Microsoft is about to give its enterprise plans a significant Intune upgrade—but one critical security tool remains locked out of the base package. Starting July 1, 2026, Microsoft 365 E3 will include advanced endpoint management features like Remote Help and Advanced Analytics, yet Endpoint Privilege Management (EPM) stays firmly in E5 and E7 territory. If your organization relies on EPM to keep users from running as local admins, prematurely dropping a standalone add-on could create a compliance gap you can't afford.
What's Actually Changing on July 1, 2026
Microsoft announced the redistribution in a July 1, 2024, Intune blog post, and the company's official licensing guidance now spells out the new entitlements clearly. The goal: fold previously separate Intune capabilities into the most common Microsoft 365 bundles. But the move isn't a blanket expansion. Instead, it splits advanced features across two tiers.
Microsoft 365 E3, the workhorse plan for many mid-size and large organizations, gains Intune Plan 2—which includes Remote Help and Advanced Analytics—at no additional cost. Previously, these were only available through add-ons or the full Intune Suite. For E5 and E7 customers, the package goes further: they also receive Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise Application Management, all formerly part of the Intune Suite or separate subscriptions.
What does that leave on the table for E3? EPM. And that matters a lot.
A Quick Glance: Which Plan Gets What
The table below distills the new reality as of July 1, 2026, based on Microsoft's published statements:
| Microsoft 365 Plan | Newly Included Intune Capabilities (from July 1, 2026) | EPM? |
|---|---|---|
| E3 | Plan 2, Remote Help, Advanced Analytics | No |
| E5 | Plan 2, Remote Help, Advanced Analytics, Endpoint Privilege Management, Cloud PKI, Enterprise Application Management | Yes |
| E7 | Same as E5 | Yes |
If you're on any other plan, you'll still need to buy Intune Suite or the specific add-ons separately. But for millions of users on E3, the message is clear: your Intune toolbox just got bigger, but it's missing a key security wrench.
The EPM Gap: More Than Just a Licensing Oversight
Endpoint Privilege Management is not a trivial feature. It's the service that allows IT to remove permanent admin rights while still letting users install approved apps, run trusted tools, and handle one-off elevation requests—all logged and audited. For many Windows shops, EPM is the foundation of a least-privilege strategy. If it's already baked into your application deployment, developer workflows, or helpdesk processes, its licensing cannot be treated as an afterthought.
The danger lies in a well-meaning but incomplete procurement memo. A phrase like "Intune Suite capabilities are coming to our E3" might lead someone to cancel all premium Intune add-ons. But EPM isn't part of that story. The license migration for E3 covers Plan 2 features only; for EPM, you remain exactly where you started.
Microsoft's own licensing rule underscores the need for precision: "An Intune license is required for any user or device that benefits directly or indirectly from the Microsoft Intune service, including access through a Microsoft API." That means if a device's endpoint is controlled by an EPM policy—even if the user never opens the Intune portal—they need a valid EPM entitlement. And merely having the E3 suite doesn't provide it.
How We Got Here: Intune's Evolution Toward Bundled Security
To understand this change, it helps to rewind a couple of years. Microsoft launched Intune Suite in 2023 as a premium add-on that bundled several advanced security and management tools, including EPM, Cloud PKI, and Enterprise Application Management. The move was part of a broader strategy to turn Intune into a full endpoint security control plane, not just a device management console. At the time, customers on any plan—including E3—had to purchase the Suite or specific add-ons to get those features.
By 2025, the company began signaling that some Intune Suite elements would eventually merge into the core Microsoft 365 plans. The July 2026 redistribution is the result. But instead of a single package, Microsoft chose to differentiate: E3 gets the "Plan 2" tier of capabilities, while E5 and E7 absorb the rest of what used to be the Suite. That makes commercial sense—E5 has always been positioned as the security-conscious, comprehensive offering—but it leaves E3 customers in a tough spot if they've grown dependent on EPM.
The timeline is generous: organizations have more than a year from the announcement to sort out their licensing. Yet the reclassification of entitlements can trigger auto-renewals, contract renegotiations, or internal miscommunications well before the cutoff. Procrastination is the real risk.
What to Do Before the Deadline
Your next steps depend on which Microsoft 365 plan actually covers the people and devices using EPM. Don't rely on a tenant-wide label like "we're an E5 shop"—many enterprises mix E3 and E5 assignments across different departments, and shared kiosks or contractor accounts often slip through the cracks.
If You're on Microsoft 365 E5 or E7
You may be able to retire a standalone EPM subscription. But only after you:
- List every user and device that benefits from EPM (including service accounts and shared endpoints).
- Confirm that each one is assigned an E5 or E7 license.
- Check for edge cases: contractors, subsidiaries, and device-only enrollments often use different plans.
- Align with procurement and your Intune admin before canceling any add-on.
- Keep the add-on active until the entire affected scope is confirmed covered, then document the change for future audits.
A premature cancellation could leave EPM policies functioning but unlicensed—a compliance violation that could surface during a Microsoft audit.
If You're on Microsoft 365 E3 Only
Do not drop your EPM add-on. While you will get Remote Help and Advanced Analytics through your plan beginning July 2026, EPM remains a separate requirement. However, this could be an opportunity to consolidate other add-ons you may have been carrying just for those now-included features. Revisit your licensing position, but keep the EPM coverage intact.
If You're in a Mixed Environment
Perform a cohort-level review. Segment your users into:
- Those with E5/E7 (might be covered for EPM)
- Those with E3 (need separate EPM add-on)
- Those on other plans or device-only licenses (will require Intune Suite or specific add-ons)
Device-only scenarios deserve special attention. A shared kiosk or lab machine enrolled without a user license can still be under EPM policy, and Microsoft's licensing requires a valid license for that device. Don't assume a blanket E5 count covers them.
Use the Admin Center—But Verify Separately
Microsoft's guidance suggests checking Tenant administration > Tenant status in the Intune admin center to see total licensed users and Intune licenses. This gives a starting point, but it won't tell you which specific users have EPM. Use that number only as a baseline, then run your own entitlement audit against the actual license assignments in Microsoft 365 admin center or Entra ID.
Also, remember the "unlicensed admin" myth. Intune administrators can manage the service without an assigned Intune license in supported configurations, but that doesn't extend to feature licensing. An unlicensed admin setting up EPM policies doesn't magically cover the endpoints that use them.
The Bigger Picture
This licensing shift is a signal of where Microsoft is heading: a tighter integration between Windows security and Microsoft 365 identity. EPM, Cloud PKI, and Enterprise Application Management are all pieces of a passwordless, least-privilege endpoint architecture. By placing them in E5 and E7, Microsoft is nudging security-conscious organizations toward those plans. For everyone else, it's a reminder that the tools to harden Windows are becoming essential—and they come at a price.
Over the next year, expect more bundling announcements and possibly a new front in the “E3 vs. E5” value debate. For now, the safest move is to treat July 1, 2026, not as a universal upgrade but as a date to revisit your licensing map. Because when it comes to privileged access, missing a license isn't just a paperwork problem—it's a security risk you're already paying to avoid.