Are the devices and applications you depend on covered by the intended controls?
Connect device inventory, policy assignment and compliance signals to real access decisions.
Begin with the business decision and the affected population. A targeted workload review may be sufficient; an interconnected tenant assessment may be more useful where the same identity, device or data dependency affects several services.
Evidence we agree to examine
- Enrolment and inventory reconciliation, stale devices and ownership
- Compliance policies, assignment filters, exclusions and treatment of unassigned devices
- Configuration profiles, security baselines, encryption and endpoint protection coverage
- App protection policies, supported platforms, exceptions and Conditional Access integration
Why context changes the conclusion
A compliant device count is incomplete without a population denominator. Compare managed devices, active users, policy assignments and the access paths that permit unmanaged clients.
Treat this as an assessment question, not a finding about your organisation. During an engagement, a conclusion must identify the dated evidence, the sampled population and any exceptions that could not be corroborated.
The output your team can use
A coverage analysis and sequenced device-policy remediation plan, with rollout and rollback considerations.
Each action should identify its accountable owner, licence or business dependency, proposed rollout safeguards and the record that will demonstrate successful closure. A policy screenshot alone is not enough when the finding concerns coverage or sustained operation.
Access and boundaries
Device-agent installation, fleet changes and malware investigation are separate work. A posture review does not certify every endpoint.
We agree evidence access before work begins. Your team can lead supervised sessions and provide approved, minimised exports. The assessment does not require you to send passwords, grant access through this website or permit production changes. See access and data handling.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Sources & further reading
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

