How to Configure Device Policies in Microsoft 365 Business Premium
Question details
The administrator needs to configure device restrictions and screen saver policies for users upgraded to Microsoft 365 Business Premium, and is seeking guidance on Microsoft Defender device configuration.

- Product
- Microsoft 365 Business Premium
- Device & OS
- not provided
- Scenario
- Setting up organization-wide device management rules and endpoint security after upgrading users from F1 licenses to Business Premium.
- Observed behavior
- Seeking the correct administrative tools and license capabilities to deploy device restrictions, screen saver timeouts, and Defender configurations.
Verify that all targeted users have been successfully assigned the Microsoft 365 Business Premium license, and ensure you have Intune Administrator or Global Administrator privileges before creating policies.
Configure Device Policies Using Microsoft Intune
Use the Microsoft Intune service, which is included with Microsoft 365 Business Premium, to deploy screen saver rules and general device restrictions.
Microsoft 365 Business Premium includes comprehensive mobile device management (MDM) through Microsoft Intune. You can use configuration profiles in the Intune admin center to push specific settings, like screen saver timeouts and feature restrictions, directly to enrolled Windows devices.
Sign in to the Microsoft Endpoint Manager admin center (Intune) using your administrator credentials.
Navigate to Devices > Configuration profiles and click on 'Create profile'.
Choose 'Windows 10 and later' as the platform. Select 'Templates' and choose 'Administrative templates' (for screen saver settings) or 'Device restrictions'.
Search for 'Screen saver' in the settings picker to define the timeout duration and enforce the lock screen, then configure any additional device restrictions required.
In the assignments tab, select the specific user groups that have been upgraded to the Business Premium license to apply the policy.

Manage Microsoft Defender for Endpoint Configurations
Determine your licensing scope for Microsoft Defender and access the correct portal for endpoint configuration and device discovery.
Need a fast, cost-effective office suite for your team?
While you use Microsoft 365 Business Premium for robust device management, you might want a lightweight, reliable alternative for document editing on secondary devices or for contractors. WPS Office offers a complete, budget-friendly solution with zero learning curve.
- 1. Visit the WPS website: Go to the official WPS Office website to find the free installer.
- 2. Download and install: Download the version compatible with your operating system and follow the setup wizard.
- 3. Start editing: Open WPS Office and instantly access, edit, or create your essential documents without a premium subscription.

Frequently Asked Questions
Can I assign Intune policies to users with Microsoft 365 F1 licenses?
No. Microsoft 365 F1 licenses do not include Intune mobile device management (MDM) rights. Users must be licensed with Microsoft 365 Business Premium or another Intune-inclusive license to receive device configuration policies.
Is Microsoft Defender for Endpoint included in Business Premium?
Microsoft 365 Business Premium includes Microsoft Defender for Business, which offers enterprise-grade endpoint protection tailored for small and medium-sized businesses. Advanced enterprise capabilities of Defender for Endpoint (Plan 1 or Plan 2) may require a separate standalone license.
Where do I configure a screen saver password requirement in Intune?
In the Microsoft Endpoint Manager admin center, create a Device Configuration Profile using 'Administrative templates'. Under User Configuration or Computer Configuration, search for 'Password protect the screen saver' and set it to Enabled.




