Microsoft Intune Experts in Germany
in minutes with vetted specialists and AI matchingHire experts who manage Intune policies, enroll devices in Windows, iOS, and Android, and set up app protection, compliance, and Conditional Access. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Microsoft Intune
Alwin G.
Last position:
IT Interim Manager & AI Strategist
- AI product development: Design of an AI-supported GRC platform to automate compliance processes.
- AI expertise: Strategic deepening in Agentic AI and GenAI as a core asset for modern IT governance
- IT interim management and strategic consulting
Markus Halbedel
Last position:
Senior M365 Consultant at BITMARCK GmbH
Creation of concepts for M365 implementation, especially Tenants, EntraID, EntraConnect and ExchangeOnline, taking BAS standards into account (mandatory baseline security requirements) in the project "Concept M365" with the aim of transferring the concepts to the M365 environments of Bitmarck and then handing them over to the customer.
- Creation of a current-state analysis of the existing M365 environments as well as the on-premises environments and the BAS standards.
- Creation of concepts for the topics Tenants, EntraID, EntraConnect and ExchangeOnline taking the BAS standards into account
- Design and implementation of an automated solution for creating standardized M365 tenants based on Microsoft M365 DSC (Desired State Configuration)
- Transfer of the concepts into the M365 environments
- Creation of detailed technical documentation
Peter Fleischer
Last position:
Subproject Manager and Solution Architect - Microsoft 365 Transformation at Automotive Industry
Integration of highly regulated countries such as China and South Korea into a company-wide M365 tenant.
Technical contact for integrating special requirements for the executive board and German subsidiaries that are subject to BaFin compliance requirements.
Subproject management.
Coordination of requirements within the overall architecture.
Design of the use of DLP features from Microsoft Purview.
Design of special access restrictions via Entra ID Conditional Access.
Support in designing the provisioning of Teams teams and SharePoint sites with higher compliance requirements.
Technical support for implementing information classification with sensitivity labels for SharePoint Online and Teams.
Technical support for the subproject introducing CoPilot for M365.
Skills: M365, Purview, DLP, Entra ID, Sensitivity Labels, CoPilot, Teams, SharePoint Online.
Rafael De Mestre Gebauer
Last position:
Project Lead Automation at Textile industry
Analysis and optimization of end-to-end processes in different business areas such as sales, procurement, order processing and logistics. Redesign of the ERP. Identification of optimization potential, especially in areas with media breaks and manual tasks, as well as creation of a prioritized transformation roadmap with clear business cases and implementation recommendations. Management of automation initiatives. RPA at the production site in China. Evaluation and introduction of relevant AI use cases as well as building basic AI competence in the organization. Training internal employees of the project team and supporting them in the transformation process to develop a continuous improvement culture. Close collaboration with IT and external implementation partners, reporting to senior management.
Main tasks and achievements:
- Analysis of business processes and design of automated processes
- Training and support for employees in China and Germany
- 20% cost savings in logistics
- Regular status reports to management
Halil Oeztoprak
Last position:
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe
Regulated environment within a German banking group (approx. 8,500 employees, hybrid cloud strategy).
Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big data/AI platform, and data science workspaces based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects for ShaiHulud and React2Shell, as well as BSI alerts – Security Operations improvements across the SDLC.
Deployment responsibility for the GenAI chat application, big data/AI platform (BDAI), and data science workspaces (AVD/VM-based) in the respective landing zones.
Deployment & release management: end-to-end responsibility for deploying portal and service applications across multiple Azure landing zones, including technical approvals, compliance with development team deployment guidelines, and ensuring ITIL-based change and release processes via ServiceNow.
Azure landing zones & network architecture: design, provisioning, and operation of Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration across separate subscriptions and tenants.
Azure DevOps governance & operations: ownership of the Azure DevOps organization, including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and audit-ready operating structures.
Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure deployment, including state management, provider versioning, reusability, and policy-as-code approaches.
CI/CD pipeline engineering: design, operation, and optimization of complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.
Git migration & platform consolidation: planning and execution of repository and pipeline migration from Azure DevOps to GitLab CI/CD, including automated scripts, full Git history transfer, pipeline porting, and platform consolidation.
Container & platform operations (AKS): operation and security assessment of containerized workloads on Azure Kubernetes Service, centralization of on-premises container registries for ACR.
OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters with critical applications, and derivation of specific hardening recommendations.
Shift-left security & DevSecOps transformation: introduction of a company-wide shift-left approach for early security integration in development and deployment processes, enabling developers to perform self-led security checks and sustainably reduce vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).
Software supply chain security: analysis and mitigation of supply chain risks in NPM- and Yarn-based applications through dependency audits, CI/CD pipeline hardening, token rotation, and restriction of risky build and lifecycle mechanisms.
Frontend & framework security (React / Next.js): security assessment and coordination of critical vulnerability remediation across platform applications and web frameworks, including coordination and complementary technical mitigations with all teams following BSI alerts.
Software composition analysis (SCA): introduction and operation of automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.
SAST/DAST integration: design and piloting of static and dynamic application security tests in close collaboration with security architecture and development teams, for continuous improvement of code and runtime security, and establishing operational acceptance tests.
Artifact & registry consolidation: analysis and consolidation of all package and container repositories for service applications and AKS workloads, aiming for a centralized, secured registry strategy with centralized vulnerability scanning and governance.
Dependency-Track & SBOM strategy: advising the compliance board on introducing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response capability.
CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, implementing least-privilege principles, and isolating build agent environments.
Azure Web Application Firewall (WAF) optimization: analysis and tuning of existing Azure WAF rules (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.
Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture overviews in Jira and Confluence, as well as active knowledge transfer between operations, development, security, and compliance stakeholders.
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Udo Neubauer
Last position:
Project Manager / Rollout Coordinator at BWI
Rollout of printers and PCs
- Effective management of external service providers to ensure smooth operations.
- Planning and implementation of a global rollout for 150,000 clients.
- Carrying out a comprehensive risk analysis, including overall risk, site-specific risks, and security risks.
- Successful consolidation of two existing ServiceNow systems to optimize service management.
- Close coordination with program management to achieve the project goals.
Thomas Nacke
Last position:
Interim Manager at Groupe SEB SA
- Interim project management for the “o9 demand management” software introduction
- Communication: building continuous stakeholder communication
- Project governance: planning and meetings for/with key users, including preparation of inputs from the software development team
- Leadership: leading and motivating key users
- Risk management: identifying potential risks and developing mitigation strategies
- Monitoring and control: tracking project performance, regular review of progress reports, status meetings
- Documentation: maintaining comprehensive project documentation, including training materials
- Running user information meetings
- Running training meetings
- Setting up the user community
- Software test control and documentation (Squash)
- Introducing risk management, bug and issue tracking
- Technical acceptance of the software product
Stefan Brutscher
Last position:
Evaluation and selection of an endpoint management platform at Liebherr
Evaluation and selection of a new endpoint management platform for an environment with around 50,000 clients. Support for a manufacturing company in evaluating a future endpoint management platform as a possible replacement for the existing client management solution. Conducting a structured software selection process including proof of concept as well as preparing the decision basis for the Enterprise Architecture Board (EAM). Defining the technical requirements and evaluation criteria and creating a short list of possible solutions (Tanium, Baramundi, Microsoft Intune / MECM). Planning and supporting the technical proof of concept as well as evaluating the architecture and operations aspects of the different platforms. In addition, evaluating tools for migrating existing software packages from the Ivanti DSM environment. Comparing and testing IDERI Move and PACE for the automated transfer of the existing package structure to the new platform, with the goal of significantly reducing migration effort. Support in selecting the required Tanium modules as well as preparing the decision documents for the Enterprise Architecture Board.
Tools: Tanium, Baramundi, Microsoft Intune, Microsoft MECM, Ivanti DSM, IDERI Move, Pace, Windows 10, Windows 11, Windows Server. VDI
Huy Nguyen
Last position:
Modern Workplace & Dynamics 365 Consultant at Thinformatics
- Administration and further development of the M365 environment including Teams, Exchange Online, Intune and SharePoint Online
- Development of dashboards for performance monitoring using Microsoft Power BI
- Implementation of user requirements and processes with low-code/no-code technologies (Power Apps, Power Automate)
- Use of Jira and Azure DevOps to plan and implement user stories in an agile project context
- Participation in daily stand-ups, sprint planning, sprint reviews and retrospectives as technical point of contact
- Planning and implementation of security policies using Azure Conditional Access and multi-factor authentication
- Configuration and deployment of clients and applications via MECM (SCCM) and Baramundi
George Ojog-Schulze
Last position:
IT Senior Consultant at Data Group
- IT Senior Consultant (bank infrastructure, Active Directory, Azure, security, PKI)
- Planning, design, and implementation of cloud solutions based on Microsoft Azure / M365
- Teams, M365, and cloud services
- Vulnerabilities, threats, attacks
- Security analysis, security policy, security architecture
- Conducting meetings and presentations at various management levels
- Organizing and leading team meetings to improve internal communication
- Tools: PowerShell, Active Directory, GPO, DNS, DHCP, scripting
Victor Omojoye
Last position:
AI Training Engineer at Confidential AI Research Client
- Codebase Evaluation & Problem Design: Designed and stress-tested complex software engineering problems against large open-source Python codebases (including pandas), requiring deep context acquisition and architectural understanding to produce well-scoped, realistic problem statements aligned to strict correctness guidelines.
- Agent Failure Analysis: Assessed LLM coding agent solutions for correctness and completeness, identifying meaningful failures across edge case handling, dtype behaviour, and multi-column NaN propagation logic; documented findings with precision for downstream evaluation use.
- Programmatic Test Suite Development: Authored comprehensive pytest suites to programmatically verify agent-generated solutions against defined requirements, with deliberate coverage of boundary conditions and failure modes not caught by naive implementations.
- Containerised Environment Engineering: Built and debugged Docker environments for reproducible agent execution, including git-based repository provisioning, dependency pinning with npm ci, and multi-stage Dockerfile authoring across Linux-based containers.
Mustafa Kablan
Last position:
Senior Consultant SCCM, SCOM, SCSM, SCVMM / Software packaging at LfSt - Bavarian State Office for Taxes
- Further development of the existing SCCM 2509 implementation
- Schema extension, CAS extension
- Creating task sequences, in-place upgrade
- Patch management (WSUS)
- Security updates, feature updates
- Emergency fixes, application updates
- Incident, change, and problem management (3rd level)
- Active Directory, DNS, DHCP, GPMC
- Managing users, groups, OUs, computers
- Setting up GPOs
- Senior consultant for software packaging in an SCCM 2509 environment
- Project management ITIL standards
- Defect management
- SIT (Software Integration Test)
- SAT (Software Acceptance Test)
- UAT (User Acceptance Test)
- Adjusting Windows 11 25H2 client deployment
- Secunet SINA management systems administrator
- Secunet SINA Workstation 3.5.4
- Maintenance and configuration work in SINA management
- Importing and adjusting IPsec policies
- Retrieving and documenting status, firmware versions, and configurations of individual SINA devices
- Consulting and implementation in fault and incident management
- Implementation of documentation and rollout of new software versions
- Creating software packages based on PowerShell App Deployment Toolkit, Flexera AdminStudio for the W11 64-bit platform and Server 2025 / 2022
- Number of PC systems: approx. 1,850.
Label: PowerShell, VBS, Batch scripting
Label: SCCM 2503, Windows 11 64 Bit, Windows 2025 Server, Windows 2022 Server, Windows 2019 Server
Michael März
Last position:
Team Lead / Service Owner 2nd Level & ITIL at Creditreform
- Service owner of the receivables management platform Ikarus
- Management and coordination of external 1st-level service providers
- Team leadership and building ITIL-compliant support structures
- Managing the handover to 3rd-level support (internal & external, incl. vendor/development)
- Stakeholder management between the business unit, IT, and external partners
- Jira ticket automations and maintenance of Confluence documentation
Alessandro Pisa Vazquez
Last position:
IT System Administrator – Client Deployment
- Main point of contact for the provisioning of end devices and operating systems
- Pre-installation of software according to company guidelines and integration into the corporate network (Wi-Fi, VPN, domain)
- User support with setup, process improvements, and handling of returns (RMAs)
Discover over 15,000 top freelancers
Statistics of experts using Microsoft Intune
Aggregated from the professional profiles of matched freelancers.
Experience
21 years
Position duration
2.2 years
Positions per freelancer
15
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Manufacturing, Banking and Finance
Certification focus areas
Information Technology, Project Management, Human Resources
Bachelor's degree or higher
61%
Master's degree or higher
28%
Doctorate
5%
Certifications per freelancer
6
Most common languages
German, English, Spanish
Speak two or more languages
93%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Microsoft Intune
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Device management
Microsoft Intune is used to control phones, tablets, and laptops from one place. It helps companies enroll devices, push settings, distribute apps, and keep work data separate from personal data. Experts working with Intune often support Windows, iOS, Android, and macOS fleets.
Security policies
Intune is often chosen with Microsoft Entra ID and Microsoft Defender for Endpoint to enforce access rules. Strong specialists know how to build compliance policies, app protection policies, and Conditional Access flows that fit real business use. They also understand when to block a device, when to warn, and when to allow limited access.
Typical work
- Set up device enrollment and onboarding
- Build policy baselines for managed devices
- Roll out company apps and updates
- Define compliance and access rules
- Troubleshoot failed enrollments or policy conflicts
When companies need help
Firms usually bring in Intune professionals during tenant setup, migration from Microsoft Endpoint Manager branding changes, or a rollout across mixed device types. They also need help when security teams and IT teams disagree on access rules, or when remote work makes manual support too slow. In Germany, this often matters for companies with office and field teams that use both company-owned and personal devices.
What good specialists do
A strong Intune expert does more than click through the portal. They document policy choices, keep scope clean, and test changes before broad rollout. They know Microsoft 365 identity basics, device compliance, app deployment, and the limits of each platform. Clear communication matters too, especially when policies must work for local teams in Germany and for remote users elsewhere.
Ecosystem and tools
Intune rarely stands alone. It is usually part of a wider Microsoft setup that may include Entra ID, Microsoft 365, Defender, Autopilot, and Windows Update for Business. Depending on the project, experts may also work with PowerShell, configuration profiles, security baselines, and reporting from the Intune admin center.
Frequently asked questions
Key details about Microsoft Intune, drawn from the questions we get asked most.
Microsoft Intune is used to manage devices, apps, and access rules from a central place. Companies use it to enroll endpoints, apply security settings, and protect business data on managed and personal devices. It is especially useful when teams work across Windows, iOS, Android, and macOS.
Intune is the product most people mean when they refer to Microsoft Endpoint Manager. Microsoft changed the branding, but the core service for device and app management stayed the same. Searchers often still use both names, so a good specialist should understand the old and new terminology.
Microsoft Intune is often strongest in Microsoft-centric environments, especially when Entra ID and Microsoft 365 are already in use. Jamf is usually discussed for Apple-first fleets, while Workspace ONE is another broader endpoint management option. The right choice depends on device mix, identity setup, and how tightly security policies need to connect.
A strong Microsoft Intune specialist usually knows Entra ID, Conditional Access, device compliance, app protection, and Windows management. PowerShell and Microsoft 365 administration are also common adjacent skills. For more complex work, experience with Autopilot, Defender for Endpoint, and reporting is valuable.
A small Intune setup may only need one specialist who can design enrollment, policy, and app deployment cleanly. Larger projects need someone who can handle device groups, policy conflicts, migration planning, and rollback decisions. The more device types and security requirements involved, the more important deep practical experience becomes.
Yes, Microsoft Intune is well suited to remote and hybrid work because devices can be enrolled and managed without a desk-side visit. That helps distributed teams in Germany and across other locations stay aligned on security and app access. A good implementation also considers language, support hours, and local IT processes.
A strong Microsoft Intune professional explains trade-offs clearly and can show how policies were tested before release. Look for clean documentation, structured naming, and evidence that they understand real device behavior, not just portal settings. Good candidates also ask about identity, device mix, and support ownership before they propose a design.
Common Intune requests include failed enrollment, app deployment issues, compliance policies that block too much, and device groups that do not reflect the business. Companies also ask for help with migration, tenant cleanup, and reducing help desk load. A reliable specialist should be able to diagnose these issues without making the environment harder to manage.
The average hourly rate of freelancers in Germany who have used Microsoft Intune in their recent projects is 95 €, which corresponds to a daily rate of about 758 € based on an 8-hour working day.
Of the freelancers in Germany who have used Microsoft Intune in their recent projects, 61% hold at least a Bachelor's degree, 28% hold at least a Master's degree, and 5% hold a doctorate.
On average, freelancers in Germany who have used Microsoft Intune in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers in Germany who have used Microsoft Intune in their recent projects are German (99%), English (91%), and Spanish (16%).
The most common industries among freelancers in Germany who have used Microsoft Intune in their recent projects are Information Technology (96%), Manufacturing (64%), and Banking and Finance (58%).
The most common business areas among freelancers in Germany who have used Microsoft Intune in their recent projects are Information Technology (99%), Project Management (79%), and Operations (78%).
Main locations of FRATCH Experts, who have recently used Microsoft Intune
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Frankfurt