Skip to main content

Devices

Tier 1 Checks

#CheckLicense
D01Windows automatic device enrollment is enforced to eliminate risks from unmanaged endpoints
D02Compliance policies protect Windows devices
D03Compliance policies protect iOS/iPadOS devices
D04Defender for Endpoint automatic enrollment is enforced to reduce risk from unmanaged Android threatsMDE P1
D05Local administrator credentials on Windows are protected by Windows LAPS
D06Data on Windows is protected by BitLocker encryption
D07Attack Surface Reduction rules are applied to Windows devices to prevent exploitation of vulnerable system componentsMDE P1
D08Defender Antivirus policies protect Windows devices from malware
D09Windows Firewall policies protect against unauthorized network access
D10Windows Update policies are enforced to reduce risk from unpatched vulnerabilities
D11Security baselines are applied to Windows devices to strengthen security posture
D12Data on iOS/iPadOS is protected by app protection policies
D13Conditional Access policies block access from noncompliant devicesP1
D14Compliance policies protect macOS devices
D15FileVault encryption protects data on macOS devices
D16Defender Antivirus policies protect macOS devices from malwareMDE P1

Tier 2 / Tier 3 coverage

Tier 1 covers the highest-impact device-posture essentials. Tier 2 and Tier 3 add depth on macOS-specific hardening, Android Enterprise governance, Endpoint Privilege Management, application protection beyond mobile, and Endpoint Analytics-driven risk identification.

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.