Practical guide · Devices
An unmanaged device is a door nobody locks.
Intune connects a device to minimum rules - screen lock, encryption, current OS version - before it can touch organizational data. Device management only helps if those rules are reviewed, not just switched on once.
The decision to make
This guide helps decide what level of management fits a corporate device, what fits a personal device, and what a departure or lost device should trigger right away.
An unmanaged device is a door nobody locks
Without a minimum requirement - passcode, encryption, an up-to-date OS - a compromised device can reach organizational mail and files as easily as a trusted one. A baseline compliance policy is the starting point, not the finish line.
A personal device needs a different policy than a corporate one
Fully managing a personal device raises legitimate privacy questions. An app protection policy can isolate work data without taking control of the whole device - a distinction the team should understand before a rule is imposed.
- Corporate devices follow a full compliance policy
- Personal devices get targeted protection scoped to work apps
- The difference is explained to the team, not just applied quietly
A departure must include the person’s devices
Blocking an account does not automatically remove work access from a personal device left configured. The departure checklist must cover removing work data and revoking access, not just changing a password.
A lost device needs a known step, not improvisation
Who to notify, how to lock or wipe the device remotely, and how to confirm the action worked should be written down before a device is actually lost - not invented under pressure.
What becomes a separate project
A full device fleet rollout, a standard image for new computers, or a large-scale patch management program go beyond routine maintenance and deserve their own scope.
A simple matrix for assigning the work.
| Situation | Owner | Cadence | Useful evidence |
|---|---|---|---|
| New corporate device | Manager + M365 | Before day one | Compliance policy applied |
| Personal device (work access) | User + M365 | At enrollment | Protection policy confirmed |
| Departure or lost device | M365 owner | Immediately | Access revoked and verified |
Decision checklist
What should be true before considering this area under control.
- Every corporate device follows a minimum compliance policy
- Personal devices have a separate protection policy, explained to the team
- A person’s departure removes work access from their devices
- A known step exists for a lost or stolen device
- Large-scale rollout is recognized as separate project work
Next step
Connect device management to the rest of the monthly scope.
The service scope shows where devices fit inside routine maintenance. Then see the rhythm to understand when these checks actually happen.