A device fleet rarely fails all at once. It drifts, one exception, one stale role, one untested policy at a time.
A solid intune security audit in 2026 should answer three things fast. Which settings define trust, which controls gate access, and which gaps need action first across Windows, macOS, iOS, and Android. That makes this checklist useful for internal audits, client reviews, and pre-renewal security assessments.
Start with baselines, compliance, and tenant controls
Begin where Intune defines what “good” looks like. If these layers are weak, every later control rests on shaky ground.
Review security baselines for drift
Audit item: compare Windows, Defender, and Microsoft 365 Apps baseline assignments against settings catalog profiles and exception groups. Why it matters: overlapping controls create conflicts and false confidence. What to verify in Intune: current baseline versions, assignment scope, filters, conflict reports, and change records. Use Microsoft Learn’s security baseline overview as your reference. Common misconfigurations: old baselines left active after a refresh, pilot groups widened to production, and one-off settings catalog entries overriding the intended baseline.

Check compliance by platform, not by template
Audit item: inspect separate compliance policies for Windows, macOS, iOS/iPadOS, and Android. Why it matters: Conditional Access trusts these results. A weak rule becomes an access gap. What to verify in Intune: minimum OS version, encryption state, password or passcode rules, jailbreak or root detection, Microsoft Defender risk level, grace periods, and actions for noncompliance. For Windows, confirm BitLocker and risk signals. For macOS, confirm FileVault and supported OS levels. For mobile, review passcode and compromised-device checks. Common misconfigurations: one copied policy for every platform, 30-day grace periods, and unsupported builds still marked compliant.
Confirm tenant-level guardrails
Review enrollment restrictions, corporate device identifiers, cleanup rules, and certificate delivery. In early 2026, multi-admin approval expanded to compliance policies, settings catalog changes, and RBAC changes, so audit whether approval is turned on and whether admins actually use it. Also review Apple certificate delivery, because new Apple enrollments are moving from SCEP to ACME in many environments. Expired tokens, stale connectors, and weak approval paths can break trust before a user even signs in.
A clean compliance dashboard can still hide risk if broad exceptions, expired tokens, or stale certs sit outside daily reporting.
Tie device trust to access and mobile data paths
A healthy device record means little if users can still reach data from the wrong place.
Map Conditional Access to real device state
Audit item: trace each access policy back to Intune signals. Why it matters: most audit failures come from exclusions and fallback paths, not from missing policies. What to verify in Intune and Entra: policies that require a compliant device or approved client app, coverage for admin portals and high-value apps, report-only testing, and a very short list of excluded emergency accounts. Review the January 2026 Intune updates if you’re using newer approval or device-trust features. On iPhone fleets, also check whether hardware-bound keys are part of your access design where supported. Common misconfigurations: permanent executive exclusions, MFA-only policies with no device requirement, and unmanaged browser access left open.

Audit app protection for BYOD and mobile-first work
Audit item: review app protection policies for iOS/iPadOS and Android, even when devices aren’t enrolled. Why it matters: this is often the last open door for corporate data. What to verify in Intune: app PIN or biometrics, approved apps, managed browser requirements, copy and paste limits, save restrictions, conditional launch rules, and selective wipe. Look closely at Outlook, Teams, OneDrive, and Office apps. Common misconfigurations: protecting enrolled users only, forgetting Android work-profile cases, allowing data moves into personal storage, or leaving unmanaged web access outside policy.
Audit endpoint controls, updates, and proof of remediation
Now move from trust decisions to hard controls on the device itself.
Inspect Endpoint Security policies by operating system
Audit item: review Endpoint Security profiles per platform. Why it matters: firewall, antivirus, disk encryption, and privilege control live here. What to verify in Intune: BitLocker key escrow, FileVault recovery key escrow, Defender onboarding, firewall state, tamper protection, and Endpoint Privilege Management assignments. Microsoft documents the core policy areas in its guide to endpoint security in Intune. In 2026, tamper protection coverage through Defender policies also matters for some unenrolled devices, so don’t assume enrollment is the only path. Common misconfigurations: duplicate settings between Endpoint Security and the settings catalog, FileVault enabled without key escrow, and Defender risk signals not tied back to compliance.
Review update rings and OS support windows
Audit item: audit patch cadence, not just patch policy presence. Why it matters: a compliant device on an old build is still exposed. What to verify in Intune: Windows update rings, feature update profiles, Autopatch readiness, restart behavior, expedite paths, and minimum OS rules for Apple and Android fleets. For shared or kiosk devices, review ring exceptions and rollback plans. Common misconfigurations: one broad ring for every user, no fast path for high-risk patches, and stale devices inflating compliance results.
Lock down admin roles and keep audit evidence
Audit item: review who can change Intune and how you prove it. Why it matters: over-privileged admins can undo good policy in minutes. What to verify in Intune: RBAC roles, scope tags, partner access, admin MFA, break-glass handling, audit log retention, and export to your SIEM or log platform. Common misconfigurations: global admins doing routine endpoint work, stale partner accounts, and no owner or due date for high-risk findings.
This quick priority view helps sort fixes:
| Priority | Fix first | Why |
|---|---|---|
| 1 | CA gaps, admin overreach | They open direct access paths |
| 2 | Compliance scoping errors | They feed bad trust signals |
| 3 | Encryption, EDR, tamper gaps | They weaken device defense |
| 4 | Reporting cleanup | It improves proof, not first-line protection |
Start with anything that lets a noncompliant or unmanaged device reach business data. Everything else comes after that.
A strong intune security audit is less about box-ticking and more about tracing trust from device state to data access. If you can prove the control, prove the owner, and prove the fix date, your 2026 fleet is in far better shape. Run that test now, before the next exception becomes your new default.

