Microsoft 365 E5 now carries the full set of advanced Intune capabilities that were previously sold through Intune Plan 2 and the Microsoft Intune Suite add-on, completing a packaging rollout Microsoft says finished on August 1, 2026. For commercial E5 tenants, that means Remote Help, Advanced Analytics, specialty-device management, Firmware Over-the-Air updates, Microsoft Tunnel for Mobile Application Management, Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise Application Management should now be available without assigning a separate Intune Suite SKU. That is a larger change than the “Intune Suite included in E5” shorthand suggests, but it is also less of a surprise windfall than it first appears. Microsoft paired the expanded entitlement with a July 1 increase in U.S. list pricing for Microsoft 365 E5, from $57 to $60 per user per month with Teams. RSM correctly identifies the procurement simplification; Microsoft’s own pricing record makes clear that the advanced endpoint-management bundle has been folded into a more expensive E5 package rather than simply given away.
For IT teams that already standardized on E5, the immediate opportunity is real: remove overlapping Intune Suite purchases at renewal after verifying entitlement and feature use. For organizations weighing an E3-to-E5 move, however, Intune should no longer be treated as a small add-on calculation. Microsoft has made endpoint privilege control, cloud certificate infrastructure, and curated Win32 app packaging part of the broader E5 value proposition—and its licensing lock-in.

Cybersecurity analyst monitors a dashboard displaying digital protection, cloud security, and connected devices.What Microsoft 365 E5 now includes​

Microsoft’s packaging table splits the new Intune entitlements between E3 and E5. Microsoft 365 E3 gained Intune Plan 2, Remote Help, and Advanced Analytics. E5 includes those E3 additions and adds Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise Application Management.
Taken together, those E5 additions cover the advanced capabilities Microsoft currently documents for Intune:
  • Intune Plan 2 brings management for specialty devices, Firmware Over-the-Air updates for supported Android hardware, and Microsoft Tunnel for MAM on unmanaged Android and iOS devices.
  • Remote Help provides an Intune-governed remote-support tool with role-based access controls, offering an alternative to separately licensed remote-control products for many help-desk scenarios.
  • Advanced Analytics expands endpoint analytics with fleet-level data intended to identify performance and user-experience problems.
  • Endpoint Privilege Management lets standard users perform approved tasks requiring elevation without routinely holding local administrator rights.
  • Microsoft Cloud PKI supplies Microsoft-hosted certificate-authority functions for certificate issuance, renewal, and revocation across supported Intune platforms.
  • Enterprise Application Management provides Microsoft’s Enterprise App Catalog for curated Win32 applications and prebuilt installation parameters.
The significant correction to the supplied framing is that Intune Suite is not becoming the base Intune product, nor is Microsoft renaming E5’s existing Intune entitlement. Intune Plan 1 remains the core unified endpoint-management service. What has changed is the license boundary around advanced Intune features: E5 has absorbed the capabilities that made the Suite a separate premium purchase.
Microsoft still sells Intune Suite and individual add-ons. That is not contradictory. The standalone products remain relevant to customers on Microsoft 365 Business, Frontline, Office 365, or other licensing combinations that do not receive the new E3 and E5 benefits. They also remain a way to add advanced management functions without moving an entire user population to an enterprise Microsoft 365 suite.

The price increase is part of the story​

Microsoft’s July 2026 commercial packaging update added more than Intune features. Microsoft 365 E5 also gained Microsoft Security Copilot, while E3 picked up Defender for Office 365 Plan 1. The vendor raised the list price for E5 with Teams by 5%, or $3 per user per month, on July 1; the no-Teams E5 price rose from $48.45 to $51.45.
Microsoft has not assigned a dollar value to each individual feature, so it would be wrong to say the entire increase pays for Intune Suite. But the timing is decisive: customers buying or renewing E5 are paying a higher bundle price that includes these capabilities alongside Security Copilot and other changes. Calling the new Intune features “free” is accurate only for an existing eligible tenant receiving them before its next renewal—not as a description of Microsoft’s current commercial price.
Microsoft says existing qualifying customers receive the new features regardless of the price paid or agreement term. That is the favorable part of the change for organizations locked into enterprise agreements signed before July 1. A tenant does not have to wait for contract renewal to see the entitlement, and Microsoft says no opt-in or manual action is required.
The rollout itself was tenant-based, not a switch thrown globally on July 1. Microsoft said commercial tenants would receive at least 30 days’ notice in the Microsoft 365 Message Center before the package changes arrived, with rollout beginning in June and finishing by August 1. On August 6, that published completion date is now in the past. An E5 administrator who still sees Suite licensing prompts or inactive add-ons should treat that as a support issue or an eligibility problem, not as normal rollout delay.

The biggest practical win is privilege management​

Remote Help will get the most attention because it can displace a visible third-party support subscription. Yet Endpoint Privilege Management may be the more consequential E5 addition for Windows administrators.
Many organizations still resolve application-install and troubleshooting friction by giving users persistent local administrator rights, maintaining generic admin accounts, or relying on help-desk staff to remotely perform elevation. Those practices make lateral movement and accidental system changes easier. Endpoint Privilege Management is designed around just-in-time elevation: a user stays standard by default but can elevate approved processes under policy, with the event governed and auditable through Intune.
That makes E5 a more coherent Windows management package. Microsoft Defender for Endpoint supplies endpoint detection and response; Microsoft Entra supplies identity controls; Intune supplies device configuration and compliance; and Endpoint Privilege Management now gives E5 customers a Microsoft-native route to remove standing admin rights. It does not eliminate the operational work. Administrators must inventory the applications and maintenance tasks users genuinely need, create elevation rules, test installers that spawn child processes, and define how exceptions are approved. The license entitlement removes a purchase decision; it does not create a least-privilege program by itself.
Cloud PKI has a similarly practical effect. Organizations that need Wi-Fi, VPN, SCEP, certificate-based authentication, or device certificates have often had to operate Active Directory Certificate Services, buy a cloud PKI service, or retain a hybrid certificate infrastructure. Microsoft Cloud PKI can reduce that dependency for supported cases, but it is not an automatic migration from an on-premises PKI. Certificate templates, trust chains, network-device compatibility, renewal behavior, and recovery procedures still need design work before an enterprise replaces a functioning certificate authority.
Enterprise Application Management may be the quietest but most useful feature for Windows endpoint teams. Managing third-party Win32 app packaging is a recurring Intune burden, especially for common applications with complex install switches, detection rules, and version churn. Microsoft’s catalog can reduce the packaging labor for supported apps. It does not mean every line-of-business application, legacy installer, or internally developed package is suddenly managed without engineering effort.

What E3 gets—and why mixed estates still matter​

Microsoft 365 E3 receives meaningful additions, but it does not receive the complete E5 Intune set. E3 now includes Plan 2, Remote Help, and Advanced Analytics. It does not receive Endpoint Privilege Management, Cloud PKI, or Enterprise Application Management under Microsoft’s current commercial packaging table.
That split matters in mixed-license environments. An IT department cannot assume that enabling an E5 feature in the Intune admin center authorizes use for every employee or device. Microsoft’s Intune licensing guidance says a license is required for each user or device that benefits directly or indirectly from the service. If an organization has E5 executives and engineers alongside E3 office workers, its Endpoint Privilege Management rules, Cloud PKI profiles, and app-management processes need to account for which users hold the E5 entitlement.
The same caution applies to shared and unattended Windows endpoints. Intune has a device-only licensing model for kiosks, dedicated devices, phone-room systems, and certain IoT scenarios, but it comes with limitations around user-based functions such as app protection policies and Conditional Access. Endpoint teams should not infer that an E5 user entitlement automatically solves licensing for every shared device in their estate.
Directions on Microsoft has separately noted that the packaging is most valuable to E5 customers and that the standalone Suite remains necessary in scenarios outside the eligible enterprise packages. Its analysis also flags a gap Microsoft has not fully resolved in public materials: academic licensing and some government environments do not follow the commercial rollout on the same schedule or with the same feature set.
Microsoft’s own government matrix confirms the difference. Microsoft 365 G5 in GCC receives the comparable E5 additions, including Endpoint Privilege Management, Enterprise Application Management, and Cloud PKI. GCC High and DoD offerings are more restricted in the published 2026 table: both list Endpoint Privilege Management, but do not list all of the commercial E5 Intune additions. Federal and education customers should therefore verify their exact SKU and tenant environment rather than applying commercial E5 guidance wholesale.

The licensing cleanup should be deliberate​

Organizations already paying for Microsoft 365 E5 plus Intune Suite should begin a contract and assignment review, but they should not cancel anything blindly mid-term. First, identify Suite licenses assigned to E5 users, determine which of the eight advanced capabilities are actually in production, and confirm that the tenant exposes each entitlement under Tenant administration > Intune add-ons. Then map users who are not on E5, including contractors, frontline staff, specialist device operators, and users in separate tenants.
The clean outcome may be straightforward: E5 users no longer need separately purchased Intune Suite licenses once their paid term permits removal. But an organization that bought Suite licenses to cover E3, Business Premium, Frontline, or non-Microsoft 365 users may still need a residual Suite or add-on pool. The procurement savings come from right-sizing that pool, not from assuming every existing Suite license is redundant.
Microsoft has changed Intune’s role in E5 from a foundational device-management service with premium extensions into a much fuller endpoint-security and operations package. The August 1 completion date means commercial E5 tenants should now have the entitlement; the next task is to decide whether their Windows support, privilege, certificate, and application-management practices are ready to use it.

References​

  1. Primary source: RSM US LLP
    Published: 2026-08-06T16:12:07.969781
  2. Related coverage: microsoft.com
  3. Related coverage: learn.microsoft.com
  4. Related coverage: learn.microsoft.com
  5. Related coverage: blogs.microsoft.com
  6. Related coverage: cloudengineerlab.com
  7. Related coverage: mrmicrosoft.com
  8. Related coverage: microsoft.com
  9. Related coverage: rsmus.com
  10. Related coverage: directionsonmicrosoft.com
  11. Related coverage: technologyblog.rsmus.com
  12. Related coverage: techcommunity.microsoft.com
  13. Related coverage: techcommunity.microsoft.com
  14. Related coverage: ailonalab.com
  15. Related coverage: cdn-dynmedia-1.microsoft.com
  16. Related coverage: cdn-dynmedia-1.microsoft.com
  17. Related coverage: biggreenit.com