Skip to main content

DEV — Device Management

Device compliance and management controls. 18 controls in total — 17 automatic, 1 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
DEV-01 Intune device compliance rate
L1
Checks how well enrolled devices comply with security policies. A noncompliant device leaves an open door.✅ 90% or higher · ⚠️ 70–89% · ❌ Below 70%Auto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-02 Noncompliant device count
L2
Checks how many devices fail security policy. Every noncompliant device is a policy breach and a risk.✅ None (0) · ⚠️ 1–5 · ❌ More than 5Auto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-03 Devices not synced for a long time
L1
Checks devices that have not synced with the organization for more than 30 days. These devices receive no updates or policies.✅ None (0) · ⚠️ 1–5 · ❌ More than 5Auto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-04 Cleanup of long-inactive devices
L1
Checks whether devices with no activity for more than 90 days are cleared from the inventory. Stale devices form an attack surface.✅ None (0) · ⚠️ 1–10 · ❌ More than 10Auto
DEV-05 Stale and noncompliant devices
L2
Checks whether any long-unused device also fails security policy. The two together carry the highest risk.✅ None (0) · ❌ One or moreAuto
DEV-06 Device compliance policy defined
L1
Checks whether at least one device compliance policy exists. With no policy, compliance cannot be measured at all.✅ Defined (at least one) · ❌ NoneAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-07 Device configuration profile
L1
Checks whether devices are set up with a standard configuration profile. Without one, settings stay inconsistent from device to device.✅ Defined (at least one) · ⚠️ NoneAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-08 OS distribution monitoring
L1
Checks whether the mix of operating systems across devices is visible. Platforms you cannot see create blind spots.✅ Monitored (data available) · ⚠️ No dataAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-09 Device enrollment restriction
L1
Checks whether a restriction on device enrollment is defined. Without one, devices enroll unchecked.✅ Defined (at least one) · ❌ NoneAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-10 Restriction of personal device enrollment
L2
Checks whether employees are blocked from enrolling their personal devices. Unmanaged personal devices are a data risk.✅ Restricted (blocked) · ⚠️ Not blockedAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-11 Windows Autopilot profile
L2
Checks whether an Autopilot profile handles the automatic, standard setup of new Windows devices. Nonstandard setup creates errors and gaps.✅ Defined (at least one) · ⚠️ NoneAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-12 Disk encryption (BitLocker/FileVault)
L1
Checks whether device disk encryption is enforced. On an unencrypted disk, a lost or stolen device exposes its data.✅ Enforced (policy defined) · ❌ Not definedAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-13 App protection policy (MAM)
L1
Checks whether an app protection policy guards corporate data in mobile apps. Without one, corporate data on mobile devices is unprotected.✅ Defined (at least one) · ❌ NoneAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-14 Windows Hello for Business
L2
Checks whether secure sign-in with biometrics or a PIN, instead of a password, is enabled. Password-only sign-in raises phishing risk.✅ Enabled · ⚠️ Not enabledAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-15 Windows update ring
L1
Checks whether an update ring keeps devices receiving updates regularly. An unpatched device carries vulnerabilities.✅ Defined (at least one) · ❌ NoneAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-16 Action defined for noncompliant devices
L1
Checks whether an automatic action (warn or block) is set for noncompliant devices. Without one, nothing responds to a noncompliant device.✅ Defined · ⚠️ Not definedAuto
Requires Business Premium (Entra P1); N/A if Intune is not used
DEV-17 Blocking copy of corporate data into personal apps (MAM)
L1
Checks whether copying corporate email or file content into personal apps is blocked. Without this, employees can move corporate data into personal apps.Auto
Reviewed manually (not measured automatically)
DEV-18 Remote wipe for lost or stolen devices
L1
Checks whether a procedure exists to remotely wipe data from lost or stolen devices. Without it, corporate data on a lost device stays accessible.Attested
Customer attestation (not measured automatically)