Watchtower Docs
ReferenceCheck catalog

Intune platform

All 36 Intune platform checks - what each one checks, why, and the access used to evaluate it.

36 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.

CheckSeverityWhat it checksWhy it mattersAccess used
Android app protection policies exist and are assigned
wt.intune.android.app-protection-assigned
MEDIUMChecks that at least one Android app protection (MAM) policy exists and is assigned (has assignment targets). This asserts deployment coverage - the MAM boundary only protects data where a policy actually targets users.On Android the app protection policy is what separates corporate data in Outlook, Teams, and Office from the rest of the device - especially personally-owned devices outside full management. Without an assigned policy there is no PIN gate on corporate apps, no transfer restriction into personal apps, and no selective wipe when a device or employee departs.DeviceManagementApps.Read.All - via androidAppProtectionPolicies
Corporate-owned Android devices have an assigned compliance policy
wt.intune.android.compliance-corporate-assigned
MEDIUMChecks that at least one Android Enterprise device-owner compliance policy (fully managed / dedicated / corporate-owned work profile - androidDeviceOwnerCompliancePolicy) exists and is assigned.Corporate-owned Android fleets are typically kiosk, frontline, or shared devices - exactly the devices nobody watches individually. An assigned device-owner compliance policy is what enforces encryption, patch level, and Play Integrity on them, and what lets Conditional Access refuse the ones that fall out of line.DeviceManagementConfiguration.Read.All - via androidCompliancePolicies
Personally-owned Android work profiles have an assigned compliance policy
wt.intune.android.compliance-personal-assigned
MEDIUMChecks that at least one Android Enterprise personally-owned work profile compliance policy (androidWorkProfileCompliancePolicy) exists and is assigned.BYOD Android is the least-controlled surface that still touches corporate data: the device is the user's, but the work profile holds your mail and files. The work-profile compliance policy is the only device-health lever you have there - without one assigned, a rooted or years-unpatched personal phone syncs corporate data exactly like a healthy one.DeviceManagementConfiguration.Read.All - via androidCompliancePolicies
Defender for Endpoint MTD connector is enabled for Android
wt.intune.android.defender-connector-enabled
MEDIUMChecks that the Microsoft Defender for Endpoint Mobile Threat Defense connector is present, enabled, and enforcing on Android. The connector is what feeds Defender's device risk score into Intune compliance.Without the connector, Defender can watch an Android device get compromised while Intune keeps reporting it compliant - device-based Conditional Access then happily admits the compromised device to everything. The connector closes that loop: risk score up, compliance down, access revoked.DeviceManagementServiceConfig.Read.All - via mobileThreatDefenseConnectors
An enterprise Wi-Fi profile is assigned for Android
wt.intune.android.wifi-enterprise-assigned
LOWChecks that at least one Android Enterprise device-owner Wi-Fi profile (androidDeviceOwnerEnterpriseWiFiConfiguration) using WPA-Enterprise (802.1X) exists and is assigned.Corporate-owned Android fleets - kiosks, frontline, shared devices - live on Wi-Fi all day. A shared passphrase across that fleet is a credential that leaks once and works for anyone, including an attacker's evil-twin access point. Certificate-based 802.1X gives each device its own network identity and mutual authentication.DeviceManagementConfiguration.Read.All - via androidConfigurationProfiles
Devices without a compliance policy are marked 'not compliant'
wt.intune.default-noncompliant-devices
MEDIUMChecks that the Intune default compliance setting marks devices as non-compliant when no compliance policy has been assigned to them, rather than treating unevaluated devices as compliant.If devices without a compliance policy are considered compliant by default, unmanaged or newly enrolled devices can satisfy device-compliance Conditional Access requirements before any security baseline has been verified. Attackers who enrol a rogue device can immediately use it to access resources gated on compliance.DeviceManagementConfiguration.Read.All - via deviceManagementSettings
Managed-device cleanup rules are configured
wt.intune.device-cleanup-rules-configured
LOWChecks that at least one Intune managed-device cleanup rule exists, automatically retiring devices that have stopped checking in.Device records that stopped syncing years ago are more than console clutter: they hold stale compliance states that keep satisfying device-based Conditional Access, and they bury the one anomalous record an investigation needs. Hygiene here is a security control with a checkbox's worth of effort.DeviceManagementManagedDevices.Read.All - via deviceCleanupRules
Device enrollment notifications are configured and assigned
wt.intune.enrollment-notifications-configured
LOWChecks that at least one enrollment notification configuration exists in Intune and is assigned, so users are told the moment a device is enrolled under their identity.The user is the one detector who is guaranteed to know whether that new device is theirs. An attacker who phishes credentials and enrolls their own device gains a persistent, 'compliant' foothold - unless the legitimate user gets the 'a device was just enrolled' message and raises the alarm. Silence is what makes rogue enrollment cheap.DeviceManagementServiceConfig.Read.All - via enrollmentNotificationConfigurations
iOS app protection policies exist and are assigned
wt.intune.ios.app-protection-assigned
MEDIUMChecks that at least one iOS/iPadOS app protection (MAM) policy exists and is assigned. Setting-level quality (blocking managed-to-unmanaged data transfer, PIN requirements) is asserted by the wt.ios.data.* checks; this control asserts the deployment coverage they depend on.App protection policies are the only data boundary on devices you do not fully manage: they keep corporate mail and documents inside managed apps, enforce an app PIN, and enable selective wipe. A tenant with no assigned iOS MAM policy has no such boundary - corporate data on every BYOD iPhone is one copy-paste away from personal apps, and there is nothing to wipe when the user leaves.DeviceManagementApps.Read.All - via iosAppProtectionPolicies
An iOS compliance policy exists and is assigned
wt.intune.ios.compliance-policy-assigned
MEDIUMChecks that at least one iOS/iPadOS compliance policy exists and is assigned - the prerequisite for jailbreak detection, OS-minimum enforcement, and Conditional Access device gating on iOS.The setting-level iOS checks (jailbreak blocked, minimum OS) assert what a compliance policy contains - this one asserts that a policy actually reaches devices. An unassigned policy leaves every enrolled iPhone reporting the tenant default, and require compliant device stops meaning anything for the platform.DeviceManagementConfiguration.Read.All - via iosCompliancePolicies
An iOS update policy is configured and assigned
wt.intune.ios.update-policy-assigned
MEDIUMChecks that at least one iOS/iPadOS software update policy exists and is assigned - either the classic MDM form (iosUpdateConfiguration) or a declarative (DDM) Settings Catalog software-update policy. Either form passes, per Microsoft Zero Trust Assessment v2.4.0.iOS releases regularly patch actively-exploited WebKit and kernel bugs, and users defer updates indefinitely when left to themselves. An assigned update policy is what turns Apple's patch into fleet reality on a schedule you chose - and modern declarative enforcement can pin a target OS version with a deadline.DeviceManagementConfiguration.Read.All - via iosConfigurationProfiles
An enterprise Wi-Fi profile is assigned for iOS
wt.intune.ios.wifi-enterprise-assigned
LOWChecks that at least one iOS Wi-Fi configuration profile using an enterprise security type (WPA2-Enterprise / WPA-Enterprise, i.e. 802.1X certificate authentication) exists and is assigned.A pre-shared-key corporate Wi-Fi means one passphrase shared by everyone, leaked once, rotated never - and anyone holding it can stand up an evil-twin access point that devices happily join. 802.1X joins devices with per-device certificates: nothing to leak, and devices authenticate the network as much as the network authenticates them.DeviceManagementConfiguration.Read.All - via iosConfigurationProfiles
A macOS compliance policy exists and is assigned
wt.intune.macos.compliance-policy-assigned
MEDIUMChecks that at least one macOS compliance policy exists and is assigned. Both classic and Settings Catalog compliance forms count.Without an assigned macOS compliance policy, require compliant device in Conditional Access is inert for Macs - they either fall to the tenant default or slip through the unmanaged path entirely. The policy is what turns FileVault, firewall, and OS-version posture into an access decision.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies
A Defender Antivirus policy is configured and assigned for macOS
wt.intune.macos.defender-av-policy-assigned
MEDIUMChecks that at least one Intune Endpoint security Antivirus policy (template family endpointSecurityAntivirus) exists for macOS and is assigned, putting Microsoft Defender for Endpoint's antivirus configuration on Macs under management.Macs are no longer a niche target - stealers and loader campaigns ship macOS builds as a matter of course. XProtect's baseline is not configurable or reportable; a managed Defender AV policy gives Macs enforced real-time protection with central visibility, matching the bar already set for Windows.DeviceManagementConfiguration.Read.All - via intuneConfigurationPolicies
macOS DEP enrollment protects the local admin with cloud LAPS
wt.intune.macos.dep-laps-enforced
MEDIUMChecks that Apple Automated Device Enrollment (DEP) is set up with at least one enrollment profile that creates a managed local administrator (macOS cloud LAPS) and that imported DEP devices actually use such a profile. Missing DEP tokens, profiles, LAPS configuration, or device usage each fail (mirrors the upstream chain). Admin account names are not collected - only presence.A fleet enrolled with a shared static local-admin password is one credential away from total lateral movement across every Mac: each technician knows it, nothing rotates it, and it outlives everyone who set it. LAPS-managed admin accounts make each machine's password unique, rotated, and escrowed - the local admin stops being a fleet-wide skeleton key.DeviceManagementServiceConfig.Read.All - via depEnrollmentProfiles
FileVault encryption is enforced by an assigned policy
wt.intune.macos.filevault-policy-assigned
HIGHChecks that at least one assigned macOS policy enforces FileVault disk encryption - either a Settings Catalog Full Disk Encryption policy with FileVault2 Enable set to On, or a classic endpoint-protection profile with fileVaultEnabled. Either form passes, per Microsoft Zero Trust Assessment v2.4.0.A lost or stolen Mac without FileVault is a data breach: target-disk mode or a lifted SSD reads everything, no password needed. Policy-enforced FileVault (with the recovery key escrowed to Intune) makes device loss an inventory event instead of an incident - but only where a policy actually reaches devices.DeviceManagementConfiguration.Read.All - via macosConfigurationProfiles
A macOS firewall policy is configured and assigned
wt.intune.macos.firewall-policy-assigned
MEDIUMChecks that at least one assigned macOS Settings Catalog policy enables the application firewall (com.apple.security.firewall → Enable Firewall). Complements the CIS macOS checks that assert firewall settings on legacy configuration profiles; this covers the Settings Catalog path.macOS ships with its application firewall OFF by default. Unmanaged, every Mac on a hostile network (airport, hotel, coffee shop) exposes whatever services happen to be listening. An enforced firewall policy closes that inbound surface fleet-wide and keeps it closed.DeviceManagementConfiguration.Read.All - via intuneConfigurationPolicies
Platform SSO with the Microsoft extension is configured for macOS
wt.intune.macos.platform-sso-configured
MEDIUMChecks that at least one assigned macOS Settings Catalog policy configures Extensible Single Sign On with Microsoft's Enterprise SSO extension (com.microsoft.CompanyPortalMac.ssoextension) - the Platform SSO configuration that binds macOS sign-in to Entra ID.Platform SSO turns the Mac's local login into an Entra ID credential - hardware-bound, phishing-resistant, covered by Conditional Access - and eliminates the password-sync drift between local and cloud accounts. Without it, Macs authenticate to M365 with re-typed passwords that phishing pages capture as easily as on any unmanaged device.DeviceManagementConfiguration.Read.All - via intuneConfigurationPolicies
A macOS software update policy is configured and assigned
wt.intune.macos.update-policy-assigned
MEDIUMChecks that at least one macOS software update policy exists and is assigned - either the classic MDM form (macOSSoftwareUpdateConfiguration) or a declarative (DDM) Settings Catalog software-update policy. Either form passes, per Microsoft Zero Trust Assessment v2.4.0.macOS point releases carry the same actively-exploited WebKit and kernel fixes as iOS, and unmanaged Macs update whenever their owners feel like rebooting. An assigned update policy converts Apple's patch cadence into an enforced fleet deadline instead of a suggestion.DeviceManagementConfiguration.Read.All - via macosConfigurationProfiles
An enterprise Wi-Fi profile is assigned for macOS
wt.intune.macos.wifi-enterprise-assigned
LOWChecks that at least one macOS Wi-Fi configuration profile using WPA-Enterprise (802.1X certificate authentication) exists and is assigned.Macs on a passphrase-secured corporate network share one secret with every other client - leaked once, it authenticates anyone, and it cannot distinguish the real access point from an attacker's. 802.1X with per-device certificates removes the shared secret and gives devices mutual authentication with the network.DeviceManagementConfiguration.Read.All - via macosConfigurationProfiles
Device enrollment for personally owned devices is blocked by default
wt.intune.personal-enrollment-blocked
MEDIUMChecks that Intune device enrollment is blocked by default for personally owned devices, ensuring only corporate-owned devices can be enrolled without explicit administrator approval.Personal devices enrolled in Intune may not meet corporate security baselines and introduce risk of data leakage through unmanaged personal apps, cloud backups, and platform features outside corporate MDM control. Blocking personal enrollment by default prevents users from placing unvetted devices into the managed device pool, which could be used to bypass device-compliance Conditional Access policies.DeviceManagementServiceConfig.Read.All - via deviceEnrollmentConfigurations
Company Portal branding includes IT support contact details
wt.intune.portal-branding-configured
LOWChecks that a Company Portal branding profile carries an organisation display name, IT support phone number, and IT support email - either on the default profile or on an assigned custom profile. Watchtower records only the PRESENCE of these fields, never the contact details themselves.Users who recognise the genuine Company Portal - the org name and a real 'call IT here' - are measurably harder to walk through a look-alike enrollment or password-reset flow. And when something does look wrong, the support contact on the page is the difference between a report and a shrug.DeviceManagementServiceConfig.Read.All - via intuneBrandingProfiles
Custom Intune scope tags exist and are assigned
wt.intune.scope-tags-assigned
MEDIUMChecks that at least one custom Intune scope tag (beyond the built-in Default) exists and is assigned. Scope tags are how Intune scopes delegated admins - helpdesk, regional IT - to their own slice of the device estate.A tenant running only the Default scope tag gives every Intune role holder visibility and reach over the entire estate: the least-privilege story ends at the role, not the scope. One compromised or careless helpdesk account then touches every device instead of its own region's.DeviceManagementRBAC.Read.All - via roleScopeTags
Intune Terms and Conditions policies exist and are assigned
wt.intune.terms-and-conditions-assigned
LOWChecks that at least one Intune Terms and Conditions policy exists and is assigned, recording user acceptance of the organisation's acceptable-use terms at enrollment.The acceptance record is the artifact legal and HR need when device misuse becomes a dispute: without it, 'the user agreed to the policy' is an assertion, not evidence. Collecting it at enrollment - before access is granted - is the only moment the organisation has guaranteed leverage.DeviceManagementServiceConfig.Read.All - via termsAndConditionsPolicies
Core Attack Surface Reduction rules are enforced
wt.intune.win.asr-rules-assigned
HIGHChecks that both of the ZTA-required Attack Surface Reduction rules - Block execution of potentially obfuscated scripts and Block Win32 API calls from Office macros - are set to at least Warn (Warn or Block) in assigned Windows policies. The two rules may live in different policies.These two ASR rules close the most-travelled initial-execution paths on Windows endpoints: obfuscated PowerShell/JScript droppers and Office macros calling into Win32 to inject shellcode. Defender only enforces an ASR rule where a policy sets it and reaches the device - an unset or unassigned rule is off.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
Windows automatic MDM enrollment is enabled
wt.intune.win.auto-enrollment-enabled
MEDIUMChecks that the Microsoft Intune MDM enrollment policy applies to users (appliesTo is not none), so Entra-joining a Windows device automatically enrolls it into Intune management.Without automatic enrollment, device management depends on someone remembering a manual step - and every forgotten device is a corporate-signed-in Windows machine with no compliance policy, no baseline, and no remote wipe. Auto-enrollment makes 'joined' imply 'managed', closing the unmanaged-device gap at its source.Policy.Read.All - via mobileDeviceManagementPolicies
BitLocker device encryption is required by an assigned policy
wt.intune.win.bitlocker-policy-assigned
HIGHChecks that at least one assigned Windows policy sets Require Device Encryption to enabled (device_vendor_msft_bitlocker_requiredeviceencryption = 1), enforcing BitLocker across targeted devices.A lost or stolen laptop without disk encryption is a data breach: the disk can be read by booting another OS, no password required. BitLocker makes the device's storage unreadable without the key - but only where policy enforces it; relying on users or OEM defaults leaves an unknown fraction of the fleet unencrypted.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
A Windows compliance policy exists and is assigned
wt.intune.win.compliance-policy-assigned
MEDIUMChecks that at least one Windows compliance policy exists and is assigned. Both the classic (windows10CompliancePolicy) and Settings Catalog compliance forms count.Compliance state is the signal Conditional Access device gating keys on: require compliant device means nothing on a platform with no assigned compliance policy, because every device reports whatever the tenant default dictates. An assigned policy is the prerequisite for making device health a real access condition.DeviceManagementConfiguration.Read.All - via windowsCompliancePolicies
A Defender Antivirus policy is configured and assigned for Windows
wt.intune.win.defender-av-policy-assigned
MEDIUMChecks that at least one Intune Endpoint security Antivirus policy (template family endpointSecurityAntivirus) exists for Windows and is assigned, putting Defender Antivirus configuration (real-time protection, cloud protection, scans) under management.Defender ships on every Windows device, but unmanaged its critical switches - real-time protection, cloud-delivered protection, tamper-visible exclusions - are user- and malware-adjustable. A managed, assigned AV policy makes protection state enforced and reportable instead of assumed.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
Endpoint Analytics health monitoring is assigned to Windows devices
wt.intune.win.endpoint-analytics-enabled
LOWChecks that at least one Windows health monitoring configuration profile (the policy that feeds Endpoint Analytics) exists and is assigned.Endpoint Analytics is the baseline for 'this device is behaving strangely': boot degradation, agent failures, and restart anomalies only stand out against telemetry that was flowing before the incident. Without the health-monitoring profile, that history simply does not exist when you need it.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
A Windows Firewall policy is configured and assigned
wt.intune.win.firewall-policy-assigned
MEDIUMChecks that at least one Intune Endpoint security Firewall policy (template family endpointSecurityFirewall) exists and is assigned. Without a managed firewall policy, host firewall state is whatever each device happens to have.The Windows firewall is the endpoint's own network boundary - it is what stands between a compromised peer on the same network and lateral movement onto the device. Unmanaged, it can be silently disabled by users or malware; a managed, assigned policy makes the firewall state enforced and self-healing across the fleet.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
Windows Hello for Business is enabled
wt.intune.win.hello-for-business-enabled
MEDIUMChecks that Windows Hello for Business is deployed - either the tenant-wide enrollment configuration is enabled, or a group-assigned PassportForWork Settings Catalog policy exists. Either path passes, per Microsoft Zero Trust Assessment v2.4.0.Windows Hello for Business replaces the password at the Windows sign-in with a device-bound key gated by PIN or biometrics - a phishing-resistant credential users touch every day. Where it is not deployed, every Windows unlock re-exercises the password, keeping the most phishable credential warm in users' muscle memory.DeviceManagementServiceConfig.Read.All - via windowsHelloEnrollmentConfigurations
Windows LAPS protects local administrator credentials
wt.intune.win.laps-policy-assigned
HIGHChecks that at least one assigned Account protection (Windows LAPS) policy backs the local administrator password up to a directory (Entra ID or on-premises AD) with automatic account management enabled - per Microsoft Zero Trust Assessment v2.4.0.Without LAPS, local administrator passwords are typically identical across imaged machines - one recovered hash opens every device (the classic pass-the-hash lateral-movement path). LAPS gives every device a unique, rotated password escrowed in the directory, so compromising one machine's local admin is worth exactly one machine.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
Local account membership is centrally managed
wt.intune.win.local-accounts-policy-assigned
MEDIUMChecks that at least one assigned Windows policy configures the Local Users And Groups CSP (device_vendor_msft_policy_config_localusersandgroups_configure), putting local group membership - notably local Administrators - under central control.Uncontrolled local accounts accumulate: help-desk-created admins, vendor accounts, one-off exceptions that never expire. Each is a sign-in surface Conditional Access never sees. Central management makes local Administrators membership declarative - drift back to the policy state instead of accreting forever.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles
A security baseline is configured and assigned
wt.intune.win.security-baseline-assigned
MEDIUMChecks that at least one Intune security baseline instance exists and is assigned. Baselines apply Microsoft's hardened Windows defaults - hundreds of vetted settings - in one policy.A security baseline captures years of Microsoft hardening guidance (credential protection, SMB/LDAP signing, UAC, audit policy) that no team rebuilds setting-by-setting. Without one assigned, Windows devices run OS defaults tuned for compatibility, not defense - and posture depends on whichever individual settings someone happened to configure.DeviceManagementConfiguration.Read.All - via securityBaselineIntents
A Windows Update ring is configured and assigned
wt.intune.win.update-policy-assigned
MEDIUMChecks that at least one Windows Update for Business configuration (windowsUpdateForBusinessConfiguration) exists and is assigned, putting patch cadence under management.Unmanaged Windows updates mean every device patches on its own schedule - or not at all, once a user hits pause. The window between a patch Tuesday and a fleet actually being patched is where commodity exploitation happens; an assigned update ring makes that window a policy decision instead of a per-device accident.DeviceManagementConfiguration.Read.All - via windowsConfigurationProfiles