach.
- Select Configure Cloud Attach. Configuration Manager 2111 and later use this wizard-based onboarding experience.
- Configure the Microsoft Entra tenant connection.
- Set automatic Intune enrollment to Pilot, All, or None, and select the device collection for enrollment.
- Complete the wizard and confirm that pilot devices become co-managed.
- Build and deploy the Intune policies for the workloads you plan to move.
See Microsoft’s co-management enablement procedure for version-specific prerequisites.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #4
- AI-enhanced Surface Studio Camera: The ultra-wide front facing camera paired with AI-powered Studio effects like automatic framing keeps you, or the whole family in focus
- Snapdragon X Plus (10 core) processor: Experience unparalleled productivity in ultra-portable laptop designs, with battery life that lasts for days
- Immersive Visuals: The 13" PixelSense Flow display offers stunning clarity with 2880 x 1920 resolution and a near edge-to-edge design. With a 1200:1 contrast ratio and up to 120Hz dynamic refresh rate, enjoy vibrant colors and ultra-smooth, responsive touch for an elevated viewing and work experience
- Surface Slim Pen: Stores and recharges in the premium keyboard designed to be used either attached to your Pro for the ultimate laptop set-up or detached as a standalone keyboard for a new level of flexibility
- Instant Copilot: Unlock new possibilities with the dedicated Copilot key, which gives you instant access to experiences that can enhance your productivity
Switch workloads gradually
- In Configuration Manager, go to Administration > Cloud Services > Cloud Attach.
- Select the co-management object, choose Properties, and open Workloads.
- For each workload, choose Configuration Manager, Pilot Intune, or Intune.
- Use the Staging tab to define pilot collections.
- Validate each pilot before expanding the collection.
Configure the Intune equivalent before switching a workload, and keep one tool authoritative for that workload to avoid conflicting settings. Workload switches are reversible: a workload assigned to Intune can be returned to Configuration Manager. Details are in Microsoft’s workload-switching guide.
Choosing an order
There is no universal sequence. Start with a pilot and lower-risk management areas, then move security, compliance, configuration, Windows Update, applications, and endpoint protection only after their Intune implementations are tested. Treat each workload as a separate change with its own rollback plan.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting common failures
The Add MDM Authority banner is missing
Verify that you are using the Intune admin center, have Global Administrator or Intune Service Administrator rights, and that the tenant is not already configured for the intended authority.
Policies disappear after licensing
The device likely switched from Basic Mobility and Security before equivalent Intune policies were assigned. Deploy replacements before licensing the next pilot, and check that assignments do not conflict.
Best Value
- Brilliant LCD Display – The 13" PixelSense touchscreen[1], with LCD and enriched HDR[2] tech, unveils crisper whites, darker blacks, and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
- Up to 15.5hours of battery life[3] - The new Surface Pro is designed for long days, late nights and everything in between.
- Productivity. All Day. Every Day. – Built with the latest Qualcomm Snapdragon X2 Plus (10 Core) processors, Surface Pro delivers fast, responsive performance with built-in AI acceleration—so you can handle everything from everyday tasks to demanding workloads with ease.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
Profiles remain duplicated
Overlapping profiles or differently named replacements can leave old settings in place temporarily. Consolidate assignments and, where appropriate, use matching profile names so the new profile supersedes the old one.
Apple enrollment fails
Upload or renew the Apple MDM push (APNs) certificate under the new Intune authority before enrolling or migrating iPhone and iPad devices.
Devices do not appear in Intune
- Confirm the user has an Intune license.
- Check whether the device has checked in.
- Verify that it has an associated user.
- Remove duplicate Microsoft Entra device objects.
- Confirm platform enrollment prerequisites and that it is not still managed by Basic Mobility and Security.
Co-management enrollment fails
Check Windows and Configuration Manager support status, client health, Microsoft Entra permissions, licensing, the auto-enrollment collection, cloud-attach configuration, and connectivity requirements for internet-based devices.
Licensing choices
Pricing and entitlements vary by region, agreement, channel, and commitment. Microsoft’s U.S. list-price signals observed on August 18, 2026 were $8.00 per user/month for Intune Plan 1, $4.00 for Plan 2, $10.00 for the Intune Suite, $39.00 for Microsoft 365 E3 with Teams, and $60.00 for Microsoft 365 E5 with Teams, each paid yearly. Check the current Microsoft Intune pricing page and your licensing agreement before purchasing. Plan 1 is typically sufficient for a standard Basic Mobility and Security replacement; Plan 2 or the Suite is justified only by specialty-device or advanced-module requirements. Bundles can be more economical when productivity, security, and compliance services are also needed.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose the correct end state
| Current state | Desired result | Supported method |
|---|---|---|
| Basic Mobility and Security | Intune management | Add Intune MDM authority, enable coexistence, license users, and migrate by check-in. |
| Configuration Manager-managed Windows PCs | Gradual cloud migration | Enable co-management and switch workloads with pilot collections. |
| Configuration Manager-managed Windows PCs | Keep Configuration Manager control | Remain Configuration Manager-only, or enable co-management without switching workloads. |
| Intune tenant | “Configuration Manager MDM authority” | No supported modern tenant-authority switch exists. |
| Mixed Windows, iOS, Android, and macOS estate | Centralized cloud management | License Intune appropriately and prepare platform-specific enrollment integrations. |
The practical distinction is simple: Basic Mobility and Security to Intune is a user-licensing and coexistence migration; Configuration Manager to Intune is co-management with workload ownership. Neither requires, nor supports, changing the tenant to a modern “SCCM MDM authority.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




