DEV — Device Management
Device compliance and management controls. 18 controls in total — 17 automatic, 1 attested.
How to read
Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.
| Control | What it checks | Result criteria | Status |
|---|---|---|---|
DEV-01 Intune device compliance rate L1 | Checks how well enrolled devices comply with security policies. A noncompliant device leaves an open door. | ✅ 90% or higher · ⚠️ 70–89% · ❌ Below 70% | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-02 Noncompliant device count L2 | Checks how many devices fail security policy. Every noncompliant device is a policy breach and a risk. | ✅ None (0) · ⚠️ 1–5 · ❌ More than 5 | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-03 Devices not synced for a long time L1 | Checks devices that have not synced with the organization for more than 30 days. These devices receive no updates or policies. | ✅ None (0) · ⚠️ 1–5 · ❌ More than 5 | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-04 Cleanup of long-inactive devices L1 | Checks whether devices with no activity for more than 90 days are cleared from the inventory. Stale devices form an attack surface. | ✅ None (0) · ⚠️ 1–10 · ❌ More than 10 | Auto |
DEV-05 Stale and noncompliant devices L2 | Checks whether any long-unused device also fails security policy. The two together carry the highest risk. | ✅ None (0) · ❌ One or more | Auto |
DEV-06 Device compliance policy defined L1 | Checks whether at least one device compliance policy exists. With no policy, compliance cannot be measured at all. | ✅ Defined (at least one) · ❌ None | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-07 Device configuration profile L1 | Checks whether devices are set up with a standard configuration profile. Without one, settings stay inconsistent from device to device. | ✅ Defined (at least one) · ⚠️ None | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-08 OS distribution monitoring L1 | Checks whether the mix of operating systems across devices is visible. Platforms you cannot see create blind spots. | ✅ Monitored (data available) · ⚠️ No data | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-09 Device enrollment restriction L1 | Checks whether a restriction on device enrollment is defined. Without one, devices enroll unchecked. | ✅ Defined (at least one) · ❌ None | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-10 Restriction of personal device enrollment L2 | Checks whether employees are blocked from enrolling their personal devices. Unmanaged personal devices are a data risk. | ✅ Restricted (blocked) · ⚠️ Not blocked | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-11 Windows Autopilot profile L2 | Checks whether an Autopilot profile handles the automatic, standard setup of new Windows devices. Nonstandard setup creates errors and gaps. | ✅ Defined (at least one) · ⚠️ None | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-12 Disk encryption (BitLocker/FileVault) L1 | Checks whether device disk encryption is enforced. On an unencrypted disk, a lost or stolen device exposes its data. | ✅ Enforced (policy defined) · ❌ Not defined | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-13 App protection policy (MAM) L1 | Checks whether an app protection policy guards corporate data in mobile apps. Without one, corporate data on mobile devices is unprotected. | ✅ Defined (at least one) · ❌ None | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-14 Windows Hello for Business L2 | Checks whether secure sign-in with biometrics or a PIN, instead of a password, is enabled. Password-only sign-in raises phishing risk. | ✅ Enabled · ⚠️ Not enabled | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-15 Windows update ring L1 | Checks whether an update ring keeps devices receiving updates regularly. An unpatched device carries vulnerabilities. | ✅ Defined (at least one) · ❌ None | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-16 Action defined for noncompliant devices L1 | Checks whether an automatic action (warn or block) is set for noncompliant devices. Without one, nothing responds to a noncompliant device. | ✅ Defined · ⚠️ Not defined | Auto Requires Business Premium (Entra P1); N/A if Intune is not used |
DEV-17 Blocking copy of corporate data into personal apps (MAM) L1 | Checks whether copying corporate email or file content into personal apps is blocked. Without this, employees can move corporate data into personal apps. | Auto Reviewed manually (not measured automatically) | |
DEV-18 Remote wipe for lost or stolen devices L1 | Checks whether a procedure exists to remotely wipe data from lost or stolen devices. Without it, corporate data on a lost device stays accessible. | Attested Customer attestation (not measured automatically) |