Skip to main content

2 posts tagged with "EndpointSecurity"

Defender, baselines & attack surface reduction.

View All Tags

Your Tenant Says Every Device Is Compliant. It's Lying.

ยท 5 min read
Fabio van der Burg
Technical Consultant, Nerd

You did everything right. Conditional Access requires a compliant device before anyone touches company data. You tested it, it worked, you closed the ticket, you felt good about yourself. โ˜•

Then one Tuesday you spot a device in the sign-in logs you have never seen before. Personal laptop. No management. No Intune. Nothing. And right next to it, in cheerful little green letters: Compliant.

Wait. What.

Wait... Standard Users Can Do *WHAT* Now?!

ยท 3 min read
Fabio van der Burg
Technical Consultant, Nerd

It started with a ticket:

"Hi IT, I wiped my device because Teams stopped syncing. Can you fix it?"

Weird.
So you check โ€” and sure enough, the device is gone from Intune. Just... gone.
No wipe, no retirement event, nothing in logs. It just vanished like a magician's assistant. ๐ŸŽฉโœจ

Turns out, the user simply went to:
Settings โ†’ Accounts โ†’ Access work or school โ†’ Disconnect

That's it. Two clicks. No password prompt. No MFA.
And poof โ€” device is unmanaged.