Capability

Data protection and endpoint

Labels nobody applies and policies stuck in test mode protect nothing. This is about the controls actually taking effect.

Purview and Intune are where good intentions go to sit in reporting mode. The pattern we see is a label taxonomy designed by committee that nobody in the business understands, DLP policies left in simulation for two years because nobody wanted to be the one who blocked an email, and device compliance that reports green because the grace period was never reduced from thirty days.

What we assess

  • Sensitivity labels. Whether the taxonomy makes sense to the people expected to use it, and whether it has been applied to anything at all outside the pilot group.
  • DLP effectiveness. Policies sitting in simulation indefinitely, rules that fire so often everyone ignores them, and the paths that are not covered at all.
  • Retention and audit. Whether retention is configured to a real requirement, and whether your audit log retention would survive contact with an actual investigation.
  • Device compliance. What the compliance policy genuinely requires, how many devices quietly fail it, and how long a failing device stays trusted.
  • Enrolment and unmanaged devices. Personal devices holding corporate access, and endpoints that never made it into management.
  • Hardening baselines. Security baselines applied, and how far they have drifted since.

What we do

  • Label taxonomy designed around how the business actually classifies its work, then rolled out with auto-labelling rather than relying on people to choose correctly
  • DLP tuning and the move out of simulation into enforcement, staged by policy and by group
  • Intune configuration: compliance policies, security baselines, and the Conditional Access integration that makes compliance mean something
  • Endpoint hardening, including attack surface reduction and local administrator rights
  • Retention and audit configuration set to what an investigation would actually need
  • Cleaning up the enrolment gap, so the device inventory matches reality

Found: A device compliance policy correctly required disk encryption and a minimum OS build, but marked non-compliant devices as compliant throughout a thirty day grace period that had never been reduced from the default.

Fixed: Grace period cut to twenty four hours, a notification path added so users knew before they lost access, and the eleven devices that had been failing for months were remediated.

The policy was correct and the reporting was green. The gap was in the setting nobody looks at, which is exactly what an outside read is for.

The rest of the stack

This does not sit on its own

The findings that matter most usually cross between these areas. We look at all of them, whether or not that is what you asked us to look at.

Want a look at your data protection and endpoint?

An assessment can be scoped to this area alone, or to the whole estate. Tell us what is worrying you and we will tell you which is worth paying for.