Consulting Module

Module 1 — Endpoint Management Foundation

You cannot govern what you cannot see. Endpoint management is almost always the right first module after the Diagnostic — it produces immediate visibility across every device and creates the foundation every other security control depends on.

What It Delivers

📱

Complete Device Inventory

Every managed device enrolled in Intune: OS version, patch level, encryption status, compliance state. Shadow IT devices flagged. You leave with a real picture of your fleet — not what should be there, but what is.

Compliance Baseline

Encryption enforced, OS minimum versions set, antivirus required, screen lock configured. Devices that fail compliance are flagged in red and blocked from data access via Conditional Access integration.

🔀

ASTRAL Deployment for Intune Drift

ASTRAL captures your Intune configuration as versioned snapshots in Git. Any policy change opens a pull request with a human-readable diff. Unauthorised changes are detected before they become incidents.

🔍

Shadow IT Discovery

Application inventory across all enrolled devices surfaces sanctioned and unsanctioned software — including consumer AI tools running on corporate devices. Every unsanctioned application is a potential data exfiltration or malware entry path.

🔐

Conditional Access Integration

Device compliance state wired into Conditional Access so non-compliant devices cannot reach email, SharePoint, or Teams. The device check becomes a real enforcement signal, not just a dashboard metric.

Why Endpoint Management First

Endpoint management is the entry vector that reveals everything else. Once enrollment runs, the consultant can see orphaned AD accounts (devices with no owner), unencrypted disks (the compliance gap nobody admitted), and consumer AI apps installed on devices that access regulated data. Every one of these becomes a natural conversation about what comes next.

The Trojan horse: the client asks to manage their laptops. You deliver that in 30 days. You also hand them a map of what you found — accounts that should not exist, devices that are not encrypted, applications leaking data. The device problem is solved. The picture that follows it is what turns a bounded engagement into a programme.

Scope and Prerequisites

Duration30–45 days
EnvironmentM365 E3+ (Intune included)
PrerequisitesGlobal Administrator access; device enrollment feasibility confirmed
Natural follow-onModule 2 (Identity Security) — identity gaps surface during enrollment

Ready to see your fleet?

Full device visibility in 30 days. The foundation every other security control depends on.