WhichM365Independent Microsoft 365 decision guide

HomeLearnSecurity foundation

Security foundation · 7-minute primer

How Entra, Intune, and Defender work together

Think of them as a decision loop: identity establishes who is asking, device management evaluates the device, security contributes risk signals, and access policy decides what happens next.

Start here when
You need to explain the Microsoft 365 security stack clearly
Primary audience
IT leaders, administrators, advisers
Verified

The short answer

Identity, device state, and threat risk inform access

Microsoft Entra manages identity, authentication, and access decisions. Microsoft Intune manages devices, apps, configuration, and compliance state. Microsoft Defender detects and responds to threats and can contribute device risk. Conditional Access in Entra can combine those signals to allow, challenge, limit, or block access.

The decision loop

Each product answers a different security question

LayerCore questionSignal or control
Microsoft EntraWho is requesting access, under what conditions?Identity, authentication, sign-in risk, roles, and Conditional Access
Microsoft IntuneIs the device or app managed and compliant with policy?Configuration, compliance state, app protection, device management
Microsoft DefenderIs there active or emerging threat risk?Threat detection, endpoint risk, investigation, and response
Conditional AccessGiven these signals, should access be allowed?Require MFA, require compliant device, restrict session, or block

One practical example

A sign-in is more than a password check

A user signs in to Microsoft 365. Entra knows the identity and sign-in context. Intune reports whether the device meets the organization's compliance policy. Defender can provide a device risk signal. Conditional Access evaluates the combined policy conditions and determines whether access is allowed, requires an additional control, or is blocked.

The products remain distinct. Their value increases when policy owners agree on how the signals should affect access.

Why not only one product?

No single layer answers the full question

Entra alone

Can authenticate and control access, but it needs reliable device and risk signals for device-aware, risk-based decisions.

Intune alone

Can manage and evaluate devices and apps, but it does not replace identity-based access policy or threat detection.

Defender alone

Can detect threats and device risk, but it does not replace device lifecycle management or identity access decisions.

The combined system

Becomes relevant when access must adapt to identity, device compliance, and threat conditions together.

Evidence before a licensing decision

Define the policy outcome first

  • Which identities, applications, and data require stronger controls?
  • Which device states should count as compliant, and who owns exceptions?
  • Which risk signals should challenge or block access?
  • How will emergency access and recovery remain possible?
  • Which incidents, access failures, or unmanaged devices establish the baseline?

Public Microsoft sources

Verify the current security relationship

Source review completed . Confirm product editions, licensing, region, agreement, and supported platforms for your environment.

Finished this primer?Optional progress stores only this primer identifier and a completion time on this device.

Continue learning

Connect security to licensing

WhichM365 provides independent educational decision support. It does not implement, deploy, operate, or manage Microsoft solutions. Product information is based only on public Microsoft sources. Its author is a Microsoft employee acting in a personal capacity. WhichM365 is not a Microsoft product or service and is not sponsored, authorized, or endorsed by Microsoft.