Microsoft Intune Experts in Munich
in minutes from 15,000 CVs with the power of AIHire experts who manage Microsoft Intune device enrolment, app protection, compliance policies, and endpoint security for Windows, macOS, iOS, and Android. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used Microsoft Intune
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Thomas Nacke
Last position:
Interim Manager at Groupe SEB SA
- Interim project management for the “o9 demand management” software introduction
- Communication: building continuous stakeholder communication
- Project governance: planning and meetings for/with key users, including preparation of inputs from the software development team
- Leadership: leading and motivating key users
- Risk management: identifying potential risks and developing mitigation strategies
- Monitoring and control: tracking project performance, regular review of progress reports, status meetings
- Documentation: maintaining comprehensive project documentation, including training materials
- Running user information meetings
- Running training meetings
- Setting up the user community
- Software test control and documentation (Squash)
- Introducing risk management, bug and issue tracking
- Technical acceptance of the software product
Konstantinos Metaxas
Last position:
IT-Fly Specialist – Global Rollout at Lufthansa Group
Plan & Prepare (Site Design & Readiness): Inventory & Design: Dell PowerEdge R-Series, Aruba switches (L2/L3), notebooks/peripherals; serials/asset tags, IPv4/IPv6 addressing, VLAN-/DHCP-/DNS plan
Runbooks/MOPs: site rollout runbook, backout strategy (<15–30 min), risk register, communication matrix; approvals via CAB/change
Images/Packages: Golden Image (Win10/11), driver packs, BIOS/UEFI baseline; O365/Teams/OneDrive KFM; BitLocker policies; MECM/SCCM, Intune/Autopilot, MDT/WinPE
Logistics: shipping/customs clearance, RMA/DOA, on-site spares; tools (barcode scanner, label printer), "Go-Bag" (cables, SFPs, console cables)
Deliver (on-site implementation): End devices: swap & migration (USMT/OneDrive KFM), peripherals (ATB/BT printers, scanners, boarding gate hardware); domain join, compliance checks, O365 activation, printers/queues, network drives
Acceptance: functional tests for DCS/CUTE/CUPPS/CUSS stations, ticketing/check-in workflows, boarding gates
Server (R-Series): rack & stack, cabling (PDU redundancy, fiber/copper), labeling/naming; firmware/RAID (PERC), Lifecycle Controller, iDRAC network; Windows Server 2022/2025 + CIS/BSI hardening; agents (backup/AV/EDR/monitoring), time service/NTP auth, Syslog/SNMPv3
Network (Aruba): VLANs, LACP trunks, MSTP root; PortFast + BPDU Guard at the edge; QoS (EF/AF); dual stack (v4/v6), DHCP relay. NAC/802.1X with ClearPass/Radius/TACACS+, roles + MAB fallback; guest isolation, ACLs (Guest→Mgmt deny). Telemetry: sFlow, SNMPv3, Syslog→SIEM; LLDP→inventory/CMDB
Airport specifics: CUTE/CUPPS/CUSS terminals; DCS/Amadeus/SITA connectivity; FIDS (read-only); bag tag/boarding pass printing; changes in off-peak/night windows
Stabilize (hypercare): first-day support, KPI tracking (login times, ticket volume, error classes), QoS fine-tuning
Troubleshooting: Wireshark/iperf, event logs, switch counters, sFlow flows; fast incident handling as SPOC
Knowledge transfer: short training sessions for station teams, mini-runbooks (fault/recovery)
Close (documentation & handover): docs & CMDB: final configs (switch/server), topology/patch plans, IP tables, serial/asset lists, before/after photos
Acceptance & sign-off: UAT protocols, functional evidence (use cases), return/reuse of old hardware
Lessons learned: risks, standard packages, driver freeze, "known issues"
Interfaces/communication: station IT, airport IT, SOC/NOC, ground ops/ramp/check-in, provider (SITA/Amadeus). ITSM: ServiceNow (Inc/Req/Change/KB), handover to BAU
Michael Møller
Last position:
Freelance Senior Consultant & Cloud Architect at Rheinmetall AG
- Specialized in designing and implementing robust, secure cloud solutions for critical client infrastructure.
- Expertise in Microsoft Intune environment with a strong focus on system hardening and comprehensive policy management.
- Architected NIST and ISO/IEC 27000 compliant Mobile Device Management (MDM) infrastructure tailored for an international government defense aerospace project.
- Performed an architectural role for an offline Microsoft Endpoint Configuration Manager (MECM) environment, ensuring NIST compliance while handling complex manufacturing infrastructure.
Philipp Schmidt
Last position:
MS365 Consultant/Solution Architect at Self-employed
- Setup and configuration of an M365 tenant on a hybrid basis
- SSO integration of the existing app infrastructure like Metamost, Huhu, etc.
- License consulting, Entra ID initial configuration, MFA, Conditional Access, Privileged Identity Management
- Intune: initial configuration, Windows 11 Autopilot, iPhone AES
- Takeover of the tenant and preparation of a security audit
- Rollout of iPhones with AES (formerly DEP) as COPE (Corporate Owned, Business Enabled)
- Connecting external customers with enhanced security through Conditional Access
- Consulting on cloud-first strategy and migration to a cloud-only business
- Connecting various apps via SSO/SCIM (e.g. Atlassian, Personio, Adobe)
- On-premises AD: security audit and project management for replacing the local AD (migration of file servers, Navision2016, user clients joined to Entra ID)
- Copilot rollout with connection to external data sources and configuration via Intune
- Support for TISAX and ISO27001 preparation
- Setup and hardening of Entra ID, switching MFA to phishing resistant via Conditional Access
- Intune management for Windows and Apple clients, web enrollment switch to AES, introduction of Autopilot, app management, integration of Microsoft Defender
- Building a device baseline for Windows (COBO) and iOS/Android (BYOD)
- Teams/SharePoint Online: access concepts and integration into Teams
- Maintenance and backup of Entra ID and Intune tenants (drift management)
- M365 backup with Veeam
- Extending Conditional Access policies, introduction of Privileged Identity Management with hardware tokens and an on-premises admin tier concept
- Revision of existing GPOs regarding structure, security, and compliance
- Security audit and hardening of on-premises Active Directory and cloud tenant, SAML VPN, PIM introduction
- Support for the HR department in introducing a booking portal and general system engineering administration & security
- Introduction of Conditional Access and passwordless MFA, platform SSO, Defender for macOS/iOS, macOS compliance with Intune, Code2 signature configuration
Dmytro Grekov
Last position:
Retraining (IT Specialist System Integration) at Comcave
Discover over 15,000 top freelancers
Statistics of experts using Microsoft Intune
Aggregated from the professional profiles of matched freelancers.
Experience
28 years (Germany: 21 years)
Position duration
1 years (Germany: 2.2 years)
Positions per freelancer
17 (Germany: 15)
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Manufacturing, Banking and Finance
Certification focus areas
Information Technology, Project Management, Business Intelligence
Bachelor's degree or higher
33% (Germany: 61%)
Master's degree or higher
33% (Germany: 28%)
Certifications per freelancer
6
Most common languages
English, German, French
Speak two or more languages
100% (Germany: 93%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using Microsoft Intune
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Device control
Microsoft Intune is used to manage company devices, apps, and security settings from one place. It supports Windows, macOS, iOS, and Android, and it is common in Microsoft 365 environments. Strong specialists design policies that balance control and daily usability.
What it covers
- Device enrolment and profile setup
- Compliance rules and conditional access
- App deployment and app protection
- Update rings and device configuration
- Remote wipe, lock, and support flows
It is often paired with Microsoft Entra ID, Defender, and Endpoint security baselines. That mix helps companies standardize access and protect work data across owned and personal devices.
When specialists help
Companies bring in freelance expertise when they roll out Intune for the first time, clean up an old tenant, or move from another device management tool. The work often includes policy design, migration planning, and fixing conflicts between security rules and business use.
Strong specialist skills
A good professional understands policy scope, platform limits, and how settings interact across device groups. They can read logs, test enrolment flows, and troubleshoot why a device is non-compliant or an app is blocked. In Munich, this often matters for distributed teams that need clear remote support and solid documentation.
Ecosystem and tools
Microsoft Intune rarely stands alone.
- Microsoft Entra ID for identity and access
- Microsoft Defender for endpoint protection
- Windows Autopilot for device provisioning
- Apple Business Manager and Android Enterprise for enrolment
- PowerShell and Graph API for automation
Specialists who know these parts can build cleaner, easier to support environments.
Typical delivery work
Intune freelancers are often asked to define naming standards, build configuration and compliance profiles, and document support steps for the service desk. They also help with app packaging, certificate issues, and secure rollout plans for new offices or remote teams. Strong work leaves a setup that is easy to operate after the project ends.
Frequently asked questions
Questions about Microsoft Intune? Start with the answers below.
Microsoft Intune is used to manage devices, apps, and security settings across a company fleet. It helps teams control enrolment, compliance, and app protection on Windows, macOS, iOS, and Android. Companies use it to keep work data secure without making devices hard to use.
Intune is the current Microsoft product name, and many people still use the older term Endpoint Manager when they talk about the same management area. It is an MDM and MAM tool, so it can manage both full devices and protected apps. That makes it more flexible than tools that only cover one of those layers.
A strong Microsoft Intune specialist should know Entra ID, compliance policies, app protection, and device enrolment across major operating systems. Practical experience with Windows Autopilot, Apple Business Manager, Android Enterprise, and PowerShell is a strong sign. Good troubleshooting and clear documentation matter just as much as policy design.
For a small policy change, an experienced Microsoft Intune professional may be enough. For a tenant migration, a new rollout, or a complex security design, you need someone who has handled enrolment, access rules, and app deployment before. The more endpoints and operating systems you have, the more project context matters.
Microsoft Intune is cloud-based and is often chosen for modern device management and security policy control. SCCM is stronger in traditional Windows infrastructure scenarios, while Jamf is focused on Apple device management. Many companies use Intune when they want one service for mixed-device environments inside Microsoft 365.
Most Microsoft Intune work can be done remotely because it centers on tenant configuration, policy testing, and documentation. On-site time in Munich can help during rollout workshops, stakeholder sessions, or device handover phases. For many projects, a hybrid setup works well.
Microsoft Intune projects often run into conflicts between compliance rules, app protection settings, and user experience. Common issues include enrolment failures, profile conflicts, and access being blocked by the wrong condition. A careful specialist tests each policy path before broad release.
Look for clear examples of tenant design, policy structure, and issue resolution in Intune projects. Good specialists explain trade-offs, document what they changed, and leave a setup that your team can support. They should also be comfortable working with Microsoft 365, identity, and endpoint security teams.
The average hourly rate of freelancers in Munich, Germany who have used Microsoft Intune in their recent projects is 95 €, which corresponds to a daily rate of about 759 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used Microsoft Intune in their recent projects, 33% hold at least a Bachelor's degree and 33% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used Microsoft Intune in their recent projects have 28 years of professional experience, with a single engagement typically lasting around 1 year.
The most common languages among freelancers in Munich, Germany who have used Microsoft Intune in their recent projects are English (100%), German (83%), and French (67%).
The most common industries among freelancers in Munich, Germany who have used Microsoft Intune in their recent projects are Information Technology (100%), Manufacturing (100%), and Banking and Finance (83%).
The most common business areas among freelancers in Munich, Germany who have used Microsoft Intune in their recent projects are Information Technology (100%), Operations (100%), and Project Management (100%).
Main locations of FRATCH Experts, who have recently used Microsoft Intune
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Frankfurt