Legal

Microsoft 365 treats a device with no policy as compliant

Here's a Microsoft 365 setting that surprises almost every firm owner I show it to.

1 min readOriginally posted on LinkedIn

Here's a Microsoft 365 setting that surprises almost every firm owner I show it to.

By default, Intune treats a device with no compliance policy assigned to it as compliant. Not blocked. Not flagged. Compliant. So the personal iPhone your paralegal added her work email to last Tuesday is, as far as your tenant is concerned, perfectly fine.

Most people assume the opposite — that an unknown device has to earn its way in. It doesn't. It walks in.

The fix isn't banning personal phones. That fight is unwinnable, and honestly, the partner answering a client at 9pm from the car is why the firm runs. The fix is separating the work data from the phone it's sitting on.

Microsoft lets you protect company data at the app level without managing the whole device — no enrolling someone's personal phone, no reaching into their personal apps and photos. Work email and work files live inside a boundary you control. When someone leaves, or loses the phone in a parking garage off Clematis, you wipe the firm's data out of the app and leave the rest alone.

The alternative is a phone call with a client about where their documents ended up. That one gets expensive in ways that never show up on an invoice.

Worth a look before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions