Why device management became a security control
When your data lives in Microsoft 365, the office network stops being the boundary of the business. The new boundary is the combination of an identity and a device — who is signing in, and on what. An unmanaged laptop with a weak password and no disk encryption, sitting in a café with a cached copy of your SharePoint, is outside every control you have built, unless the device itself is managed.
Microsoft Intune is how that management happens without the old baggage of imaging servers and domain joins. Devices enrol over the internet, policies follow the device wherever it is, and compliance is evaluated continuously rather than checked whenever the machine next visits the office. For a distributed or hybrid workforce, it is the difference between managing a fleet and hoping about one.
The pieces below — enrolment, compliance, app deployment, encryption escrow, BYOD containment — are one system, and the connective tissue is Conditional Access: the device's compliance state becomes a condition of reaching company data at all.
Autopilot: new laptops without the IT pit stop
The traditional new-starter routine — laptop shipped to the office, imaged by IT, couriered onward — adds days of delay and one unnecessary journey. Windows Autopilot removes it. The device ships from the supplier directly to your new starter, wherever they are; on first sign-in with their company account, it identifies itself to your tenant, and enrolment, encryption, policies and applications flow onto it automatically.
By the time the desktop appears, the machine is encrypted with the key escrowed, compliant with your policies, and loaded with the applications the role requires. Nobody in IT touched it. The same mechanism covers rebuilds: a machine in a bad state can be reset and rebuilt to a known-good configuration remotely, which turns "my laptop is broken" from a courier problem into an afternoon.
Compliance policies, and what non-compliance costs
A compliance policy is a definition of the minimum acceptable state of a device: disk encrypted with BitLocker, screen lock enforced, operating system current, the device not jailbroken or rooted. Intune evaluates every enrolled device against it continuously — not annually, not on request.
The enforcement is what makes it real. Through Conditional Access, compliance becomes a condition of access: a device that drifts out of policy — encryption off, OS too old — is blocked from Microsoft 365 until it is brought back in line. Nobody has to notice, chase, or ask nicely. The estate converges on the policy, because non-compliant devices lose access to the things people need to work.
Application deployment rides the same rails: Office apps, Adobe, line-of-business installers pushed to enrolled devices, updated centrally, and removed when the device is wiped or retired. The alternative — every machine hand-built, every update a per-desk errand — does not survive contact with a distributed team.
Conditional Access in our Microsoft 365 practice →
BYOD: work data on personal phones, without seizing the phone
Staff will read work email on personal phones whether or not you have a policy — the only question is whether company data is protected when they do. Fully enrolling a personal device is the wrong answer for most businesses: it is intrusive, staff resist it, and it creates obligations nobody wants.
App protection policies are the proportionate tool. Work apps — Outlook, Teams, OneDrive — run inside a managed container on the personal device: company data encrypted within the apps, a PIN or biometric required to open them, copy-paste into personal apps restricted by policy, and the ability to wipe company data from the work apps without touching the owner's photos, messages or anything else personal. The employee keeps a personal phone; the business keeps its data.
This is also the honest answer to the privacy question staff will ask: with app protection, the business manages its apps and its data — not the phone.
Lost laptops, and leavers
Every fleet eventually loses a device — a taxi, an airport, a theft. The difference between an incident and a shrug is preparation. BitLocker encryption is enforced by policy, and the recovery keys escrow automatically to Microsoft Entra, so encryption never depends on a user remembering to switch it on or on IT remembering to record a key. A lost device is unreadable to whoever has it, and is wiped remotely from the console the moment it is reported.
Leavers are the same discipline on a schedule: access revoked at the identity, company data removed from personal devices via app protection, and company laptops wiped and rebuilt for the next starter — a routine, not an improvisation. Between incidents, the device inventory Intune maintains carries its own operational value: what hardware exists, who has it, and which machines are ageing toward replacement.