This is for you if

  • Devices are enrolled inconsistently, or half your estate isn't managed at all
  • You want devices centrally policed, patched and wiped without chasing every user individually
  • You're evaluating or already licensed for Intune but haven't configured it properly

An unmanaged laptop is a laptop that can be lost, stolen, or compromised with no way to enforce encryption, wipe it remotely, or even prove what state it was in. Ad hoc device management isn't a smaller version of this problem, it's the same problem with worse visibility.

Central device management isn't about locking devices down for the sake of it, it's about being able to see, patch, police and wipe every device in your estate without chasing individual users. This checklist covers what a properly configured Intune setup actually includes.

Work through it with whoever manages your Microsoft 365 tenant. If you can't confidently tick a box, that's a policy gap sitting in your estate right now, not a future problem.

1. Enrolment

  • Company-owned devices enrolled automatically via Autopilot or bulk provisioning, not manual sign-in
  • Personal (BYOD) devices enrolled through app protection policies, without full device control
  • Enrolment restrictions in place so unmanaged personal devices can't join the tenant unchecked
  • A named owner for enrolment failures, so devices don't sit unmanaged indefinitely
  • Enrolment status tracked so 100% of issued hardware is accounted for, not just a majority

2. Compliance policy

  • Minimum OS version, encryption and password/PIN requirements defined and enforced
  • Jailbroken or rooted devices automatically marked non-compliant
  • Compliance status feeding into Conditional Access, not just sitting in a dashboard nobody checks
  • Grace periods set deliberately, not left on defaults that give risky devices weeks of access
  • Non-compliant devices reviewed regularly, not just flagged and forgotten
Actions for noncompliance, on a scheduleA seven-day timeline of an example from Microsoft Learn. Day 0: the device is marked noncompliant, the default action, and Conditional Access can block it. Day 2: an email to the user. Day 5: a second email. Changing the schedule of the default action is what creates a grace period.FoundDay 1Day 2Day 3Day 4Day 5Day 6Day 7Marked noncompliant: the default, atzero daysEmail the userEmail again; lock or retire if stillnoncompliantExample schedule from Microsoft Learn (checked 5 October 2026); any action takes 0 to 365 days. Moving thedefault action off zero is a grace period, so set it deliberately. Separately, a device that stopsreporting is treated as noncompliant after the validity period: 30 days by default, 1 to 120.
Intune marks a device noncompliant immediately by default, and Conditional Access can then block it. Changing that schedule is what creates a grace period, so set it deliberately. Example schedule from Microsoft Learn, checked 5 October 2026.

3. Conditional Access

  • Access to email and company data blocked from unmanaged or non-compliant devices
  • Multi-factor authentication required for all users, enforced through Conditional Access, not left optional
  • Risky sign-in locations or impossible-travel patterns trigger additional verification
  • Legacy authentication protocols blocked, since they bypass MFA entirely
  • Policies tested in report-only mode before enforcement, so nobody gets locked out by surprise

4. App deployment and patch management

  • Core business applications deployed automatically to new devices, no manual installation required
  • OS and application updates managed centrally, with a defined ring/wave rollout rather than all-at-once
  • Update compliance tracked so ageing, unpatched devices are visible, not silent
  • Required apps distinguished from available (self-service) apps, deliberately, not by default
  • Configuration profiles (Wi-Fi, VPN, certificates) deployed automatically rather than set up by hand

5. Retire and wipe

  • A defined offboarding process wipes company data from a leaver's device the same day, not at convenience
  • Lost or stolen devices can be remotely wiped or locked without waiting on the user
  • Selective wipe available for BYOD, removing company data only, not personal photos and files
  • Retired devices formally removed from Intune and Entra ID, not left as stale records
  • A regular audit confirms every enrolled device is still a real, active, accounted-for device
Retire, wipe and app selective wipe compared: what each removes, and when to use it
RetireWipeApp selective wipe
What it removesManaged apps and data, settings and email profiles assigned through Intune; the device leaves Intune managementEverything: the device is restored to its factory default settings and removed from IntuneCompany app data only, from the apps that carry an app protection policy
Personal dataLeft on the deviceRemoved, unless you choose to keep the enrolment state and user accountLeft in place
When it runsThe next time the device checks inThe next time the device checks inThe next time the protected app runs
FitsA personally owned device leaving organisational controlA lost or stolen company device, or one being reissuedBYOD with app protection and no device enrolment
AfterwardsRetire does not remove the Microsoft Entra device record: remove it too, so it is not left as a stale recordRemove the Intune and Entra records if the device is not coming backThe account, the apps and the user's own files stay as they were
Retire, wipe and app selective wipe remove different things. Retire leaves personal data and does not remove the Microsoft Entra device record; wipe restores factory settings; app selective wipe removes company app data only. Checked against Microsoft Learn, 5 October 2026.

Where this leaves you

Most estates have Intune licensed and partly configured, enough to feel managed without actually enforcing anything. The gap between "enrolled" and "controlled" is exactly what this checklist closes: compliance policies that actually gate access, patching that doesn't depend on someone remembering, and an offboarding process that doesn't leave company data on a departed employee's laptop. Systech's Intune and device management service builds and runs this configuration end to end.

  • Every box ticked, with evidence

    Compliance policies gate access, patching does not depend on someone remembering, and offboarding does not leave company data on a departed employee's laptop. That is the gap between enrolled and controlled, closed.

  • Enrolled, but compliance does not gate access

    The commonest position: Intune licensed and partly configured, enough to feel managed without actually enforcing anything. Feed compliance into Conditional Access, starting in report-only mode.

  • Devices you cannot see, patch or wipe

    Every one of them is a device you do not actually control. Account for 100% of issued hardware, then decide the enrolment route for each.

  • Not sure your setup is actually enforcing anything

    Request a call. The endpoint and Intune review checks what is enrolled against what should be, what your compliance figure is really measuring, and which policies are winning.