MDM and endpoint hardening: a baseline
The device-side controls that make identity and MFA trustworthy: enrollment, disk encryption, patch enforcement, configuration baselines, compliance-gated access, and remote wipe.
What to implement
Enroll every device in MDM, enforce full-disk encryption and screen lock, mandate OS/app patching with deadlines, apply a hardened configuration baseline (CIS/vendor benchmarks), gate access on device compliance via conditional access, and enable remote lock/wipe. The endpoint is where credentials and sessions actually live — device trust is the foundation identity controls stand on.
Strong authentication assumes the device is trustworthy. A compromised or unmanaged endpoint can steal session tokens after login, keylog a password, or exfiltrate a vault — bypassing MFA entirely. Endpoint management is therefore not a separate concern from identity; it's the ground it rests on, and a core pillar of zero trust.
Enrollment and inventory
- Enroll all corporate devices in **MDM/UEM** (Intune, Jamf, or equivalent); use automated/zero-touch enrollment so devices are managed from first boot.
- Maintain an **accurate asset inventory** — you cannot secure endpoints you don't know about.
- For personal devices (BYOD), use **app protection / managed app policies** or containerization so work data is controlled without owning the whole device.
The hardening baseline
- **Full-disk encryption** enforced and its key escrowed (BitLocker/FileVault), so a lost device is not a data breach.
- **Screen lock** with a strong passcode and short idle timeout; biometrics for convenience.
- **Patch enforcement** with deadlines — OS and third-party apps — not optional user-deferred updates. Unpatched software is the most exploited weakness.
- **Configuration baseline** from a recognized benchmark (CIS Benchmarks, vendor security baselines): disable legacy protocols, restrict local admin, configure the host firewall.
- **Least privilege on the endpoint** — remove standing local-admin rights; use elevation-on-request tooling.
- **EDR / antimalware** deployed and reporting to a central console.
- **Application control** (allowlisting where feasible) and controlled installation sources.
Gate access on device compliance, not just user identity
Wire MDM compliance signals into conditional access: only devices that are enrolled, encrypted, patched, and healthy may reach sensitive resources. This is what turns MDM from an inventory tool into an access control — an attacker with valid credentials on an unmanaged device still gets blocked.
Loss, theft, and offboarding
- Enable **remote lock and wipe**; for BYOD, use **selective wipe** that removes only corporate data.
- Tie device deprovisioning to the **leaver process** so a departing employee's device access and data are pulled promptly.
- Log and alert on **non-compliant or jailbroken/rooted** devices attempting access.
Endpoint compliance evidence
Track enrollment coverage (managed vs total known devices), encryption and screen-lock compliance rates, patch-latency percentiles (e.g. % critical patches applied within SLA), EDR coverage, count of devices with standing local admin, and conditional-access block events for non-compliant devices.