INTUNE-021: Remote actions audit (wipe, retire, lock)
- Platform
- Entra ID / M365
- Category
- Intune / Endpoint Management
- Severity
- High
- Zero Trust pillar
- Devices (weight 3)
- Golden fixtures
- 1
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Intune remote actions such as wipe, retire, and remote lock are powerful device management capabilities that, if misused, can result in data loss or denial of service to legitimate users. Unauthorized or accidental remote wipes can destroy business-critical data on devices, while unaudited remote lock actions could indicate account compromise. All remote actions must be logged and reviewed for authorized use.
Recommended value
All remote actions logged with operator identity; wipe actions require documented approval; audit logs reviewed weekly
Remediation
Review the Intune audit logs for all remote action events including wipe, retire, remote lock, and passcode reset to identify any unauthorized or unusual activity. Implement an approval workflow for destructive remote actions such as full wipe that requires documented justification and secondary approval. Configure alert notifications for remote wipe actions to ensure security teams are immediately aware when devices are being wiped.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| not-implemented | Not Assessed |
Framework mappings
- NIST SP 800-53
- AU-6, MP-6