Join our Newsletter — 33% off our NHI Course

Co-Management

Co-management is a dual-management model where Intune and Configuration Manager control the same Windows endpoints at the same time. It lets organisations divide workloads between cloud and on-premises tooling so they can modernize gradually while preserving legacy application dependencies and endpoint controls that still require traditional Microsoft infrastructure.

What Co-Management Actually Is

Co-management is a transitional endpoint-management operating model, not a product feature by itself. It matters because the same Windows device can be governed by two management planes at once, so policy ownership, workload assignment, and device state must be understood as shared rather than exclusive.

That shared-control model is what makes co-management useful during modernization, but it also means the term is about operational governance as much as tooling. The core question is which management authority owns compliance, security baselines, application delivery, updates, and user experience at any given stage of the rollout.

How Co-Management Works in Practice

In a co-managed environment, Intune and Configuration Manager each handle selected workloads for the same endpoint. One workload might remain anchored in on-premises configuration because of legacy application dependencies, while another shifts to cloud-based policy or update management where the organisation is ready to move.

This division lets teams modernize incrementally instead of forcing a hard cutover. It is especially useful when the endpoint estate includes mixed readiness levels, because the model preserves existing operational controls while enabling gradual adoption of cloud management capabilities.

For this reason, co-management should be read as a control-splitting model: it defines where authoritative decisions are made, how changes are staged, and which management plane is trusted for each workload. The practical value comes from reducing migration risk while avoiding a brittle all-or-nothing endpoint strategy.

Why Co-Management Matters for Endpoint Security

Co-management changes the security conversation from “which tool do we use?” to “which control owns which outcome?” That distinction matters because conflicting policies, inconsistent baselines, or overlapping configuration sources can create drift across the same endpoint if ownership is not clearly assigned.

It also affects visibility. If one platform manages compliance while another manages deployment or remediation, defenders need a coherent view of the endpoint state or they can miss gaps between the two control planes. In mature environments, co-management is valuable precisely because it can preserve strong legacy controls while extending cloud governance, but only when the split is deliberate.

Used poorly, the model can leave teams with partial enforcement, unclear accountability, or duplicated effort. Used well, it becomes a controlled migration path that reduces disruption without weakening endpoint governance.

Common Misunderstandings About Co-Management

A common mistake is to treat co-management as simple duplication, as if both platforms should do the same thing. In reality, the model works best when workloads are intentionally divided so that one system owns a given control area and the other complements it rather than competing with it.

Another misunderstanding is assuming that moving to co-management automatically modernizes the environment. The model only creates value when the organisation also defines workload boundaries, evaluates legacy dependencies, and decides which endpoint controls remain on-premises versus which move to the cloud.

That makes co-management a governance decision as much as a technical one. The endpoints stay the same, but the operating model changes, and that is where most implementation mistakes occur.

Risk and Threat Considerations

Co-management introduces risk when the split between Intune and Configuration Manager is unclear, inconsistent, or poorly monitored. The main concern is not the concept itself, but the possibility of control gaps, conflicting policy enforcement, or drift between the two management planes.

Failure mechanism: A workload may be assumed to be governed by one platform while effective enforcement still depends on the other, creating blind spots in compliance, configuration, or remediation.

Impact: The organisation can end up with inconsistent endpoint posture, delayed security changes, or incomplete enforcement across a shared device estate, which weakens confidence in the endpoint control model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Co-management hinges on limiting which platform owns which endpoint workload.
CM-2 — Baseline Configuration Co-managed endpoints still need a defined configuration baseline across both tools.
CM-8 — System Component Inventory Co-management depends on knowing which endpoints and workloads are under each control plane.
Recommendation — Assign each management plane only the workload controls it must administer. Define and maintain approved endpoint baselines for both management planes. Maintain an accurate inventory of co-managed devices and their workload owners.
CIS Controls v8 CIS-4 — Secure Configuration of Enterprise Assets and Software Co-management is a configuration-governance model for enterprise endpoints.
Recommendation — Standardize endpoint configurations and track drift across both management systems.
NIST CSF 2.0 GV.PO-01 — Policies, processes, and procedures Co-management requires explicit policy decisions about workload ownership and authority.
Recommendation — Document which platform owns each endpoint workload and how changes are approved.

Practitioner Guidance

Governance implication: Treat workload ownership as a first-class design decision, not an implementation detail. Co-management works best when each endpoint control area has a clear authority, a known source of truth, and an explicit migration path.

Common misunderstanding: Do not assume that enabling co-management means the environment is automatically more secure or more modern. The security outcome depends on how precisely the organisation assigns workloads and monitors the overlap between the two systems.