Opens in a new tab
vmblog logo 2024 wht (updated)

NerdioCon 2026: Microsoft’s Lior Bela Makes the Case for Cloud-Native Endpoint Management with Microsoft Intune

Share: 

David Marshall | Published: May 6, 2026
nerdiocon 2026 intune keynote

By day three of NerdioCon 2026, you could feel the energy shift. The late-night pool cannonball sessions were behind everyone, the hallway conversations had gotten sharper, and the crowd filing into the keynote room at 8:00 in the morning had a specific kind of focus — the kind that comes when people know they’re about to hear something worth waking up early for.

They weren’t wrong.

This year, for the first time at NerdioCon, Microsoft Intune got its own dedicated keynote slot. And the decision to give Intune that platform says a lot about where the market is heading. When Nerdio first started bringing partners together, the conversation was almost entirely about Azure Virtual Desktop and Windows 365. Intune was in the mix, sure, but it wasn’t the headliner. Over time, that changed. Intune breakout sessions started drawing some of the biggest crowds at the event — right up there with Nerdio’s own roadmap sessions. The audience had spoken.

So who better to take the stage than the man the community has nicknamed “Agent Intune” — Lior Bela of Microsoft.


Welcome to the Part Where You Put Your Phone Down

Lior opened with a game. Everyone in the room stood up, and he started reading statements. Stay standing if you enforce privileged roles. Stay standing if you have conditional access policies covering both devices and identities. Stay standing if you’ve deployed a custom security agent. The room thinned out with each statement, and Lior let the silence do the work.

His point was simple: the people still standing had already started building what he was about to spend the next hour talking about. For everyone else, that was the reason to pay attention.

The session moved fast — deliberately so. Lior warned the audience upfront: “Get off your phone. Get off your computers and wake up, because we are about to start.” It was part stand-up comedy, part genuine urgency. By the end of it, you understood why he felt that way.


The Mindset Shift Nobody Can Afford to Ignore

Before getting into product announcements or demos, Lior spent time on something a lot of technical sessions skip: the why. Not the why of Intune specifically, but the why of the moment we’re all operating in right now.

Here’s the data he put in front of the room. Enterprises that have adopted generative AI are reporting productivity gains roughly 8x higher than companies that haven’t. AI is giving back meaningful time to employees — every single day. And over 70% of roles going forward will require some level of AI fluency. Lior’s challenge to the audience wasn’t corporate: “Prioritize learning AI the same way you prioritize your exercise, your diet, your personal life. You don’t have time to wait.”

That’s not a vendor pitch. That’s someone who genuinely believes the clock is already running.

But here’s where it gets interesting for IT and security teams specifically. The way we’ve always thought about identity — about who is doing what on a network — was built entirely around human behavior. Humans work eight to ten hours a day. If a device checks in at 3 AM, that’s a red flag. Changes are intentional. Logins are deliberate.

AI agents don’t work that way. They run around the clock, autonomously, and they don’t “log in” the way a person does. Which means the whole model of asking “is this user who they say they are?” is no longer sufficient. Today, identity needs to account for all of this:

  • Device compliance state — is the machine in a known good state?
  • Workload trust — is the policy what it’s supposed to be?
  • Risk posture — what does the threat intelligence say right now?
  • Change intent — was this change expected, or did it appear out of nowhere?
  • Agent identity and execution context — who or what authorized this action?

That’s a fundamentally different problem than the one most organizations built their security programs to solve. And that gap is exactly what Lior spent the rest of the keynote addressing.


Microsoft’s Message Has Been Evolving — Here’s Where It Landed in 2026

Lior was honest about something that a lot of speakers wouldn’t admit on stage: the Microsoft message has shifted, year over year, and it probably felt inconsistent if you’ve been following along.

In 2024, the push was simple: move to the cloud, leave your on-premises environment behind, get into Intune. People pushed back. In 2025, the emphasis moved to AI agents — Lior and a colleague literally dressed up as agents on stage in Paris to drive the point home. In hindsight, he acknowledged, that was a bit much.

2026 is different. The message is more grounded. Yes, cloud-native matters. Yes, AI is coming. But neither of those things works if the foundation isn’t there first.

“The question is not whether you are ready,” Lior told the room. “The question is — did you build the foundation?”

Without cloud-native infrastructure, real zero trust policies, and clean identity hygiene underneath everything, AI adoption isn’t going to be delayed — it’s going to be blocked. He put it plainly: if your CIO walks in tomorrow and says they want to enable AI across the organization, but you’re still running legacy management infrastructure, you’re not six months away from being ready. You’re years away. The foundation has to come first.


The Microsoft and Nerdio Partnership: Filling the Gap That Matters

Microsoft’s product portfolio is, by design, built to serve the broadest possible customer base. That works well for a lot of things. Where it gets complicated is multi-tenancy — the ability to manage multiple customer environments from a single pane of glass, which is the daily reality for every MSP in the NerdioCon audience.

Native Microsoft tools don’t fully solve that problem. That’s not a criticism — it’s just a scope issue. And it’s precisely why the Nerdio partnership exists.

Nerdio Manager for MSPs sits on top of Microsoft 365, Windows 365, and Azure Virtual Desktop and adds the multi-tenant management layer that MSPs actually need to operate efficiently. On the enterprise side, Nerdio Manager for Enterprise does the same for large organizations running complex environments. The goal, as Lior framed it, is to make sure customers and partners are getting full value out of the licenses they’re already paying for — not leaving capabilities on the table because the tooling doesn’t quite fit their operational model.


What Does Cloud-Native Endpoint Management Actually Mean?

Lior has a slide he shows every year. He jokes about it. He acknowledges it’s the same slide. And then he shows it anyway — because the message still isn’t landing universally, and he’s not going to stop saying it until it does.

Cloud-native endpoint management, at its core, comes down to four things working together:

Identity is the foundation. Everything else is built on top of it. Applications are managed natively in the cloud, not deployed via on-premises distribution systems. Workloads live in Intune, not in legacy management infrastructure. And Conditional Access is the connective tissue that makes all of it function as a system rather than a collection of separate tools.

Lior’s analogy for the audience who has Intune and Azure AD configured separately but not tied together with Conditional Access: “It’s like bringing two ingredients to the kitchen but not cooking them together.” You have everything you need. You just haven’t assembled it yet.

One quick note on platform coverage that’s worth calling out: Intune supports Windows, macOS, iOS, Android, and Linux. That’s the full picture for most organizations. But Lior dropped one more data point that got a laugh from the room — Intune now manages the infotainment systems in Mercedes-Benz vehicles. So yes, if your company issues Mercedes to executives, you can manage those, too. The reach of the platform is broader than most people realize.


What Microsoft Has Been Building: Key Improvements Over the Past Year

Lior was clear that there are hundreds of updates that ship to Intune in any given year — most of which never make it onto a conference slide. But a few things stood out as genuinely worth highlighting for an MSP and enterprise audience.

macOS management has seen meaningful improvement, and Lior issued a direct challenge to anyone in the room still using a third-party solution for Mac management: show him a better option that’s also included in a license they’re already paying for. He wasn’t worried about takers.

Latency was another topic he addressed head-on, because the “Intune only checks in every eight hours” narrative has been circulating for years and it’s simply not accurate anymore. Here’s the reality: 99.6% of check-ins happen on the first attempt. The P50 latency — meaning half of all check-ins — happens in under five minutes. For priority tasks like remotely wiping a stolen device, the response comes in under an hour. For an enterprise-scale MDM, those are solid numbers.

Security Copilot has been added to the Intune Suite, and for organizations on Microsoft 365 E5, Microsoft is providing enough credits to actively use it — at no additional cost. That’s not a trial. That’s a production-capable entitlement that a lot of E5 customers haven’t activated yet.


The Licensing News That Changes the Math for E3 and E5 Customers

Here’s the thing that probably should have been the headline of the session: Intune Suite capabilities are coming to Microsoft 365 E3 and E5 plans. No extra purchase required. These aren’t lite features — this is the Suite.

For organizations that are already paying for E3 or E5, that means they’re about to gain access to:

  • Remote Help — the ability to connect directly to managed devices for support and troubleshooting
  • Application management with eSIM and VPN capabilities
  • Microsoft Cloud PKI — a cloud-native certificate infrastructure that gives organizations a clear migration path away from traditional, on-premises PKI systems

Lior’s message to the audience was direct: “This is stuff coming through your tenants — something you’re already paying for. Benefit from it. Use it.”

For MSPs, this is significant. It means more capabilities to offer customers without additional licensing conversations, and it means the technical gap between what a customer pays for and what they’re actually getting deployed may be wider than it should be. That’s an opportunity.


The Demo Section: Where the Session Got Interesting

Lior had clearly spent time thinking about which demos would resonate most with this particular audience — a mix of MSPs, enterprise IT leaders, and technical administrators who work in Intune every day. He moved quickly, but each demo told a specific story.

Real-Time Policy Visibility

The first demo was a direct response to the latency conversation. Lior showed device check-in status and policy compliance updating in near real-time, which is different from what a lot of people expect based on older Intune behavior. The key message: “You don’t need one-second updates. You need visibility.” Knowing what’s happening in your environment — even with a five-minute lag — is more valuable than obsessing over the time interval.

Multi-Admin Approval Workflows

This one generated genuine interest in the room. Lior walked through the process of creating a policy and triggering a dual-admin approval workflow — a second administrator in a separate tenant view has to review and approve the request before it executes. The demo showed the full chain: request submitted, notification received, review completed, approval granted, change applied.

Yes, it adds steps. That’s the whole point. As Lior put it: “Does it add three more steps? Absolutely. Does it enhance your security to amazing levels? Yes.” For organizations managing sensitive environments — and for MSPs managing customer environments — that kind of change governance is exactly the kind of control that prevents the mistakes that make the news.

Deployment Plans and Deployment Rings

This demo addressed something every IT administrator has dealt with: users who ignore update prompts, or worse, who get interrupted mid-workday by a forced update they weren’t expecting.

Deployment Plans let administrators schedule application and update pushes to specific time windows. Push Adobe Acrobat at 2 AM on a Tuesday. Segment the rollout by deployment rings — Low Traffic, Pilot group, New Hires, specific departments. Lior’s example was pointed: don’t push anything to Finance at month-end. You don’t want that call from the CFO.

The ring-based approach also gives IT teams a way to monitor for breakage before a change rolls out to the full organization. If something breaks in the Pilot ring, you catch it there instead of across the entire company.

Enhanced Device and Software Inventory

Intune’s inventory capabilities got a meaningful upgrade, and what’s notable here is that these improvements are coming to Intune Plan 1 — the baseline tier. No upsell required.

Administrators can now see software version details, installation dates, management state, and per-device application inventory, all within the console. For patch management workflows and vulnerability targeting, having clean, current software inventory data inside the same platform you use for policy management is a genuine operational improvement.

Enterprise Privilege Management (EPM) Elevations

The EPM demo focused on the audit and history side of privilege management, which tends to get less attention than the enforcement side but is arguably just as important. Every elevation event — what app triggered it, who initiated it, when it happened — is logged and accessible.

The interesting insight Lior surfaced: elevation history isn’t just for compliance. It’s a roadmap for automation. If a specific application has been elevated and approved a hundred times in the past six months, that’s a signal. Maybe it shouldn’t require manual elevation every single time. Maybe there’s an automated policy that should just handle it. EPM gives you the data to have that conversation intelligently.


AI Agents Are Coming Into Intune — Here’s What That Looks Like

This section of the keynote was forward-looking, and Lior was clear about what was live versus what was coming. But the direction is unmistakable: AI agents are being woven into the Intune management experience, and the design philosophy behind them is worth understanding.

The Change Monitoring Agent is already available. It watches the Intune environment, pulls from threat intelligence feeds, and surfaces changes with contextual detail — what changed, when, what the risk context looks like. When an administrator sees a flagged change and goes to review it, the agent provides an explanation of what the change does, what the associated risks are, and what action is recommended. The administrator still makes the call. The agent does the research.

Lior was deliberate about this framing: “AI is there to help you make an educated decision — not make the decision for you.” That’s an important distinction, especially in a room full of people who are responsible for managed environments they didn’t build themselves.

A Vulnerability Remediation Agent is coming soon. It pulls all vulnerabilities from the environment, maps them to affected devices using Exposure Management data, scores them by risk level, and provides recommendations. When you’re ready to act, one click marks it for remediation and the action executes. For a large enterprise — or an MSP managing dozens of customer tenants — the difference between manual cross-referencing and AI-assisted prioritization is measured in hours per week.

And then there’s something newer: the ability to register AI agents in Intune itself. As AI agents proliferate across organizations — doing work, making changes, executing tasks — those agents have identities. Those identities need to be managed, governed, and audited just like any other identity in the environment. Intune is building toward being the place where that governance happens.


The Seven-Step Zero Trust Roadmap: Your Actual To-Do List

Lior closed his technical content with what he called the MVP for securing an enterprise ready for the AI era. He put it on a slide and told the audience he wanted them to photograph it, print it, and put it on the wall. Here’s what it contains:

  1. Enable Conditional Access and enforce your compliance policies. A compliance policy that isn’t enforced does nothing. This is the step that makes everything else matter.
  2. Deploy MDM and MAM — Mobile Device Management and Mobile Application Management through Intune. Cover managed devices and unmanaged ones.
  3. Activate Endpoint Privilege Management (EPM) if you’re eligible under your license. Run standard users. Elevate when necessary. Log everything.
  4. Enable Security Copilot Agents. If you have the entitlement, it’s already there. Use it.
  5. Deploy Microsoft Edge for Business, especially for BYOD and unmanaged device scenarios. Mobile Application Management from Intune applies here, giving you data protection without requiring full device enrollment.
  6. Register your AI agents in Intune. Give them managed identities. Apply governance policies to what they can do and where they can go.
  7. Audit everything. As more work gets handed off to autonomous agents, the audit trail is the one thing that keeps you accountable and informed. Don’t skip it.

Phishing-resistant MFA and hardware-backed attestation — now extended to Android, joining iOS, macOS, and Windows — sit underneath all of this as baseline requirements. And least-privilege access, enforced through EPM, is the thread that runs through all seven steps.


Free Tools Worth Bookmarking Before You Leave This Page

Lior wrapped up with a few resources he wanted to make sure the audience left with, and these are worth passing along.

The Zero Trust Assessment Tool is available free on GitHub through the Zero Trust Workshop at aka.ms/zerotrust. It works for both enterprise environments and MSP customer environments. The idea is to run it against your own tenant, understand where your gaps are, and use that as a starting point for building the foundation Lior spent the whole session talking about. It’s not a sales tool — it’s a diagnostic.

For M365 E5 customers: Security Copilot credits are already in your tenant. If you haven’t activated them, that’s worth a look this week.


What This Session Actually Meant

Stepping back from the demos and the product announcements, here’s the read on what NerdioCon 2026’s Intune keynote was really saying.

Intune is no longer just a mobile device management tool that enterprise IT uses to push policies to laptops and phones. It is positioning itself as Microsoft’s central security platform for the cloud-native era — the place where device compliance, identity governance, AI agent management, privilege control, vulnerability remediation, and audit all live together. That’s a significant expansion of scope, and it’s one that the licensing changes to E3 and E5 are designed to accelerate.

For MSPs, the message is clear: your customers are already paying for more than they’re using. The gap between what’s in their Microsoft 365 license and what’s actually deployed is an opportunity — both to deliver more value and to shore up security postures that are going to matter a lot more as AI agents start operating inside those environments.

For enterprise IT teams, the shift from managing user identities to managing AI agent identities is not a future problem. It’s a present one. The organizations that build the governance framework now — conditional access, EPM, agent registration, audit trails — are the ones that will be able to move quickly when the next wave of AI tooling arrives. Everyone else will be playing catch-up.

Lior’s challenge to the room, and honestly to anyone reading this: “The question is not whether you are ready. The question is — did you build the foundation?”

If the answer is no, the tools are available. Most of them are free, or already included in licenses you’re paying for. The roadmap is seven steps. The starting point is aka.ms/zerotrust.

There really aren’t many excuses left.

##