Skip to content

Practical guide · Devices

An unmanaged device is a door nobody locks.

Intune connects a device to minimum rules - screen lock, encryption, current OS version - before it can touch organizational data. Device management only helps if those rules are reviewed, not just switched on once.

The decision to make

This guide helps decide what level of management fits a corporate device, what fits a personal device, and what a departure or lost device should trigger right away.

An unmanaged device is a door nobody locks

Without a minimum requirement - passcode, encryption, an up-to-date OS - a compromised device can reach organizational mail and files as easily as a trusted one. A baseline compliance policy is the starting point, not the finish line.

A personal device needs a different policy than a corporate one

Fully managing a personal device raises legitimate privacy questions. An app protection policy can isolate work data without taking control of the whole device - a distinction the team should understand before a rule is imposed.

  • Corporate devices follow a full compliance policy
  • Personal devices get targeted protection scoped to work apps
  • The difference is explained to the team, not just applied quietly

A departure must include the person’s devices

Blocking an account does not automatically remove work access from a personal device left configured. The departure checklist must cover removing work data and revoking access, not just changing a password.

A lost device needs a known step, not improvisation

Who to notify, how to lock or wipe the device remotely, and how to confirm the action worked should be written down before a device is actually lost - not invented under pressure.

What becomes a separate project

A full device fleet rollout, a standard image for new computers, or a large-scale patch management program go beyond routine maintenance and deserve their own scope.

A simple matrix for assigning the work.

SituationOwnerCadenceUseful evidence
New corporate deviceManager + M365Before day oneCompliance policy applied
Personal device (work access)User + M365At enrollmentProtection policy confirmed
Departure or lost deviceM365 ownerImmediatelyAccess revoked and verified

Decision checklist

What should be true before considering this area under control.

  • Every corporate device follows a minimum compliance policy
  • Personal devices have a separate protection policy, explained to the team
  • A person’s departure removes work access from their devices
  • A known step exists for a lost or stolen device
  • Large-scale rollout is recognized as separate project work

Next step

Connect device management to the rest of the monthly scope.

The service scope shows where devices fit inside routine maintenance. Then see the rhythm to understand when these checks actually happen.

Let’s discuss ownership of your M365 tenant

Describe your team, what currently lacks an owner, and the outcome you need. No tenant access is required for this first conversation.

Direct email remains the simplest way to start. Use the public m365care.ca address with an already attributed subject.