shadow device detection

One in five devices touching your data never enrolled. We list them all.

In a typical tenant, one device in five that touches company data is not in the directory at all - personal phones, home PCs, and machines that read files without ever signing in. 1Security rebuilds every device from the sign-ins and activity your tenant already produces, classifies it as registered, unregistered or shadow, and shows what each one reached. Nothing installed on any endpoint.

  • 3
    device classes - registered, unregistered, shadow - for every device seen
  • 0
    agents, profiles or certificates - devices are rebuilt from activity alone
  • Today
    last-seen per device, derived from this morning's activity rather than a periodic directory refresh

The problem

Attackers log in. The account looks normal. The device is what does not fit.

Once someone holds a valid token, every log line is legitimate, because the credential is. The machine using it is the only part of the story that gives them away.

A finance account that suddenly works from a Windows PC nobody enrolled, in a browser your builds never ship, is a lead no account-side telemetry gives you. That is why the device is where most identity attacks first become visible - and why the device list is a security control, not an IT hygiene chore.

Enrollment-based management starts, by design, at enrollment. A device that never enrolled has no record anywhere. In a typical tenant that is 15-25% of the devices touching data - personal phones and home PCs - plus a smaller set that never authenticated at all.

1Security calls that last set shadow devices: machines seen opening or downloading data with no observed sign-in. That pattern is the signature of a stolen or replayed token being used somewhere it should not be, and it is visible from your audit data without deploying anything.

Capabilities

A device inventory built from what actually happened.

Every device is a persistent identity with its users, locations, activity and Intune posture attached - kept current from activity.

  • Shadow devices, one click

    The Shadow chip on the Devices screen filters to machines seen accessing data with no observed authentication, with a live count. In most tenants the first pass finds a handful - each one is either a token problem or a gap in your logging, and both are worth an hour.

  • Unregistered devices with a stable identity

    Devices outside the directory are keyed by a fingerprint and their sessions are stitched onto it. That turns "an odd event last Tuesday" into "this machine, these 40 documents, these two accounts, first seen 3 days ago".

  • users, apps, IPs

    Numbers no directory has

    Sign-in count, distinct users, applications and IP addresses per device, plus manufacturer, model and browser. A device shared by 4 users across 9 IPs reads very differently from a one-user laptop.

  • A last-seen that is actually today

    1Security derives last-seen from the activity logs, so a device that opened a file this morning shows this morning - not the date of its last directory refresh.

  • Shadow, Unmanaged, Personal

    Nine quick filters with live counts

    Shadow, Unregistered, Unmanaged, Non-compliant, Rooted, Compliance expired, No activity in a year, Personal, Disabled. They combine: Unmanaged + Personal is the BYOD-nobody-controls list, usually dozens of devices on the first day.

  • Where each device has been

    The Locations tab in the device drawer is a travel timeline: every country, city and network the device was active from, newest first, with event counts. "Has this laptop started connecting from a hosting provider abroad?" takes seconds.

Working with Intune

Intune enforces. 1Security discovers.

Compliance, management state, ownership and trust type are read natively from Entra ID and Intune, so the posture you see always agrees with your MDM.

On top of that shared foundation, 1Security adds the discovery layer: the devices that never enrolled, a last-seen derived from real activity, and the data view - which files, users and locations a device has touched.

None of it needs extra licensing. A Business Basic tenant is enough for everything 1Security produces itself: discovery, classification, activity statistics, locations and the data linkage. An Intune license enriches the same rows with Intune's own posture fields and unlocks remediation - when a device deserves to be wiped, retired or disabled, you do it in Intune or Entra, and 1Security tells you exactly which ones deserve it.

In practice

A confidential file left at 22:40. From what?

What device attribution looks like on the day it matters.

  1. 01

    Open the download in Activity logs

    The audit event carries a session id but no device id - which is exactly where most tools stop. In 1Security the row already shows the device column, because the session was mapped to a fingerprinted device when it was ingested.

  2. 02

    Open the device

    An unenrolled Windows machine, a browser your builds never ship, seen with 2 different accounts and 9 IP addresses this month, first seen 3 days ago. Unmanaged, Personal, no Intune record.

  3. 03

    Read the Locations tab

    The travel timeline just added a country your team has never worked from, on a hosting network. Impossible travel is flagged against the account's last known city. This is not an inventory row - it is a lead.

  4. 04

    Act in minutes

    Disable the account and expire its sessions from 1Security under the opt-in write module, behind the review window; wipe or retire the device in Intune. The "from what?" question was answered before the call started.

The difference

What activity-based discovery adds.

These come from rebuilding devices from activity, not from adding columns to a directory.

  • Devices that never enrolled anywhere, discovered from sign-ins and data activity
  • Shadow devices: data access with no observed authentication - the closest passive telemetry gets to "this token is not with its owner"
  • Last-seen from activity logs - a device that opened a file this morning shows this morning
  • Session-to-device attribution - audit events carry a session id, and the mapping to a fingerprinted device is what makes that traffic attributable
  • Distinct users, apps and IPs per device - a shared machine reads differently from a personal one
  • A per-device travel timeline with one-click pivot to the exact events from each place
  • Unmanaged + Personal in one click - the BYOD list nobody controls, with a live count
  • The lingering devices of a departed employee, still holding a session, found before they become a breach

Deployment

Nothing to install. Nowhere.

Connect with read-only consent and devices assemble from the activity your tenant already produces - the first shadow and unregistered devices show the same day. No agent, no certificate rollout, no network appliance, and no Intune license needed for anything 1Security derives itself.

  • 1 day
    from read-only consent to the first shadow-device findings
  • 0
    endpoints touched - reconstruction runs from audit and sign-in data
  • 100%
    of Intune posture fields read natively from Microsoft, so both tools agree

Use cases

Three device questions answered in week one.

The BYOD audit: filter Unmanaged + Personal with a recent last-seen range and you are looking at exactly the private machines that touched company data lately - each with its users, files and places attached. Most tenants meet dozens of devices they cannot explain within the first hour.

The offboarding sweep: a leaver's account is disabled, but their devices linger. Filter Devices by user, review what each machine still reached, and close the loop - including the personal laptop nobody knew about.

Incident scoping: when an account is suspected compromised, its device list separates the story into "their usual laptop" and "a fingerprinted stranger first seen this week". Pair it with a previously unseen origin from the travel timeline and you have about as close to a definitive token-theft signal as passive telemetry gets. 1Security finds and ranks; Intune enforces.

  • Impossible Travel Detection

    The location half of the same story - where every device and account actually works from, with impossible-travel verdicts.

    Explore locations
  • Conditional Access Monitoring

    Whether the sign-ins those devices make are governed by any policy at all - and the share that walk in ungoverned.

    Check your coverage
  • 1Security + Microsoft Intune

    How the two products split the device problem: discovery and ranking here, enforcement there.

    See the pairing

FAQ

Common questions.

What exactly is a shadow device?

A device observed accessing your data with no observed authentication at all - for example, a sensitive document opened from a machine that never signed in the normal way. It is the riskiest subset of unregistered devices, because that pattern is the signature of a legitimate token being used somewhere it should not be.

Do I need Intune for this to work?

No. Everything 1Security produces itself - discovery, classification, activity statistics, locations, data linkage - works on a Business Basic tenant. If you run Intune, its posture fields (compliance, management state, ownership) enrich the same rows, read natively from Microsoft, so the two tools never disagree.

Does 1Security install anything on devices?

Nothing. Devices are reconstructed server-side from the sign-in and activity data your tenant already produces. There is no agent, no profile, no certificate - which is also why unmanaged and shadow devices are visible at all.

Can 1Security wipe or disable a risky device?

Disabling a device account is available through the opt-in write module, staged behind the same review window as every other automation. Wipe and retire stay Intune operations by design - 1Security tells you exactly which devices deserve them, and the action lands in the tool built to perform it.

How many unknown devices do tenants usually find?

On the first day it is common to see 15-25% of the devices touching data outside the directory - mostly personal phones and home PCs - and a handful of shadow devices. The share matters less than the list: each row comes with the users, files and locations behind it, so triage is minutes, not a project.

See every device touching your data. Then decide.

Connect read-only and the machines actually reaching your data - including the ones your inventory has never heard of - are listed the same day, each with what it opened and from where.

Or keep discovering devices one incident at a time.