M365Clarity Blog · 18 July 2026 · Intune Device Management MSP

Intune Health Report: What M365Clarity Scans and Why It Matters

Microsoft Intune is one of the most powerful tools in the Microsoft 365 stack — and one of the most commonly misconfigured. Organisations license Intune, enrol devices, and assume the job is done. The reality is that a correctly licensed Intune deployment with poor configuration offers little more protection than no Intune at all.

M365Clarity's Intune Health Report scans your Intune environment via the Graph API and surfaces the gaps that matter — not a list of every policy, but the specific issues that represent actual risk. Here's what it checks and why each one matters.

Device compliance

Compliance policy coverage
Whether compliance policies exist and cover all device platforms. A tenant with no compliance policy has no baseline — every device is treated as compliant by default, which undermines Conditional Access entirely.
Compliance grace period
How long non-compliant devices retain access before being blocked. A 30-day grace period means a device can be non-compliant for a month before Conditional Access takes effect. Best practice is 3 days or less.
Non-compliant device count
How many enrolled devices are currently non-compliant. M365Clarity surfaces the count and flags it when non-compliant devices exceed 10% of enrolled devices.

Windows Update for Business (WUfB)

Update rings configured
Whether WUfB update rings exist. Without update rings, Windows devices update on Microsoft's default schedule — which often means feature updates land the day they release, with no testing window. Best practice is three rings: pilot, general, and broad.
Deferral periods
How long feature and quality updates are deferred. A pilot ring with zero deferral defeats the purpose. M365Clarity checks that at least one ring has a meaningful deferral period (14+ days for quality updates).

BYOD and Mobile Application Management (MAM)

App protection policies
Whether MAM policies exist for iOS and Android. Without app protection policies, company data accessed on a personal device has no protection — the Outlook app on a personal phone can copy emails to the phone's native clipboard or other apps with no restriction.
Platform coverage
Whether policies cover both iOS and Android. It's common to configure one and forget the other. M365Clarity flags single-platform coverage as amber.

Configuration profiles

BitLocker encryption policy
Whether a BitLocker enforcement policy exists. Without it, encryption on Windows devices depends on the user having enabled it manually — which most haven't. M365Clarity checks for a policy, not just whether individual devices are encrypted.
Endpoint security profiles
Whether antivirus and firewall endpoint security profiles are configured and assigned. These are separate from compliance policies — a device can be compliant but have no antivirus profile deployed.

The AI lost-device scenario

The most distinctive part of the M365Clarity Intune Health Report is the AI-generated lost-device scenario. Rather than listing compliance scores, it generates a realistic description of exactly what would happen to your tenant's data if a device was lost today.

The scenario is built from your actual configuration. If BitLocker is not enforced, the scenario describes the data on the device as readable. If no remote wipe policy exists, it describes the inability to remove company data. If MAM policies are missing for personal devices, it describes email data persisting on the device indefinitely.

Why this matters for MSPs: The lost-device scenario is one of the most effective tools for communicating Intune gaps to non-technical decision makers. A compliance score of 72% means nothing to a business owner. "If an employee's laptop was stolen today, an attacker could access your client files because BitLocker is not enforced" is immediately actionable.

How to access the report

The Intune Health Report is available to Pro plan subscribers under Security & Compliance → Intune Health. It requires that your connecting account has the Intune Administrator or Global Reader role — the report reads Intune configuration data, not user device data, so it doesn't require device-level permissions.

Results are generated on first open and cached per scan. After a rescan, the cache clears and the report regenerates with fresh data.

Intune and Agent 365 governance: If your organisation is evaluating Microsoft Agent 365, M365Clarity also checks Intune as part of the Agent 365 governance readiness assessment. Intune enrolment and compliance policies are prerequisites for a secure agent deployment — the Intune Health Report surfaces these gaps before you commit to expanding your AI footprint.

Check your Intune health

Scan your tenant and see the Intune Health Report including the AI lost-device scenario.

Run a free scan →