1Security + Microsoft Intune
Intune manages the devices you enroll. We show you the ones you did not.
In a typical tenant, one device in five that opens company files never enrolled anywhere: a home laptop, a phone, a browser on a borrowed machine. 1Security finds them from real sign-in and file activity, shows which users and files each one carried, and reads Intune's compliance and management state onto the same row. You enroll, block or wipe in Intune - with a list instead of a guess.
What Intune does
Intune runs the fleet you enroll, end to end.
Enrollment, configuration, compliance and remediation for Windows, macOS, iOS and Android, from one console.
Enroll once, inherit everything
A device joins and picks up configuration profiles, security baselines, update rings, certificates and apps. Thousands of machines converge on the state you declared, and stay there.
Compliance that Conditional Access can act on
Encryption, OS version, jailbreak status and more become a compliance verdict. Conditional Access reads it, so a non-compliant device does not get in until it is fixed.
Remediation from the console
Wipe, retire, restart, disable, push a script or an app. When a device has to stop being a risk, Intune is where that happens, and it sticks.
What you still need to know
Enrollment covers the devices you know. Your data is also opened from the ones you do not.
Every organisation has a BYOD policy. Very few have the BYOD list. Enrolled laptops are documented to the last certificate; the personal phone reading email, the home PC that synced a SharePoint library and the browser session on a contractor's machine are on no list, because nobody asked them to join. In tenants we connect to, roughly one device in five that opens company data has never enrolled.
Those are also the devices that matter most in an identity attack. Attackers log in with a valid token, so every log line looks legitimate - the one thing that does not fit is the machine. A stolen session replayed from an unknown laptop is a device your data has met and your inventory has not.
So the question on top of enrollment is: which devices actually touch our Microsoft 365 data, what did each one open, who was on it, where has it been - and how do we get the ones that belong into Intune and the ones that do not out of the tenant.
What 1Security adds
Every device that touched your data, built from activity.
1Security rebuilds the device list from sign-ins and data access, so it reflects how your data is actually reached, and puts Intune's view of each device on the same row.
- 01
Registered, unregistered and shadow devices
Every device seen in sign-ins or file activity gets a stable identity, whether it enrolled or not. Shadow devices - seen opening data with no matching sign-in - are flagged separately, because that pattern is the signature of a token used somewhere it should not be.
- 02
Last seen from real activity
Last-seen comes from the last file opened, mail read or sign-in, next to counts you can sort by: sign-ins, distinct users, apps and IP addresses per device. Devices unused for 90 days but still holding access are one filter away.
- 03
Files, users and places per device
Which files a device touched, which accounts it carried, and a travel timeline of where it has been active - country, city, network - with one click to the exact events, up to three years back.
- 04
Intune and Entra state on the same row
Compliance, management state, ownership and trust type are read from Intune and Entra as they are, so the two views never disagree. Filters like Unmanaged + Personal + seen this month are one click.
How the two work together
Find it in 1Security. Fix it in Intune.
Intune stays exactly where it is: enrollment, compliance, remediation. 1Security connects to the same tenant with read-only consent, no agents, and shows first findings the same day: every device rebuilt from activity, with the files, users and locations attached and Intune's posture fields read onto the row. A Business Basic license is enough for everything 1Security produces on its own; an Intune license adds the compliance and management columns. When the list shows a machine that should be enrolled, blocked or wiped, you do that in Intune - with the exact device, its users and its files in front of you.
- Same dayfrom read-only consent to the first device list
- 1 in 5devices opening company data that never enrolled, in a typical tenant
- 3 yearsof per-device activity history
Joint use case
The BYOD reality check, in two clicks.
Filter Devices to Unmanaged + Personal, seen in the last 30 days. The result is the exact list of personal, unmanaged devices currently opening company files - each with its users, its file activity and where it has been. In a mid-size tenant that list is usually a few hundred rows long, and nobody had it before.
Sort it by files touched or sensitive files reached, and the top of the list is your enrollment campaign: the devices that carry the most data and belong to people who should be on managed hardware. Enroll them in Intune. Block or wipe the ones that should not be there. The same sweep at offboarding finds a leaver's phone and laptop while their token still works.
Then keep the filter as a saved view with an alert: a new unmanaged device opening sensitive files becomes an email within minutes, not a discovery at the next audit.
See every device that opens your data. Then manage it in Intune.
Connect read-only in the morning. By the afternoon you have the list of unmanaged devices touching company files, with users and files attached - ready to enroll, block or wipe.
Or keep assuming the enrolled fleet is the whole fleet.