TL;DR: Agent-based endpoint management lets IT teams inventory, patch, deploy software to, script, and remediate devices without depending on the corporate LAN or a VPN connection. That means operational management can continue as endpoints move between office, home, field, and other networks. Moving those workflows online does not require a full Intune migration, and organizations can still use Intune where they need Microsoft-focused enrollment, policy, Conditional Access, or MDM capabilities.
IT teams can manage most operational endpoint workflows over the internet without migrating everything into Microsoft Intune. Agent-based endpoint management handles inventory, patching, software deployment, scripting, and remediation whenever devices are online, and no VPN tunnel is required. Intune may still make sense for enrollment, compliance policy, and Conditional Access integration, but those are separate architectural decisions.
In other words, "we need to manage devices over the internet" and "we need to migrate to Intune" are not the same sentence — even if they tend to arrive in the same meeting.
What changes when endpoint management moves off the corporate network?
Traditional endpoint management often assumes network reachability between your management system and the device. That assumption breaks down fast when laptops leave the building.
Dependencies you might not think about until they fail:
Corporate LAN access for network scans
VPN connectivity for patch delivery
Local management servers for software distribution
Internal repositories for package hosting
Devices regularly returning to the office
Consider the laptop that's in the office Monday, at a home desk Tuesday, in an airport Wednesday, and won't touch the corporate network again for three weeks. Your responsibility for that endpoint doesn't change when its network does, but your ability to manage it might.
If routine endpoint management only works while a device is reachable through the corporate network or VPN, network location has become part of your management workflow. Internet-based management removes that dependency for supported operations.
This is not an argument that VPNs are obsolete. They still serve legitimate purposes. But building your entire patching and deployment strategy around "device must VPN in first" creates friction that compounds across a distributed workforce.
How does internet-based endpoint management work?
Internet-based endpoint management combines a cloud-hosted management service with an agent installed on each endpoint. The agent communicates with the service over the internet, letting IT receive device information and push management actions without requiring direct corporate network connectivity.
The basic workflow:
Install or provision the endpoint agent during imaging or onboarding.
The endpoint checks in over the internet on its regular schedule.
The platform collects inventory and current device state.
IT identifies or groups devices based on relevant attributes.
IT initiates a management action — patch, deployment, script, remediation.
The endpoint receives the action on its next check-in (or immediately, depending on platform).
The endpoint performs the action.
Results return to the management console.
IT verifies success or queues additional remediation.
Depending on the platform, internet-based actions can include hardware and software inventory, OS patching, third-party patching, software deployment, script execution, automation rules, vulnerability remediation, and remote troubleshooting.
According to PDQ's 2026 State of Sysadmin report, 51% of sysadmins say timely security patch implementation takes up too much time. Internet-based management won't eliminate that work, but it does remove the "waiting for devices to connect to the network" bottleneck that makes patching feel like herding cats.
What can IT manage over the internet without a VPN?
An agent-based endpoint management platform can perform supported management actions over the endpoint's regular internet connection. The device doesn't need to establish a VPN connection before IT can inventory it, patch it, deploy software to it, run a script on it, or troubleshoot it.
High-level capabilities that work without VPN dependency include pushing Windows or macOS patches; updating third-party applications such as Chrome and Zoom; deploying new applications; pushing internal tools, scripts, or configurations; running PowerShell, Bash, or custom scripts remotely; identifying exposed devices and pushing fixes; keeping hardware and software inventory current; and connecting to devices for diagnostics without VPN tunneling.
Practical scenarios where this matters:
The employee working from home indefinitely
The laptop that visits the office once a quarter
The field technician whose device never sees the corporate network
The traveling executive who's always one version behind on everything.
The architecture handles all of these the same way: agent checks in, IT pushes action, device executes, results come back.
How do you manage endpoints that move between office and remote networks?
The management workflow should follow the endpoint instead of changing every time the endpoint changes networks.
Internet-based management lets IT use the same operational workflow whether a device is on corporate LAN, home Wi-Fi, a branch office network, hotel Wi-Fi, a client site, or a coffee shop with questionable network hygiene. The agent doesn't care where the packets are coming from; it just needs to reach the management service.
This consistency matters because managing devices in a hybrid workplace means your fleet is constantly in motion. According to PDQ's research, 65% of organizations expect to be hybrid or cloud-only within five years. That's the new baseline, not just a temporary state to wait out.
Management groups and automations can target devices based on attributes that actually matter:
Operating system and version
Installed applications and versions
Patch state and missing updates
Vulnerability exposure
Department or device type
Custom tags based on your environment
None of those attributes depend on physical location. The endpoint doesn't require a different management workflow just because someone worked from the patio today.
One caveat: Public Wi-Fi and the corporate network do not have identical security characteristics. The point is that supported endpoint management operations can continue across those network transitions without rebuilding your approach for each scenario.
What can IT manage without an on-site endpoint management server?
A cloud-hosted endpoint management platform can handle most operational workflows without maintaining local management infrastructure:
Endpoint inventory and hardware/software data
Patch management for OS and third-party applications
Software deployment and removal
Scripts and automation rules
Vulnerability identification and remediation
Device status and health monitoring
Deployment results and reporting
Remote troubleshooting and access
But there's an important distinction. "No on-site endpoint management server" does not mean "no servers anywhere." Organizations may still operate directory services, application servers, file services, certificate infrastructure, and internal line-of-business applications. This section is specifically about removing the requirement for local endpoint management infrastructure, the WSUS box, the SCCM server, or the on-prem deployment console.
For teams without dedicated server infrastructure or IT staff to maintain it, cloud-hosted endpoint management removes a maintenance burden. For larger teams, it's one less thing to patch, back up, and troubleshoot at 2 a.m.
Do you need to migrate these endpoint workflows into Intune?
No. Moving operational endpoint management onto the internet does not inherently require migrating those workflows into Intune.
Intune is one way to manage internet-connected endpoints. Agent-based endpoint management platforms are another. The choice is not binary.
An organization might:
Use Intune alone for everything
Use a different internet-based endpoint management platform
Use Intune for enrollment and compliance plus another platform for operational management
Maintain a mixed environment based on specific requirements
The key insight is that "we need to manage devices over the internet" and "we need to migrate to Intune" are related but separate decisions. You can solve the first problem without committing to the second.
When does Intune still make sense?
Intune remains relevant when organizations need Microsoft-focused capabilities, such as device enrollment with Autopilot and enrollment profiles, configuration profiles for policy and settings, compliance policies, Conditional Access integration, mobile device management for iOS and Android, mobile application management for personal devices, and integration with Defender, Entra ID, and other Microsoft security services.
Internet-based operational endpoint management and Microsoft device management are related decisions, but they are not the same decision. Organizations can use Intune and PDQ together, letting each platform handle what it does best.
How do you maintain visibility into internet-connected endpoints?
Visibility follows the same agent-based loop as management actions:
Endpoint checks in over the internet.
Inventory and state data update in the console.
IT identifies exceptions — outdated software, missing patches, vulnerabilities.
IT takes action.
Results return to the console.
IT verifies remediation.
Useful signals for remote endpoint health and compliance include online status, last check-in time, hardware inventory, installed applications and versions, patch status, vulnerability exposure, deployment results, and reboot state.
One terminology note: "Compliance" in this context means operational compliance — checking whether devices meet your defined patch, software, or configuration conditions. That's not the same as regulatory compliance or Microsoft's compliance policy framework. Different problems, sometimes overlapping solutions.
What makes an endpoint management platform work well over the internet?
The strongest fit depends on your operating systems, management needs, Microsoft environment, existing infrastructure, and team capacity. Certain architecture characteristics matter for internet-first management:
A persistent endpoint agent that maintains communication without requiring VPN connectivity
A cloud-hosted console so management does not depend on reaching an on-prem server
Current off-network inventory so device data stays fresh when devices roam
Internet-based patch and software delivery with no dependency on internal distribution points
Remote scripting to run commands on devices wherever they are
Automation rules to define conditions and let the platform handle routine actions
Clear deployment results so you know what succeeded, what failed, and why
Offline-device handling to queue actions for devices that aren't currently online
Remote troubleshooting to connect to devices for diagnostics without additional VPN setup
Each criterion matters because hybrid environments don't wait for network conditions to align. If your management platform needs the stars to align before it can push a patch, you'll spend more time waiting than managing.
How does internet-based endpoint management work with PDQ?
Here's how the architecture works in practice with PDQ:
A managed endpoint has the PDQ agent installed during imaging or enrollment.
The employee leaves the corporate network, works from home, travels, or similar.
The endpoint continues communicating with PDQ over the internet.
IT maintains visibility into device inventory, installed software, and patch state.
IT identifies an outdated application, missing patch, or vulnerability.
IT sends the appropriate deployment, patch, script, or remediation action.
The endpoint performs the action while internet-connected.
Results return to PDQ.
IT verifies the outcome.
The endpoint can move between office, home, field, and other networks without requiring a different operational workflow.
PDQ supports patching remote devices and deploying software to remote devices through this same agent-based model. Vulnerability remediation, scripting, automation, and remote troubleshooting all work over the internet connection.
Organizations can still use Intune for enrollment, Conditional Access, and compliance policy while using PDQ for the operational patching, deployment, and remediation work. Different tools, different jobs, same endpoints.
If you're managing endpoints that rarely see the office, PDQ handles that without requiring you to rebuild your entire management stack.
Manage Windows & macOS devices from anywhere
With PDQ Connect, get real-time visibility into remote and local devices, deploy software, remediate vulnerabilities, automate routine maintenance, and remotely troubleshoot endpoints from one easy-to-use platform.


