Anyone who has been using Matrix42 Empirum for years usually knows the environment down to the last detail: software packages have evolved, processes are well-established, and many workflows are tailored to the existing infrastructure. This is precisely why switching to Microsoft Intune is more than just replacing an endpoint management solution.
The real question is: which existing structures should you keep – and where does it make sense to consciously rethink things?
Key takeaways
- Intune does not automatically replace Matrix42 Empirum on a 1:1 basis: Before migrating, you should evaluate which processes need to be adopted, simplified, or redesigned.
- Software packaging and patch management are major drivers of effort: Clean up your software catalog and use automation for standard software where it makes sense.
- Co-management can ease the transition: Empirum, Intune, and potentially SCCM or baramundi can be operated in parallel for a time before legacy structures are decommissioned.
- Clarify your target state and licensing early on: Determine which functions will run via Intune in the future and which Microsoft licenses or add-on solutions you actually need for them.
1. Why switch from Matrix42 Empirum to Microsoft Intune?
Matrix42 Empirum is traditionally strong in on-premises-oriented client management scenarios. Microsoft Intune, by contrast, takes a cloud-based approach to Unified Endpoint Management.
Switching can be particularly attractive if you want to manage your devices increasingly independently of the corporate network and make greater use of your existing Microsoft environment.
Typical reasons for a migration include:
- Centralized management of Windows, macOS, iOS, Android, and Linux devices via Intune
- Greater integration with Microsoft Entra ID and Microsoft 365
- Cloud-native deployment of new devices with Windows Autopilot
- Compliance policies and Conditional Access
- Reduced reliance on your own endpoint management infrastructure
- Consolidation of existing management and security solutions
The latter point is also reflected in our own data: many companies use an upcoming migration not just for a technology change, but also for consolidation.
In our State of Endpoint Study it becomes clear that 61% of organizations with concrete migration plans intend to consolidate multiple existing UEM solutions onto a single central platform within the next twelve months. Microsoft Intune was most frequently cited as the target system.
SOFTTAILOR is already supporting this exact scenario in practice. For a national social services provider, Matrix42 Empirum was replaced by Intune in a cloud-only scenario. In addition to the Intune implementation, the project included configuration profiles, security baselines, Autopilot, system hardening and software packaging.
SOFTTAILOR frequently advises former Matrix42 Empirum customers on selecting the right alternative to the Matrix PackageCloud: Patch My PC for Intune and/or SCCM, or Robopack for Intune. For packages not included in the new third-party patch management catalog, we handle the migration of Matrix42 Empirum software packages to Intune or baramundi software packages.
There are also advantages regarding licensing: Microsoft Intune Plan 1 is included in Microsoft 365 E3 and E5, among others. Additional features can be added via further Intune licenses or the Intune Suite depending on the required scope. Since June 2026, however, core features of the Intune Suite have already been integrated into E3 and E5. Before you plan for additional licenses, it is worth taking a close look at which features are already included in your existing Microsoft setup.
2. What needs to be migrated from Matrix42 to Intune?
A Matrix42 to Intune migration involves much more than just the devices themselves. During your inventory assessment, you should cover at least the following areas:
Existing configurations should not be replicated without review. Policies and GPOs that were created years ago for local client managementstructures may no longer make sense in a cloud-native scenario.
This also applies to your server landscape. The servers on which Empirum itself is operated can be gradually decommissioned after a successful migration. However, if you also manage Windows Servers via Empirum, you will need a separate solution such as the baramundi Management Suite. Intune is primarily designed for managing clients and mobile devices and cannot manage servers.
3. Straight to Intune or start with co-management?
A migration does not have to be a big bang event. Especially in larger Empirum environments, it can make sense to use Matrix42 and Intune in parallel for a limited period. This allows you to transition individual functions and device groups step by step.
Which tasks each system handles and when the remaining Empirum workloads should be shut down should, of course, be clearly defined in advance.
Matrix42 itself distinguishes between "Classic," "Modern," and "Co-Managed." Devices are considered co-managed if they are managed via both the classic Empirum agent layer and a modern management layer such as Intune.
Intune can already take over policies, security settings, or new cloud-native processes, while certain software packages continue to be distributed via the Empirum agent for the time being.
This can be particularly useful if you have a large or complex software catalog and do not want to migrate it entirely before the initial Intune rollout.
4. Software packages and patch management: the crux of the migration
The migration of software packages from Matrix42 Empirum to Intune is often one of the most time-consuming parts of the project.
Empirum packages cannot simply be exported and then imported into Intune unchanged. Therefore, the goal should not be to replicate every existing process exactly.
Instead, it is worth cleaning up the software catalog before the migration. Some applications are often no longer needed at all.
Important for patch management: The number of necessary patches is rising, while the window of time for rolling them out is shrinking. The current Claude myth illustrates just how significantly AI can accelerate this trend: Modern AI models can uncover vulnerabilities on a large scale, forcing manufacturers to react faster and more frequently. At the same time, AI also helps attackers analyze and exploit published vulnerabilities more quickly.
Anyone who continues to package, test, and update a large software inventory primarily by hand will quickly reach their limits. Automation is becoming an essential requirement in patch management to keep pace with the speed of new releases and security updates.
For standard software, solutions like Patch My PC or Robopack can handle a large portion of this work. They are designed for deploying and updating applications via Microsoft Intune, reducing the manual effort required for packaging and recurring updates. By the way: the equivalent add-on for baramundi is called Managed Software.
However, such a catalog is not always sufficient for custom business applications, proprietary installers, or complex installation logic. These applications often still need to be packaged, tested, and rolled out individually for Intune.
Migrating to Intune is therefore a good opportunity to do more than just transfer existing Empirum packages. You should simultaneously determine which applications can be automated in the future and where custom packaging remains necessary. This allows you to create a software and patch process that remains scalable even with shorter release and patch cycles.
By the way, we recommend migrating Matrix42 Empirum packages to PSADT. This has the advantage, among others, that packages are created independently of the distribution solution and can be deployed via different systems, or do not need to be completely repackaged in the event of another migration of the endpoint management solution.
5. How a Matrix42 to Intune migration works
A proven migration process can be broken down into eight compact steps:
- Analyze the Empirum environment: devices, software packages, policies, servers, dependencies, and existing processes.
- Define the target Intune state: Determine what will be managed via Intune in the future and what may be managed via other systems.
- Check licensing: Evaluate existing Microsoft 365 licenses, required Intune features, and potential additional licenses.
- Prepare Intune: Configure Entra ID, groups, roles, configuration profiles, compliance, and security.
- Migrate software catalog: Remove unnecessary packages, automate standard software, and repackage custom applications for Intune.
- Migrate pilot group: Test enrollment, software, policies, security, and user experience using representative devices.
- Execute rollout in waves: Transition additional devices to Intune in a controlled manner and use co-management temporarily if needed.
- Decommission Empirum: Only once all relevant functions have been migrated and tested, decommission agents, infrastructure, and redundant servers in a controlled manner.
This process also illustrates why individual work packages cannot be viewed in isolation. Software packaging, policies, enrollment, and co-management are directly intertwined. If, for example, applications are migrated only shortly before the rollout or if there is a lack of clear responsibilities between Empirum and Intune, unnecessary dependencies and delays quickly arise.
It is therefore crucial to define the target state early on and then implement the migration in controlled waves. This allows you to test new Intune processes in a production environment while Empirum remains in place temporarily for functions that have not yet been migrated. The old infrastructure should only be decommissioned once all relevant workloads are running reliably via the new setup.
6. Conclusion: Don't just replace Matrix42 with Intune
A successful migration from Matrix42 Empirum to Microsoft Intune is not about replicating your existing environment in the cloud as precisely as possible.
The greater value lies in using the transition as an opportunity to rethink your existing processes: Which software still needs to be packaged individually? Which applications can be managed automatically by Patch My PC or Robopack? Which systems still require their own management outside of Intune? And which existing infrastructure can actually be eliminated after the migration?
Once these questions are resolved before the rollout, a simple product migration transforms into a future-proof endpoint management strategy.
SOFTTAILOR supports you throughout the process, from analysis and planning to migrating Matrix42 Empirum software packages through to the setup and ongoing operation of Microsoft Intune. You can find more information on our page about UEM solution migration.














