Your Intune, in a repo.
Repolicy manages Microsoft Intune policies as code across many customer tenants. Git is the source of truth. Repolicy renders, diffs, approves, and orchestrates every change so you run Modern Workplace operations with control, repeatability, and less manual work.
Intune at MSP scale is hard to control
Running Modern Workplace for many customers means the same policy, tenant by tenant, by hand. That is slow, risky, and drifts out of sync.
Intune changes are hard to standardize across many tenants without creating drift and inconsistency.
Small policy updates become risky when they are made tenant by tenant, by hand.
MSPs need strong change control, and a way to roll out improvements quickly from a single golden baseline.
How it works
From admin consent to a safe ring-by-ring rollout, in four steps.
-
Step 1
Connect each customer tenant
A one-time admin consent link connects the tenant. Repolicy imports the existing policies into the repo.
-
Step 2
Use GitHub as the source of truth
Policies live in the customer's GitHub repo, where change control happens through PRs or in-portal approval.
-
Step 3
Plan every change before it applies
Repolicy compares desired state to the live tenant, shows the diff, and posts the plan as a PR check run.
-
Step 4
Approve and roll out safely
Apply ring by ring, from pilot to broad, while Repolicy keeps policies in sync and detects drift nightly.
Key capabilities
Everything you need to run Intune like code.
Policies as code, many tenants
Manage Microsoft Intune policies as code across multiple customer tenants from one control plane.
Baselines plus overrides
Golden baselines with per-tenant overrides for scalable, repeatable policy management.
Plan and apply
Terraform-style plan and apply with live tenant diffs shown before anything executes.
Nightly drift detection
Detect drift nightly, then one-click revert the tenant to code or adopt the drift into a PR.
GitHub integration
PR checks, PRs on drift adoption, and review-based control keep Git the source of truth.
Safety controls
Repolicy only touches the policies it manages, gated by server-side allowlists.
Built for MSPs
Repolicy gives MSPs one operational model for many customers. Update one golden policy, approve the change once, and roll it out consistently across tenants. Protect customer environments with strict guardrails, preserve clear auditability through GitHub, and cut the time spent on manual Intune maintenance.
Supported today: compliance policies, configuration profiles, Settings Catalog, and app protection policies. More is coming.
- Baselines MSP-wide golden policies, defined once and shared across every customer.
- Per-tenant overrides Effective policy computed per tenant, so customer-specific deviations stay clean.
- Rings Roll out from pilot to broad, ring by ring, with a plan before each stage.
- Multi-tenant One portal across all customer tenants, each connected by admin consent.
Secure by design
Repolicy manages only the policies it created, writes nothing without a planned diff and an approval, and can apply only what a server-side allowlist permits.
Marker safety model
Every managed policy carries a Repolicy marker. Policies you created by hand carry no marker and are never updated or deleted.
Apply allowlists
Server-side kind and name-prefix allowlists gate every apply. Out of the box only test-named policies can be written.
Approval gates
Apply is only possible on an approved plan. Nothing is written blind, and stale plans cannot be approved.
Azure Key Vault
All secrets live in Azure Key Vault and are read via managed identity. No secrets in source, chat, or images.
EU data residency
Compute runs on Azure Container Apps in North Europe; the application database is in Sweden Central.
Least-privilege Graph
App-only Graph roles for the four supported policy kinds. No directory write, user management, mail, or delegated access.
Ready to manage Intune like code?
See how Repolicy helps your MSP standardize, control, and scale Microsoft Intune delivery.