--- title: "Module 1 — Endpoint Management Foundation" description: "Device inventory, Intune enrollment, compliance baseline, shadow IT discovery, and ASTRAL deployment for drift detection. Full device visibility in 30–45 days." eyebrow: "Consulting Module" lead: "You cannot govern what you cannot see. Endpoint management is almost always the right first module after the Diagnostic — it produces immediate visibility across every device and creates the foundation every other security control depends on." actions: - label: "Get in Touch" url: "/about/#contact" primary: true - label: "View All Modules" url: "/consulting/skills/" --- ## What It Delivers
Every managed device enrolled in Intune: OS version, patch level, encryption status, compliance state. Shadow IT devices flagged. You leave with a real picture of your fleet — not what should be there, but what is.
Encryption enforced, OS minimum versions set, antivirus required, screen lock configured. Devices that fail compliance are flagged in red and blocked from data access via Conditional Access integration.
ASTRAL captures your Intune configuration as versioned snapshots in Git. Any policy change opens a pull request with a human-readable diff. Unauthorised changes are detected before they become incidents.
Application inventory across all enrolled devices surfaces sanctioned and unsanctioned software — including consumer AI tools running on corporate devices. Every unsanctioned application is a potential data exfiltration or malware entry path.
Device compliance state wired into Conditional Access so non-compliant devices cannot reach email, SharePoint, or Teams. The device check becomes a real enforcement signal, not just a dashboard metric.
Full device visibility in 30 days. The foundation every other security control depends on.