The News
Recast, a vendor specializing in endpoint management tooling built on top of Microsoft’s stack, released its State of Intune in 2026 survey, drawing on responses from 890 IT professionals across North America, Europe, Latin America, the Middle East, Africa, and Asia-Pacific. The survey finds that while 81% of respondents report satisfaction with Microsoft Intune and 83% feel confident troubleshooting it, the operational reality remains grinding: 65% spend six to fifteen hours weekly on manual tasks including packaging, patching, troubleshooting, and reporting. Hybrid environments running both Intune and Microsoft Configuration Manager (ConfigMgr) remain the dominant model at 62%, with fully Intune-based environments representing just 15% of respondents.
Analyst Take
Satisfaction without relief is a product opportunity, not a success metric
The headline number here is not the 81% satisfaction score. Vendor satisfaction surveys routinely produce results like that, and Intune has earned genuine market trust over years of investment from Microsoft. The more telling number is that 65% of these satisfied users are still spending between six and fifteen hours every week on manual work. That’s not a platform problem; it’s an automation gap. IT teams have accepted Intune as their management plane while simultaneously accepting a workload that reflects an earlier, more manual era of endpoint operations. Recast, whose business is built on extending Intune and ConfigMgr with automation and remediation capabilities, has a clear commercial interest in surfacing this gap. That doesn’t make the finding wrong. It makes it worth taking seriously.
The engineering time problem runs deeper than endpoint management alone. ECI Research’s 2026 Application Development survey found that 65.2% of respondents selected “0–20” when asked what percentage of engineering time is spent on net-new innovation. That number applies broadly to software engineering teams, but it maps directly onto the IT operations reality Recast is describing: the majority of technical capacity is consumed by maintenance, compliance, and keeping things running, not by advancing capabilities. Application packaging and patching are unglamorous examples of exactly that dynamic.
The “messy middle” is not a transitional state
The framing of hybrid ConfigMgr-plus-Intune environments as a “messy middle” implies that organizations are moving through it toward a cleaner destination. The survey data suggests otherwise. More than half of respondents currently using ConfigMgr alone or in a hybrid model say they have no plans or no timeline to retire ConfigMgr. That’s not a migration in progress; that’s a permanent operating model. For ITDMs, this matters because it reshapes how to think about tooling investment. If hybrid is the long-term state, the right question is not “when do we finish the migration?” but “how do we operate efficiently across two platforms indefinitely?” Vendors that frame their value around migration completion are selling to a shrinking audience. Vendors that build for durable hybrid operations are selling to the majority.
For developers and platform engineers, the practical implication is architectural. Win32 application packaging, which 49% of organizations still handle manually, is not a legacy artifact waiting to be replaced by modern deployment methods. It persists because the enterprise application estate is heterogeneous and the cost of repackaging at scale is high. Automation that works within that constraint, rather than requiring organizations to first rationalize their application portfolios, has a more realistic path to adoption.
Where AI-generated risk enters the picture
The survey flags a “concerning rise in AI-driven application vulnerabilities” as context for why patching discipline matters more than ever. This connects to a broader security trend worth quantifying. According to ECI Research’s 2026 Application Development: DevSecOps & AppSec survey, 29.1% of respondents identified AI-generated package risk as their biggest open-source security concern in 2026. Third-party patching, which ranked as the second-largest Intune challenge at 33% of respondents, is exactly the surface area where AI-generated or AI-assisted malicious packages would land. The intersection of slow manual patching workflows and accelerating AI-driven threat vectors is a genuine risk amplifier, and it gives IT leaders a sharper business case for automation investment than operational efficiency alone can provide.
Looking Ahead
The endpoint management market is consolidating around Microsoft’s cloud-native stack, but the timeline for that consolidation is far longer than the vendor ecosystem has historically assumed. Recast’s survey data, combined with broader ECI Research findings on engineering time allocation, points toward a durable market for tooling that extends and automates within hybrid environments rather than betting on their rapid obsolescence. Microsoft will continue to invest in Intune’s native capabilities, but the gap between platform functionality and operational efficiency at scale is wide enough to sustain a meaningful independent tooling market for several more years.
The more urgent near-term dynamic is the convergence of manual patching workflows and AI-accelerated threat surfaces. Organizations that have normalized slow or reactive third-party patching cycles will face increasing pressure from security teams and regulators as AI-generated vulnerabilities become more common and harder to detect through traditional scanning. IT leaders who treat patching automation as a cost-reduction exercise are underpricing the risk. Those who frame it as a security control will find it easier to fund and faster to prioritize.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
