Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Confirm which devices meet policy-and which do not.

Compliance policy only protects what it can see. The review maps enrollment coverage, policy strictness, and what actually happens to a device that fails a check.

Start from enrollment, not from policy design.

A well-designed compliance policy has no effect on a device that never enrolled. The review establishes which platforms and ownership types are actually inside Intune before judging the rules themselves.

Platform coverage

Compare Windows, iOS/iPadOS, Android, and macOS enrollment against the devices the organization actually issues or permits.

Ownership model

Separate corporate-owned, BYOD, and unmanaged personal devices, since each supports a different compliance and privacy boundary.

Enrollment method

Confirm whether automatic enrollment, user-driven enrollment, or manual registration is the deployed path, and where it can be skipped.

Read compliance policy as a real gate, not a label.

A policy can exist and still not block access anywhere. Compliance settings only function as a control when Conditional Access actually requires them.

Policy settings

Review encryption, minimum OS version, jailbreak/root detection, and password requirements against what the organization intends to require.

Conditional Access linkage

Confirm whether sign-in actually depends on compliance status, or whether the policy is evaluated without consequence.

Grace periods

Check compliance grace periods and retire actions so a device is not silently trusted during an extended non-compliant window.

Decide what happens to a non-compliant device.

A device marked non-compliant does not automatically lose access, notify anyone, or get remediated. The review traces the actual consequence.

Access consequence

Confirm whether non-compliance blocks mail, SharePoint, Teams, or other resources, or only appears in a report.

Owner notification

Check whether the device user or an administrator is actually notified when status changes.

Remediation path

Document how a user restores compliance and how long an exception can persist before review.

Connect compliance evidence to licensing and support reality.

Compliance requirements should match what the organization can support and licence, not a generic best-practice template.

Licence dependency

Confirm which compliance and Intune capabilities the current Microsoft 365 or EMS licence actually includes.

Support capacity

Match policy strictness to the support model available for exceptions, lost devices, and legitimate older hardware.

Decision record

Record which settings are enforced, which are monitored only, and why-so the next reviewer inherits reasoning, not just a policy export.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.