Skillplan M365 Checklist
2026-07-20 19:33
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 14 of 17
Intune — Endpoint Management
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Enforce a device compliance policy that requires BitLocker, Secure Boot, antivirus, and a current OS build.
Not Fulfilled
Fulfilled
Accepted
Require Conditional Access to consume Intune device compliance signals (no access for non-compliant devices).
Not Fulfilled
Fulfilled
Accepted
Enroll all Windows devices via Autopilot; eliminate manual on-the-box administrator provisioning.
Not Fulfilled
Fulfilled
Accepted
Apply App Protection Policies (MAM) requiring a PIN, blocking copy/paste to unmanaged apps, and wiping on jailbreak.
Not Fulfilled
Fulfilled
Accepted
Deploy Defender for Endpoint via Intune; do not rely on user-driven onboarding.
Not Fulfilled
Fulfilled
Accepted
Enable Endpoint Privilege Management to grant just-in-time local-admin elevation for approved actions.
Not Fulfilled
Fulfilled
Accepted
Apply ASR rules and Controlled Folder Access via the Intune Endpoint Security blade.
Not Fulfilled
Fulfilled
Accepted
Maintain a corporate-device wipe policy for retired or lost devices and exercise it quarterly.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →