What It Delivers
Complete Device Inventory
Every managed device enrolled in Intune: OS version, patch level, encryption status, compliance state. Shadow IT devices flagged. You leave with a real picture of your fleet — not what should be there, but what is.
Compliance Baseline
Encryption enforced, OS minimum versions set, antivirus required, screen lock configured. Devices that fail compliance are flagged in red and blocked from data access via Conditional Access integration.
ASTRAL Deployment for Intune Drift
ASTRAL captures your Intune configuration as versioned snapshots in Git. Any policy change opens a pull request with a human-readable diff. Unauthorised changes are detected before they become incidents.
Shadow IT Discovery
Application inventory across all enrolled devices surfaces sanctioned and unsanctioned software — including consumer AI tools running on corporate devices. Every unsanctioned application is a potential data exfiltration or malware entry path.
Conditional Access Integration
Device compliance state wired into Conditional Access so non-compliant devices cannot reach email, SharePoint, or Teams. The device check becomes a real enforcement signal, not just a dashboard metric.
Why Endpoint Management First
Endpoint management is the entry vector that reveals everything else. Once enrollment runs, the consultant can see orphaned AD accounts (devices with no owner), unencrypted disks (the compliance gap nobody admitted), and consumer AI apps installed on devices that access regulated data. Every one of these becomes a natural conversation about what comes next.
The Trojan horse: the client asks to manage their laptops. You deliver that in 30 days. You also hand them a map of what you found — accounts that should not exist, devices that are not encrypted, applications leaking data. The device problem is solved. The picture that follows it is what turns a bounded engagement into a programme.
Scope and Prerequisites
| Duration | 30–45 days |
| Environment | M365 E3+ (Intune included) |
| Prerequisites | Global Administrator access; device enrollment feasibility confirmed |
| Natural follow-on | Module 2 (Identity Security) — identity gaps surface during enrollment |
Ready to see your fleet?
Full device visibility in 30 days. The foundation every other security control depends on.