Intune & Device Management
10 checks · 2 sub-categories
Access controls only hold if the device on the other end is trustworthy. This section covers whether the phones and laptops reaching your email are encrypted, patched, managed and capable of being wiped when they're lost or the staff member leaves.
Device compliance
Compliance policies defined and assigned
Checks for policies requiring encryption, a minimum OS version, a screen lock and jailbreak/root detection — and whether they're actually assigned to anyone.
BitLocker / FileVault encryption enforced
An unencrypted stolen laptop with a cached mailbox is a notifiable data breach on its own.
- Privacy Act / NDB
- ACSC ISM — media encryption
Operating system patch compliance
Reports devices behind on OS updates and how far behind they are.
- Essential Eight — Patch operating systems
Application patch compliance
Covers browsers, Office and other high-risk applications on managed devices.
- Essential Eight — Patch applications
Conditional Access tied to device compliance
A compliance policy that doesn't gate access is a report, not a control. We confirm the two are joined up.
Enrolment and BYOD
Enrolment restrictions
Which platforms and ownership types can enrol, and whether personal devices can join unchecked.
App protection (MAM) policies for personal devices
Keeps company mail and files in a protected container on BYOD phones so they can be wiped without touching personal data.
Remote wipe capability verified
Confirms you can actually wipe company data from a lost device today, not in theory.
Unmanaged devices accessing company data
Lists devices with active Microsoft 365 sessions that are not enrolled in any management at all.
Offboarding process for departing staff devices
Whether device access is revoked as part of offboarding, or only the password is changed.
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.