Does Microsoft Intune Work in China? The 21Vianet Sovereign Environment, Device-Data Residency & Cross-Border
Microsoft Intune is available in mainland China — but through a separate, physically separated environment, Intune operated by 21Vianet (世纪互联), run inside the country on its own datacenters, with a narrower feature set than the global service. The real decision for a China device fleet isn't speed — it's data residency: enroll China devices into a global Intune tenant and the device inventory, identifiers, enrolled-user identity and management data rest in Microsoft geographies outside China (North America, Europe, Asia Pacific), a PIPL cross-border transfer, while the data-resident lawful path is the 21Vianet-operated China environment. A compliance-first look at the two services, the cross-border and residency questions, Cybersecurity Law Article 39 (formerly Article 37), and the lawful in-country path.
Does Microsoft Intune work in China?
Yes — Microsoft Intune is available in mainland China, but through a separate, physically separated environment: "Intune operated by 21Vianet" (世纪互联), not the global service most tenants sign in to. Microsoft documents it as a physically separated instance located in China, operated by 21Vianet from local datacenters that keep your data within China — with a narrower feature set than global Intune.
Because a lawful in-country environment exists, the real decision is data residency, not speed. Intune holds a register of your devices and the people who carry them — hardware and OS inventory, device identifiers, the enrolled user's identity, installed-app lists and compliance state, nearly all of it personal information under Chinese law. Enroll China devices into a global tenant and Microsoft documents only three geographies — North America, Europe and Asia Pacific, none of them mainland China — so that record rests offshore, a PIPL cross-border transfer (and, for a CII operator, a residency problem under Cybersecurity Law Article 39 (formerly Article 37)); larger or sensitive transfers can add a CAC data-export security assessment. A tenant's geography is fixed when its Microsoft Entra directory is created and can't be changed later, so moving onto the data-resident 21Vianet environment is a migration, not a toggle — and its feature parity is something you confirm with Microsoft and 21Vianet.
21YunBox maps the environment choice, localizes your endpoint management onto the data-resident China path, and delivers the China-facing apps and portals your managed devices reach in-country on ICP-filed infrastructure — so it runs legally in the mainland, with no circumvention of any kind. Treat the specifics as a risk to confirm with counsel.
What Microsoft Intune's own documentation says about China
| Fact | Primary source |
|---|---|
| Intune runs in China through a China-specific environment operated by 21Vianet. Microsoft's documentation states that “21Vianet operates, provides, and manages delivery of the service” and that, “by licensing Microsoft technologies, 21Vianet operates local datacenters to provide you with the ability to use Intune service while keeping your data within China.” It is a distinct China environment, not the global service. | Microsoft Learn — Intune operated by 21Vianet in China (learn.microsoft.com), updated 2025-10-16, retrieved 2026-10-09 |
| The China environment is a physically separated instance with a narrower feature set. Microsoft states it is “a physically separated instance of cloud services located in China,” and that “because the China services are operated by a partner from inside China, there are some feature differences with Intune” — it “only supports standalone deployments,” the “tenant attach” feature and “Derived Credentials aren't supported,” and “Migrations from public clouds to sovereign clouds aren't supported,” so parity must be confirmed per workload. | Microsoft Learn — Intune operated by 21Vianet in China (learn.microsoft.com), updated 2025-10-16, retrieved 2026-10-09 |
| On the global service, Intune's data geographies don't include mainland China. Microsoft states it “offers and operates Intune services in three major geographic regions” — North America, Europe and Asia Pacific — with no mainland-China geography, and that a tenant's Customer Data “is hosted in the geography that best aligns with the country/region value in its Microsoft Entra directory,” a value that “can't be modified later.” So a global tenant's China device data rests offshore. | Microsoft Learn — Intune Data Storage and Processing Overview (learn.microsoft.com), updated 2026-05-05, retrieved 2026-10-09 |
| Using an offshore tenant for China device data is a cross-border transfer. Sending the device inventory, identifiers and enrolled-user identity of China devices to an Intune tenant hosted outside the mainland triggers PIPL Chapter III (Articles 38–43): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — with in-country storage under Article 40 (and Cybersecurity Law Article 39, formerly Article 37) for CII operators. | Personal Information Protection Law of the PRC, Chapter III, Articles 38–43 (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For an organization managing the phones, laptops and tablets its people carry in mainland China, the first question about Microsoft Intune isn’t whether the admin console loads or how quickly a policy reaches a device — it is which Intune you are running. Microsoft operates two separate things that matter here: the global Intune service most tenants sign in to, and a distinct, physically separated China environment — Intune operated by 21Vianet (世纪互联) — run inside the mainland by a licensed local operator, on its own datacenters, with the management data kept in-country. So the honest answer to “does Microsoft Intune work in China?” is yes — but through a specific environment, on a specific legal footing, and with a feature set you have to check against what you actually use.
Because a lawful in-country option already exists, the decision moves off the speed axis and onto a data one. Intune keeps a register of an organization’s devices and the people who hold them — hardware and OS inventory, serial numbers and device identifiers, the enrolled user’s identity, installed-app lists, compliance state, and in some configurations device location — and nearly all of it is personal information under Chinese law. Enroll China devices into a global Intune tenant and that record rests in Microsoft’s datacenters outside the mainland, which is a cross-border transfer under PIPL; run them in the 21Vianet-operated China environment and Microsoft’s own documentation says the data is kept within China. Which environment you deploy, and how you deliver the apps and portals your managed devices actually reach, is the compliance question — not the sync speed.
Microsoft Intune in China at a glance
| What decides it | In Microsoft's own terms — and China's law |
|---|---|
| What it is | Microsoft Intune — cloud mobile-device and app management (MDM/MAM): it enrolls phones, laptops and tablets, pushes configuration, compliance policy and apps, and keeps an inventory of each device and the user behind it. Two separate services matter for China: the global Intune service, and a distinct China environment, Intune operated by 21Vianet (世纪互联), run inside the mainland. |
| Is it available in the mainland? | Yes — through the separate, physically separated China environment. Microsoft documents "Intune operated by 21Vianet" as a physically separated instance located in China, operated by 21Vianet, with its own standalone deployment and sign-up. The global service is a different deployment and is not connected to it. |
| Where the management data lives | On the 21Vianet-operated China environment, Microsoft says your data is kept within China. On the global service, Microsoft documents only three geographies — North America, Europe and Asia Pacific — none of them mainland China (Hong Kong SAR is listed, but it is not the mainland), so device inventory, identifiers, the enrolled user and management data for your China devices sit offshore. |
| Cross-border & residency | Enrolling China devices into an offshore tenant is a cross-border transfer under PIPL (Articles 38–43: notice, a separate consent, one transfer mechanism). For a critical information infrastructure operator, in-country storage is required under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37); larger-volume or sensitive transfers can add a CAC data-export security assessment. |
| The lawful path | Deploy in the 21Vianet-operated China environment (or otherwise keep management data in-country), and deliver the China-facing apps, portals and intranets your managed devices reach on ICP-filed, in-country infrastructure. 21YunBox maps the environment choice, localizes your endpoint management onto the data-resident path, and delivers it in-country — subject to the China environment's availability and feature parity, which you confirm with Microsoft and 21Vianet. |
Availability: a distinct China environment, operated by 21Vianet
Intune’s presence in the mainland is set in Microsoft’s own documentation, not by a load-time test of the admin console. The page for Intune operated by 21Vianet states that it is “a physically separated instance of cloud services located in China,” that “Microsoft doesn’t operate the service itself” — “21Vianet operates, provides, and manages delivery of the service” — and that, “by licensing Microsoft technologies, 21Vianet operates local datacenters to provide you with the ability to use Intune service while keeping your data within China.” This is a sovereign cloud: run inside the mainland by a licensed local operator, physically separate from the global service, with the management data kept in-country.
But Microsoft is equally plain that the environment is not a mirror of global Intune. “Because the China services are operated by a partner from inside China, there are some feature differences with Intune,” the same page says — and the list is substantial. Intune operated by 21Vianet “only supports standalone deployments”; the “tenant attach” feature and “Derived Credentials aren’t supported”; “Migrations from public clouds to sovereign clouds aren’t supported,” so a move from the global cloud is done by hand; Windows Autopilot is limited to Device Preparation; Endpoint Analytics and Log Analytics aren’t currently available; and because Google Mobile Services isn’t available in China, Android capabilities that depend on it — managing apps from the Google Play Store, Play Protect, Android Enterprise — aren’t available, with some tasks delayed. So which workloads and controls you depend on are offered in the China environment is something to confirm directly with Microsoft and 21Vianet before you commit. For that reason this page publishes no first-party China latency figure for Intune: a lawful in-country environment already exists, so speed is not the axis the decision turns on.
The cross-border-data story: device inventory, identifiers and the enrolled user are personal information
The gate that actually decides an Intune deployment for China is the data, not the dashboard. Device inventory is a list of who in your organization carries which hardware; the enrolled identity ties each device to a named employee; installed-app lists, compliance state and, in some configurations, device location round out a detailed picture of people and their equipment. Almost all of it is personal information under China’s Personal Information Protection Law, and some of it — precise location, for instance — can be sensitive. Served from a global Intune tenant, that record rests in Microsoft’s datacenters outside the mainland, and putting it there is a cross-border transfer. PIPL places the duty on the handler — you, not Microsoft: Chapter III (Articles 38–43) requires notice, a separate consent distinct from the employee’s agreement to enroll a device, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
Two structural facts make this hard to wave away. First, Microsoft documents only three Intune geographies — North America, Europe and Asia Pacific — and none is mainland China; a tenant’s geography “is set as part of the Microsoft Entra directory creation process and can’t be modified later,” so an existing global tenant cannot simply switch on a China region. Second, residency bites underneath the transfer: a critical information infrastructure operator or large-volume handler must store personal information collected in China inside the mainland — PIPL Article 40, together with Cybersecurity Law Article 39 (formerly Article 37), the data-localization provision renumbered by the 2025 amendment that took effect on January 1, 2026, its substance unchanged — an obligation an offshore tenant structurally cannot meet. And where data volumes or sensitivity cross the thresholds, the transfer itself can require a CAC data-export security assessment before it may proceed. How heavy each of these is scales with your data and your role, so treat it as a risk to confirm with counsel against what you actually enroll — not a default assumption.
The data-resident path: the 21Vianet-operated China environment
The lawful, in-country footing is the one Microsoft already documents: the 21Vianet-operated China environment, where — in Microsoft’s words — your data is kept within China. On that path the cross-border question does not arise in the same way, because the management data does not leave the mainland. The work is to plan the deployment onto it. Because the China environment is a separate, standalone sign-up rather than a region of a global tenant — and because “Migrations from public clouds to sovereign clouds aren’t supported” — there is no switch-over flag; devices, policies and identities are stood up there and enrolled fresh, or migrated by hand. And because Microsoft names concrete feature gaps, the first step is an availability-and-parity check: confirming that the capabilities your fleet relies on — the enrollment methods, the Autopilot path, derived credentials, tenant attach, the Android management model, Mobile Threat Defense connectors and any Jamf integration — are offered in the China environment as you need them. That check is not a formality; it is what tells you whether the data-resident path carries your deployment as-is or needs a redesign.
The lawful path — map, localize, deliver
There is a compliant way to manage a China device fleet with Intune, and its shape is clear: the management data stays in-country in the 21Vianet-operated environment, and the China-facing apps and portals your managed devices sign into are themselves delivered compliantly inside the mainland. That second half is easy to miss. A line-of-business app pushed to enrolled phones, a staff intranet, or a customer portal that your managed devices reach is a public-facing service in China, so it carries an ICP filing (备案) duty and needs compliant in-country delivery like any other mainland property — a fleet whose policies are perfectly resident but whose apps hang off an unfiled, offshore front end has solved only half the problem.
That is the footing 21YunBox owns, and it is more than advice. Our China team works three jobs on it. We map which Intune you should be running and the PIPL, residency and licensing exposure that attaches to the device and identity data you collect, so the obligations are visible before you build. We localize your endpoint management onto the data-resident path — standing up and integrating the 21Vianet-operated China environment, or otherwise keeping the management data in-country, in place of an offshore tenant that cannot meet the residency duty. And we deliver the China-facing apps and portals your managed devices reach in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is an Intune deployment that runs legally and compliantly for your users in China. What we do not do is route anyone around anyone’s terms or around China’s network controls: this is a lawful in-country deployment built on the environment Microsoft and 21Vianet already provide, and we neither use nor suggest circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — Article 39 (formerly Article 37) and data localization
- China’s data-export security assessment measures
- How to get an ICP filing for China
