Set up an Intune sandbox tenant
For an Intune online course you need your own Intune sandbox tenant: a Microsoft tenant where you can safely try devices, policies and apps. Microsoft currently documents a time-limited Intune trial. Availability, eligibility, and terms can vary by account and region, so verify the current Microsoft sign-up flow. Alternatively, you can license your own lab environment, which remains available while the subscription is active.
Important up front
- Never use a production company tenant for practice - set up your own sandbox.
- You need a new work or school account (not a personal Microsoft account like outlook.com).
- A credit card is only used for verification - the trial charges nothing.
- Trial tenants are time-limited; Microsoft shows the current duration during sign-up.
Option A - Intune trial (recommended)
The fastest route. You get an Enterprise Mobility + Security (EMS) subscription with Microsoft Entra ID P1/P2 and Intune ↗ for the trial duration currently offered by Microsoft.
- 1
Open the sign-up page
Open the Intune trial sign-up page ↗ and enter an email address. Choose “Set up account” to create a new tenant.
- 2
Create the account & tenant
Enter name, phone number, company name (any label, e.g. “Lab Smith”) and region. Choose a user name and an
…onmicrosoft.comdomain - this becomes your tenant. - 3
Verify & finish
Confirm the phone number with the code and register a payment method for verification only (no charge). Your tenant is then live.
- 4
Sign in to the Intune admin center
Sign in at intune.microsoft.com ↗ with your new account. Note: admin sign-ins require multi-factor authentication - set it up on first login.
- 5
Check the MDM authority
Under Tenant administration the MDM authority should be set to Microsoft Intune (default for new trials).
Official Microsoft guide: Sign up for the Intune trial ↗.
Option B - Microsoft 365 Developer Program
A renewable developer tenant with Microsoft 365 E5 (incl. Intune and 25 test users). Ideal if you want to practise longer. Note: joining the programme is subject to eligibility requirements (e.g. an active Visual Studio subscription) and can change.
- 1
Open the programme page
Go to the Microsoft 365 Developer Program ↗ and sign up. Check the current eligibility rules there.
- 2
Set up the developer tenant
Create your E5 sandbox tenant and set up test users. Intune is included in E5.
- 3
Open Intune
Sign in at intune.microsoft.com ↗ and start with the exercises.
Option C - Your own permanently licensed lab environment
For companies and private learners who can budget for the ongoing cost, a dedicated tenant is a reliable alternative to a time-limited trial. The environment remains available while the subscription is active and does not depend on Developer Program eligibility.
Which licence covers which labs?
- Intune Plan 1, lowest-cost baseline: €6.90 before VAT per user/month with annual billing in Germany. It supports hands-on practice with core device and app management, enrolment, configuration and compliance policies, app deployment, update rings, and basic reporting. It does not include Entra ID P1, risk-based Conditional Access, or the Intune Suite advanced capabilities.
- Intune Plan 1 + Entra ID P1, focused lab combination: €13.00 before VAT per user/month with annual billing in Germany (€6.90 + €6.10). This adds dynamic groups, automatic MDM enrolment, and standard Conditional Access. Risk-based policies using user or sign-in risk require Entra ID P2. Windows, Microsoft 365 apps, and Defender for Business are not included in this combination.
- Microsoft 365 Business Premium, recommended for apprentice and core labs: €19.06 before VAT per user/month with annual billing or €22.87 before VAT with monthly billing in Germany. It includes Intune Plan 1, Entra ID P1, and Defender for Business, among other services. This is the simplest single licence for the foundations scope including standard Conditional Access, but it does not cover every advanced-course module, risk-based Conditional Access, or every specialist scenario.
- Advanced course / Intune Suite: Business Premium alone is not enough. Depending on the lab, Intune Plan 2 (€3.50) or an individual add-on is required, such as Remote Help (€3.00), Endpoint Privilege Management (€2.60), Advanced Analytics (€4.30), Enterprise Application Management (€1.73), or Cloud PKI (€1.73), each before VAT per user/month with annual billing in Germany and in addition to Plan 1. Alternatively, each capability can be trialled once per tenant for 90 days. Since July 2026, Microsoft 365 E3/E5 plans include selected advanced capabilities; verify the exact entitlement in the tenant first.
Visible does not automatically mean licensed or fully testable: an administrator may see parts of the portal without holding an Intune licence. Every user who directly or indirectly benefits from the service must still be licensed. One licence can be enough for a solo learner, but an end-to-end Remote Help session needs a licensed helper and a licensed user. Autopilot, Apple scenarios, Tunnel for MAM, and similar labs also need suitable devices, operating systems, or external infrastructure; a Microsoft licence alone does not make them testable end to end.
How to verify the tenant's actual scope: under Tenant administration > Tenant status, check the Intune licence count and MDM authority. Check products assigned to a user in the Microsoft 365 admin center. Review advanced capabilities under Tenant administration > Intune add-ons > Capabilities. For reliable hands-on evidence, then complete the relevant lab with a licensed test user and all required devices.
Current official details: Business and Entra pricing ↗, Intune plans and add-ons ↗ and Intune licensing ↗.
Practice recommendations
- For the Windows exercises (Autopilot, configuration), a test VM with Windows 11 Pro/Enterprise is useful - you can enrol and reset devices safely.
- What is Intune? Read up front “What is Microsoft Intune?” ↗ or check our reference.
- When your trial ends, check Microsoft’s current options before setting up another sandbox tenant.