logo
search
Others

How to Configure Device Policies in Microsoft 365 Business Premium

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 869 views

Question details

The administrator needs to configure device restrictions and screen saver policies for users upgraded to Microsoft 365 Business Premium, and is seeking guidance on Microsoft Defender device configuration.

How to Configure Device Policies with Microsoft 365 Business Premium
Product
Microsoft 365 Business Premium
Device & OS
not provided
Scenario
Setting up organization-wide device management rules and endpoint security after upgrading users from F1 licenses to Business Premium.
Observed behavior
Seeking the correct administrative tools and license capabilities to deploy device restrictions, screen saver timeouts, and Defender configurations.
Before you start

Verify that all targeted users have been successfully assigned the Microsoft 365 Business Premium license, and ensure you have Intune Administrator or Global Administrator privileges before creating policies.

Solution 1Recommended

Configure Device Policies Using Microsoft Intune

Use the Microsoft Intune service, which is included with Microsoft 365 Business Premium, to deploy screen saver rules and general device restrictions.

Microsoft 365 Business Premium includes comprehensive mobile device management (MDM) through Microsoft Intune. You can use configuration profiles in the Intune admin center to push specific settings, like screen saver timeouts and feature restrictions, directly to enrolled Windows devices.

1
Access the Endpoint Manager

Sign in to the Microsoft Endpoint Manager admin center (Intune) using your administrator credentials.

2
Create a new configuration profile

Navigate to Devices > Configuration profiles and click on 'Create profile'.

3
Select platform and profile type

Choose 'Windows 10 and later' as the platform. Select 'Templates' and choose 'Administrative templates' (for screen saver settings) or 'Device restrictions'.

4
Configure the specific settings

Search for 'Screen saver' in the settings picker to define the timeout duration and enforce the lock screen, then configure any additional device restrictions required.

5
Assign the policy

In the assignments tab, select the specific user groups that have been upgraded to the Business Premium license to apply the policy.

Configure Device Policies Using Microsoft Intune
Policy Syncing: After assignment, it may take up to 8 hours for devices to automatically sync and apply the new policies, though users can manually sync their devices from the Windows Settings app.
Free Microsoft Office alternative

Need a fast, cost-effective office suite for your team?

While you use Microsoft 365 Business Premium for robust device management, you might want a lightweight, reliable alternative for document editing on secondary devices or for contractors. WPS Office offers a complete, budget-friendly solution with zero learning curve.

  1. 1. Visit the WPS website: Go to the official WPS Office website to find the free installer.
  2. 2. Download and install: Download the version compatible with your operating system and follow the setup wizard.
  3. 3. Start editing: Open WPS Office and instantly access, edit, or create your essential documents without a premium subscription.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formatsLightweight architecture that runs smoothly on low-spec hardwareFree to download and use for essential daily office tasksFamiliar tabbed user interface for seamless migration
microsoft office alternative - wps office

Frequently Asked Questions

Can I assign Intune policies to users with Microsoft 365 F1 licenses?

No. Microsoft 365 F1 licenses do not include Intune mobile device management (MDM) rights. Users must be licensed with Microsoft 365 Business Premium or another Intune-inclusive license to receive device configuration policies.

Is Microsoft Defender for Endpoint included in Business Premium?

Microsoft 365 Business Premium includes Microsoft Defender for Business, which offers enterprise-grade endpoint protection tailored for small and medium-sized businesses. Advanced enterprise capabilities of Defender for Endpoint (Plan 1 or Plan 2) may require a separate standalone license.

Where do I configure a screen saver password requirement in Intune?

In the Microsoft Endpoint Manager admin center, create a Device Configuration Profile using 'Administrative templates'. Under User Configuration or Computer Configuration, search for 'Password protect the screen saver' and set it to Enabled.