INTUNE-021: Remote actions audit (wipe, retire, lock)

Platform
Entra ID / M365
Category
Intune / Endpoint Management
Severity
High
Zero Trust pillar
Devices (weight 3)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Intune remote actions such as wipe, retire, and remote lock are powerful device management capabilities that, if misused, can result in data loss or denial of service to legitimate users. Unauthorized or accidental remote wipes can destroy business-critical data on devices, while unaudited remote lock actions could indicate account compromise. All remote actions must be logged and reviewed for authorized use.

Recommended value

All remote actions logged with operator identity; wipe actions require documented approval; audit logs reviewed weekly

Remediation

Review the Intune audit logs for all remote action events including wipe, retire, remote lock, and passcode reset to identify any unauthorized or unusual activity. Implement an approval workflow for destructive remote actions such as full wipe that requires documented justification and secondary approval. Configure alert notifications for remote wipe actions to ensure security teams are immediately aware when devices are being wiped.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for INTUNE-021
ScenarioExpected verdict
not-implementedNot Assessed

Framework mappings

NIST SP 800-53
AU-6, MP-6