{"id":40844,"date":"2026-10-08T04:55:43","date_gmt":"2026-10-08T04:55:43","guid":{"rendered":"https:\/\/www.insentragroup.com\/nz\/insights\/uncategorized\/using-device-compliance-to-protect-corporate-data\/"},"modified":"2026-10-08T05:46:06","modified_gmt":"2026-10-08T05:46:06","slug":"using-device-compliance-to-protect-corporate-data","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/nz\/insights\/geek-speak\/modern-workplace\/using-device-compliance-to-protect-corporate-data\/","title":{"rendered":"Using Device Compliance to Protect Corporate Data"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">What happens when a valid corporate identity is being used from a device the organisation does not control?&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The identity may be legitimate and the user may be authorised, but that does not necessarily mean the endpoint can be trusted. If the device can access corporate data without meeting the organisation\u2019s security requirements, the access decision is missing an important piece of context.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not simply a theoretical security concern. Verizon\u2019s 2025 Data Breach Investigations Report found that 46% of compromised systems containing corporate logins were non-managed devices, with the analysis indicating that these devices were likely associated with BYOD or enterprise-owned devices being used outside permitted policy.<sup>1<\/sup> Palo Alto Networks similarly found that 33% of devices observed on corporate networks were unmanaged in its analysis of more than 27 million devices, highlighting the gap that can exist between the devices organisations expect to control and the devices actually present in their environments.<sup>2<\/sup><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Identity is only part of the decision<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Identity alone does not provide enough context to determine whether access is safe. A legitimate account can be used from an unmanaged, compromised or insecure endpoint, potentially giving that device access to the same corporate resources as a trusted and properly secured device. Modern access decisions therefore need to consider not only\u202fwho\u202fis requesting access, but also\u202fwhat they are accessing it from.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where device compliance becomes an important part of the security model. Compliance policies provide a way to evaluate whether managed devices meet defined security requirements, including conditions such as operating system versions, encryption, password requirements and device risk. The resulting compliance state can then be provided to Microsoft Entra Conditional Access, allowing the organisation to use the current state of the device as part of its access decision.<sup>3<\/sup>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a broader introduction to how Microsoft Intune supports device management, application management and compliance, read <a href=\"https:\/\/www.insentragroup.com\/nz\/insights\/geek-speak\/secure-workplace\/the-ultimate-guide-to-microsoft-intune\/\" target=\"_blank\" rel=\"noreferrer noopener\">The Ultimate Guide to Microsoft Intune<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Compliance becomes an access signal<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The distinction between these two capabilities is important.\u202fCompliance assesses the device, while Conditional Access enforces the decision.\u202fIntune can determine that a device does not meet the organisation&#8217;s requirements, but it is Conditional Access that can use that information to prevent the device from accessing protected resources.<sup>3<\/sup>&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The question therefore moves beyond&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWho is accessing this data?\u201d&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">to\u202f&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhat device are they using, and can we trust it right now?\u201d\u202f&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second question becomes increasingly important as users work from anywhere and corporate data is accessed across a growing range of corporate, personal and third-party devices.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A device that met security requirements when it was deployed may not remain compliant indefinitely. Security controls can be disabled, operating systems can become outdated, configurations can change or a device can develop a security risk after deployment. Compliance therefore provides a mechanism for evaluating the current state of the endpoint rather than assuming that a device remains trustworthy simply because it was trusted previously.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Trust has to be current<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This makes compliance more than an endpoint management control. It becomes a\u202fsecurity signal that can contribute directly to an access decision based on the current state of the device. Microsoft describes device compliance and Conditional Access as part of a Zero Trust approach in which access is explicitly evaluated rather than implicitly trusted, with device health and risk contributing to decisions about access to organisational resources.<sup>4<\/sup>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The model can also extend beyond relatively static compliance requirements. Microsoft Defender for Endpoint can provide device risk information that can be integrated with Intune and used alongside compliance and Conditional Access, allowing access decisions to respond to active security threats as well as configuration state. This creates a progression from asking whether a device meets a defined baseline to considering whether the device remains sufficiently trustworthy when access is requested.<sup>4<\/sup>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is, however, a balance to find. Compliance policies that attempt to control every possible risk can create unnecessary disruption, increase support overhead and encourage exceptions that weaken the overall model. A more effective approach is to identify the security conditions that genuinely matter to the organisation and use those conditions to establish a practical definition of a trusted device.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organisations looking to apply this approach, the starting point is understanding which devices can currently access corporate data and whether those devices are managed, unmanaged or operating outside the organisation&#8217;s intended policy. From there, define the minimum security conditions that need to be true for a device to be considered trusted, then align those requirements with Intune compliance and Conditional Access. The final question is \u201cWhat happens when a device stops meeting those conditions?\u201d, because a compliance model is only useful if the resulting signal leads to an appropriate response.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key considerations<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Define what a trusted device means for your organisation.<\/strong> Focus on the security conditions that genuinely matter rather than attempting to enforce every possible control.&nbsp;<\/li>\n\n\n\n<li><strong>Make access conditional on device security.<\/strong> Use compliance as a signal alongside identity and other risk indicators, with Conditional Access enforcing the appropriate response.<\/li>\n\n\n\n<li><strong>Plan for when trust changes.<\/strong> A device that is compliant today may not be compliant tomorrow, so the model needs to define what happens when a device no longer meets the required conditions.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is not to make every device pass every possible security check. It is to make access conditional on the security of the device being used, with the controls proportionate to the sensitivity of the data and services being accessed. Protecting corporate data is therefore no longer just about knowing who is accessing it, but also what they are accessing it from, whether that device can be trusted, and whether it remains trusted when access occurs.&nbsp;&nbsp;<\/p>\n\n\n\n<div style=\"height:31px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<div style=\"height:31px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-extra-small-font-size wp-block-paragraph\"><sup>1<\/sup> Verizon,\u202f<em>2025 Data Breach Investigations Report<\/em>, Verizon Business&nbsp;<br><a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/?utm_source=chatgpt.com\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/<\/a>&nbsp;<\/p>\n\n\n\n<p class=\"has-extra-small-font-size wp-block-paragraph\"><sup>2<\/sup> Palo Alto Networks,\u202f<em>Device Security Threat Report<\/em>&nbsp;<br><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/infographics\/device-security-threat-2025?utm_source=chatgpt.com\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/www.paloaltonetworks.com\/resources\/infographics\/device-security-threat-2025<\/a>&nbsp;<\/p>\n\n\n\n<p class=\"has-extra-small-font-size wp-block-paragraph\"><sup>3<\/sup> Microsoft,\u202f<em>Use compliance policies to set rules for devices you manage with Intune<\/em>, Microsoft Learn&nbsp;<br><a href=\"https:\/\/learn.microsoft.com\/en-us\/intune\/device-security\/compliance\/overview?utm_source=chatgpt.com\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/learn.microsoft.com\/en-us\/intune\/device-security\/compliance\/overview<\/a>&nbsp;<\/p>\n\n\n\n<p class=\"has-extra-small-font-size wp-block-paragraph\"><sup>4<\/sup> Microsoft,\u202f<em>Zero Trust deployment approach with Microsoft Intune<\/em>, Microsoft Learn&nbsp;<br><a href=\"https:\/\/learn.microsoft.com\/en-us\/intune\/fundamentals\/zero-trust-deployment?utm_source=chatgpt.com\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/learn.microsoft.com\/en-us\/intune\/fundamentals\/zero-trust-deployment<\/a>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where to Begin<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Our team works with organisations to understand their current endpoint environment, compliance practices and operational challenges, and identify opportunities to strengthen data protection without creating unnecessary barriers to productivity. This can include reviewing how capabilities such as Microsoft Intune and Microsoft Entra Conditional Access can support a more consistent and controlled approach to device compliance and access. The focus is on understanding the problem first and then determining the approach that best aligns with the organisation&#8217;s requirements.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your organisation is reviewing device compliance, endpoint management or looking to strengthen data protection by ensuring only trusted devices have access, explore Insentra\u2019s <a href=\"https:\/\/www.insentragroup.com\/nz\/services\/professional-services\/modern-workplace\/modern-management\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Modern Device Management services.<\/strong><\/a>\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our team can help you assess your current environment, understand the challenges you are looking to solve and determine an approach that aligns with your security requirements and operational needs. <a href=\"https:\/\/www.insentragroup.com\/nz\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Contact us<\/strong><\/a> <strong>to start the conversation<\/strong>.<\/p>\n\n\n\n<style data-wp-block-html=\"css\">\n.has-extra-small-font-size {\n    font-size: 15px !important;\n}\n<\/style>\n\n\n\n<style>\n.has-extra-small-font-size {\n    font-size: 14px !important;\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Learn how Microsoft Intune device compliance and Entra Conditional Access help organisations protect corporate data by making device trust part of access decisions. <\/p>\n","protected":false},"author":232,"featured_media":40845,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-40844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modern-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/40844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/users\/232"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/comments?post=40844"}],"version-history":[{"count":1,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/40844\/revisions"}],"predecessor-version":[{"id":40846,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/40844\/revisions\/40846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media\/40845"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media?parent=40844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/categories?post=40844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/tags?post=40844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}