Microsoft Intune Health Assessment
See what is working in Intune. Find what is not.
Get a tailored assessment of your Microsoft Intune configuration, security posture, device estate and application landscape.
You will receive a clear view of where your environment stands today, where risk and configuration drift may be accumulating, and which actions should come next.
Your assessment will help you:
- Understand the health of your Intune environment.
- Identify configuration, compliance and security gaps.
- Prioritize the actions that will have the greatest impact.
Complete the form and a Devicie specialist will contact you to explain the read-only assessment process and help you get started.

What you will receive
A clearer picture of your Intune environment
The Intune Health Assessment turns configuration and device data into an actionable view of your environment. Rather than giving you another raw export or list of settings, it shows what is working, where material gaps exist and what it will take to address them.
Overall health score
See a weighted view of your environment across key operational and security domains.
Configuration and security findings
Understand your Intune configuration, CIS Level 1 coverage, enrollment approach, security baselines and policy maturity.
Device and operational health
Review device compliance, operating system patch currency, encryption coverage and active device status.
Application visibility
Identify outdated applications, version gaps and areas where unmanaged software may be creating exposure.
Prioritized actions
Receive a practical remediation plan showing the relative effort, impact and ongoing nature of each recommended action.
Business-ready risk summary
Translate technical findings into language that leadership, auditors and security stakeholders can act on.
A report built to be read three ways
About 25 pages, structured so each part stands alone.
- A two-page executive summary — the score, the top findings, the business risk.
- Findings by impact — critical, high, medium and low, each with what it is and what to do about it.
- Technical detail — the evidence, the method, and the specific settings behind every score.
Start with part one and go only as deep as you need. Nobody has to translate it for anybody.
.png)
HOW IT WORKS
From request to actionable report
01
Speak with a Devicie specialist
After you submit the form, we will confirm your objectives, environment and assessment scope.
02
Run the read-only collector
We send you a PowerShell script. You run it in your environment, which takes about 20 minutes, and send the results back in a password-protected archive. Nothing in your tenant is changed, no agent is installed, and you do not grant Devicie access to your tenant.
Because it is a script you can read before you run it, it usually avoids the NDA, infosec review and access-approval queue that a tenant-connected assessment needs.
03
Receive your tailored assessment
We analyse the findings and prepare a report covering your current state, priority gaps, business risk and recommended next steps.
04
Decide how to act
Use the report as an internal action plan, or work with Devicie to address the gaps and maintain your environment over time.
The review itself takes 30 to 60 minutes, whenever suits you.
Secure by design
Your tenant stays yours
The assessment is designed to give you visibility without disrupting your environment. Collection is read-only, nothing in your tenant is changed, and your report is prepared specifically for your organisation.
- A PowerShell script you can read before you run it
- No agent installed, no configuration changed, no tenant access granted
- No personally identifiable information collected. Your company name is attached to the report, no employee detail is collected
- Confidential assessment report, prepared for your organisation only
- Delivered by a Microsoft Partner and MISA member
And what it does not cover
Entra Conditional Access, per-device endpoint health telemetry and device warranty data sit outside the assessment. Where a collection call returns partial data, the report marks it rather than filling the gap with an estimate.
Fixing the gaps is a project.
Keeping them fixed is the job.
The findings are what your estate looks like today. Left alone, it looks like this again in six months. Configuration drifts, applications fall behind, and new devices arrive outside the baseline.
Without Devicie
You have a prioritised list and a project. Someone owns it, closes it, and runs the exercise again next year.
With Devicie
The baseline is deployed and then held. Drift is detected and remediated continuously, applications are kept current from a maintained catalog, and new devices arrive already compliant.
The report is yours either way.
Questions people ask
Before you request one
Do you need access to our tenant?
No. You run a PowerShell script we send you and return the output in a password-protected archive. Devicie is never granted access to your tenant, and no agent is installed. Most teams find that avoids the approval process a tenant-connected assessment would trigger.
How much of our time does this take?
About twenty minutes to run the collector, up to thirty on a very large estate, and 30 to 60 minutes for the review. Nothing in between. The assessment work is ours.
What data do you collect?
Configuration and device data only. No personally identifiable information. Your company name is attached to the report; no employee detail is collected. You can read the script before you run it.
Which benchmark do you assess against?
The CIS Benchmark for Microsoft Intune for Windows, version 4.0.0, Level 1. Controls are matched by setting definition ID rather than by name, and 351 controls are assessed.
What does the report actually contain?
About 25 pages in three parts that each stand alone: a two-page executive summary, findings ranked by impact, and the technical detail behind every score. Your environment is scored out of 100 across eight domains.
What if our scores come back poor?
Then that is what the report says. We do not grade on a curve. If a domain scores low because you use a different tool for that function, we say so and leave the number alone, because adjusting it would defeat the point of measuring.
We already pay for Intune. Why would we need this?
Intune is where policy lives. It does not tell you whether the policy you set six months ago is still in force, which devices have drifted from it, or which applications have fallen behind. This measures that, against a published benchmark, and tells you what to close first.
What happens after the report?
It is yours to keep and act on, whether you work with Devicie or not. Use it as an internal action plan, take it to another vendor, or work with us to close the gaps and hold the position afterwards.
