Back to blog
IntunePublished on September 15, 20268 min read

Discovering Unmanaged Devices That Access Your Data

Personal devices, forgotten machines, ghost accounts: how to detect the unmanaged devices reaching your data and bring them under control.

In almost every organisation, unknown devices access company data. A personal phone set up for email, an old laptop never enrolled in Intune, a contractor's machine or a family computer used for remote work: all of these are endpoints outside any control. You cannot protect what you cannot see, so the very first step of serious security is an honest inventory of what actually reaches your data, not of what you assume about your fleet.

Why unmanaged devices are dangerous

An unmanaged device is not a mere administrative detail: it is a potential entry point that entirely escapes your security policies and your visibility.

  • They escape the company's encryption, antivirus and update policies.
  • They may keep company data locally, outside any control or backup.
  • If lost or stolen, no remote wipe is possible on these devices.
  • They are a major blind spot for ISO 27001, NIS2 and GDPR compliance.
  • They can introduce malware into the information system through legitimate access.

The danger lies in the fact that these devices use valid credentials. To the system, access from an infected family computer looks like legitimate access, because it presents the right password. Without a rule that distinguishes compliant devices from the rest, nothing stops it. Worse, an unmanaged device that is compromised can quietly serve as a foothold for weeks before anyone notices, precisely because it never appears in your management console.

How to detect them

The good news is that Microsoft 365 and Entra ID keep a trace of every sign-in. These signals, used properly, let you build the real list of devices reaching your resources, including those you had never recorded.

  • Review Entra ID sign-in logs to spot unenrolled devices.
  • Cross-check the list of devices enrolled in Intune against actual app access.
  • Flag access coming from unusual operating systems or geographic locations.
  • Identify accounts still using legacy authentication, often tied to unmanaged devices.

Bringing them under control

  • Require Intune enrolment for any device that accesses company data.
  • Block non-compliant devices through Conditional Access rules.
  • Offer a scoped BYOD enrolment with selective wipe for accepted personal devices.
  • Communicate the rule clearly to staff: no compliance, no access to data.
Every invisible device is a risk: inventory comes before protection.

A three-stage approach

Regaining control of an opaque fleet is done gradually, not abruptly, so you do not lock out a team overnight. Here is the sequence that works.

  1. 1Inventory: build the real list of devices reaching your data using Entra ID logs.
  2. 2Scope: decide which devices to enrol, which to move to managed BYOD, which to block.
  3. 3Enforce: enable Conditional Access gradually, previewing the impact at each step.

A worked example

An SMB believes it manages 45 machines. Reviewing the Entra ID sign-in logs, it discovers 70 distinct devices reaching its data: personal phones on email, two laptops belonging to former contractors never removed, and several family computers used for remote work. It decides to enrol the corporate machines in Intune, offer a scoped BYOD with selective wipe for personal phones, and block the rest through Conditional Access. By previewing each rule before applying it, it tightens control without ever locking out a legitimate employee by mistake.

Common mistakes to avoid

  • Believing you know your fleet without ever reviewing the real sign-in logs.
  • Bluntly blocking all unmanaged devices without previewing the impact, risking paralysing the team.
  • Banning BYOD instead of scoping it, which pushes usage into the shadows.
  • Forgetting to remove access from former contractors or ghost accounts.
  • Leaving legacy authentication active, which hides unmanaged devices.

The goal is not to ban remote work or BYOD, which meet genuine needs, but to ensure every access to data goes through a known, enrolled and compliant device. The difference between a controlled fleet and a blind one is not the number of devices, but the visibility you have of them and the rules you apply. Most organisations discover, once they finally look, that the number of devices touching their data is far higher than they assumed.

Shadow IT: a symptom, not a fault

Unmanaged devices do not reflect employee malice, but a need the official tool failed to meet quickly enough. Someone checks their email on a personal phone because it is convenient, not to bypass security. Understanding shadow IT as a symptom, rather than a fault to punish, changes how you handle it: you offer a simple official route before blocking the workarounds.

Offer an alternative before blocking

Blocking a use without offering an alternative merely moves the problem: the employee will find another, even more discreet workaround. Offering a scoped BYOD enrolment first, fast and privacy-respecting, and applying the block only afterwards ensures legitimate usage continues through a controlled route rather than in the shadows.

A living inventory, not a snapshot

A fleet is never frozen: new devices appear every week, others disappear. An inventory done once and filed in a spreadsheet is out of date within a month. Visibility must be continuous, anchored to the real sign-in logs, to immediately spot any new unmanaged device attempting to reach your data.

How AuPoint helps

AuPoint surfaces the devices reaching your data and helps you enforce, through Conditional Access, that only compliant endpoints get in, in a few clicks and without PowerShell. You preview the impact before applying a rule, so you tighten control without locking out your team by mistake, and you can roll back instantly if something unexpected appears.

  1. 1See every device that actually reaches your data.
  2. 2Preview a Conditional Access rule's impact before applying it.
  3. 3Enforce compliance gradually without blocking legitimate usage.
  4. 4Roll back in one click if an unforeseen case appears.
Seeing your whole fleet clearly is the starting point of any security.

FAQ

How do I know which devices access my data?

Entra ID sign-in logs record every access, with the device, operating system and location. Cross-referencing them with the list of devices enrolled in Intune reveals the unmanaged endpoints that had escaped your visibility until now.

Should you ban BYOD entirely?

No. A ban pushes usage into the shadows. It is better to scope BYOD with enrolment and a selective wipe, which protect corporate data while preserving the employee's personal data.

How do I avoid blocking a legitimate employee?

By previewing the impact of every Conditional Access rule before applying it, and keeping the ability to roll back in one click. You thus tighten control gradually, with no surprises or abrupt blocks.

Seeing your whole fleet clearly is the essential starting point of any security worthy of the name. Instead of chasing shadow IT device by device, you set a clear rule once and let it apply to everyone. With AuPoint, this inventory and scoping become a simple, reversible process aligned with ISO 27001, NIS2 and GDPR, without a single line of PowerShell.

Secure your tenant in 15 minutes

Free trial