MDM and endpoint hardening: a baseline
The device-side controls that make identity and MFA trustworthy: enrollment, disk encryption, patch enforcement, configuration baselines, compliance-gated access, and remote wipe.
What to implement
Enroll every device in MDM, enforce full-disk encryption and screen lock, mandate OS/app patching with deadlines, apply a hardened configuration baseline (CIS/vendor benchmarks), gate access on device compliance via conditional access, and enable remote lock/wipe. The endpoint is where credentials and sessions actually live: device trust is the foundation identity controls stand on.
Strong authentication assumes the device is trustworthy. A compromised or unmanaged endpoint can steal session tokens after login, keylog a password, or exfiltrate a vault, bypassing MFA entirely. Endpoint management is therefore not a separate concern from identity; it's the ground it rests on, and a core pillar of zero trust.
Enrollment and inventory
- Enroll all corporate devices in MDM/UEM (Intune, Jamf, or equivalent); use automated/zero-touch enrollment so devices are managed from first boot.
- Maintain an accurate asset inventory: you cannot secure endpoints you don't know about.
- For personal devices (BYOD), use app protection / managed app policies or containerization so work data is controlled without owning the whole device.
The hardening baseline
- Full-disk encryption enforced and its key escrowed (BitLocker/FileVault), so a lost device is not a data breach.
- Screen lock with a strong passcode and short idle timeout; biometrics for convenience.
- Patch enforcement with deadlines (OS and third-party apps), not optional user-deferred updates. Unpatched software is the most exploited weakness.
- Configuration baseline from a recognized benchmark (CIS Benchmarks, vendor security baselines): disable legacy protocols, restrict local admin, configure the host firewall.
- Least privilege on the endpoint: remove standing local-admin rights; use elevation-on-request tooling.
- EDR / antimalware deployed and reporting to a central console.
- Application control (allowlisting where feasible) and controlled installation sources.
Gate access on device compliance, not just user identity
Wire MDM compliance signals into conditional access: only devices that are enrolled, encrypted, patched, and healthy may reach sensitive resources. This is what turns MDM from an inventory tool into an access control: an attacker with valid credentials on an unmanaged device still gets blocked.
Loss, theft, and offboarding
- Enable remote lock and wipe; for BYOD, use selective wipe that removes only corporate data.
- Tie device deprovisioning to the leaver process so a departing employee's device access and data are pulled promptly.
- Log and alert on non-compliant or jailbroken/rooted devices attempting access.
Endpoint compliance evidence
Track enrollment coverage (managed vs total known devices), encryption and screen-lock compliance rates, patch-latency percentiles (e.g. % critical patches applied within SLA), EDR coverage, count of devices with standing local admin, and conditional-access block events for non-compliant devices.