← Microsoft 365 audit scope

Intune & Device Management

10 checks · 2 sub-categories

Access controls only hold if the device on the other end is trustworthy. This section covers whether the phones and laptops reaching your email are encrypted, patched, managed and capable of being wiped when they're lost or the staff member leaves.

Device compliance

  • Compliance policies defined and assigned

    Checks for policies requiring encryption, a minimum OS version, a screen lock and jailbreak/root detection — and whether they're actually assigned to anyone.

  • BitLocker / FileVault encryption enforced

    An unencrypted stolen laptop with a cached mailbox is a notifiable data breach on its own.

    • Privacy Act / NDB
    • ACSC ISM — media encryption
  • Operating system patch compliance

    Reports devices behind on OS updates and how far behind they are.

    • Essential Eight — Patch operating systems
  • Application patch compliance

    Covers browsers, Office and other high-risk applications on managed devices.

    • Essential Eight — Patch applications
  • Conditional Access tied to device compliance

    A compliance policy that doesn't gate access is a report, not a control. We confirm the two are joined up.

Enrolment and BYOD

  • Enrolment restrictions

    Which platforms and ownership types can enrol, and whether personal devices can join unchecked.

  • App protection (MAM) policies for personal devices

    Keeps company mail and files in a protected container on BYOD phones so they can be wiped without touching personal data.

  • Remote wipe capability verified

    Confirms you can actually wipe company data from a lost device today, not in theory.

  • Unmanaged devices accessing company data

    Lists devices with active Microsoft 365 sessions that are not enrolled in any management at all.

  • Offboarding process for departing staff devices

    Whether device access is revoked as part of offboarding, or only the password is changed.

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.