<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Saskia Kim on Microsoft 365]]></title><description><![CDATA[Practical guides on Microsoft 365, Intune, Entra ID and email security for UK small businesses. Clear, jargon-free advice for IT managers and owners.]]></description><link>https://saskiakim001.hashnode.dev</link><generator>RSS for Node</generator><lastBuildDate>Sat, 03 Oct 2026 09:07:33 GMT</lastBuildDate><atom:link href="https://saskiakim001.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[Five Microsoft Intune Settings Every Small Business Should Check]]></title><description><![CDATA[Many small businesses already pay for Microsoft Intune without realising it. It is included in Microsoft 365 Business Premium, so the licence is there, but in many tenants, the configuration stops at ]]></description><link>https://saskiakim001.hashnode.dev/five-microsoft-intune-settings-every-small-business-should-check</link><guid isPermaLink="true">https://saskiakim001.hashnode.dev/five-microsoft-intune-settings-every-small-business-should-check</guid><dc:creator><![CDATA[Saskia Kim]]></dc:creator><pubDate>Tue, 29 Sep 2026 11:09:16 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6634d63de69a6eb3c89a577b/8ea734dc-45fa-4c66-8c21-7ef8bfde4a9d.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Many small businesses already pay for Microsoft Intune without realising it. It is included in Microsoft 365 Business Premium, so the licence is there, but in many tenants, the configuration stops at enrolling a few laptops.</p>
<p>That leaves devices managed in name only. They appear in the admin portal, yet nothing is actually enforced: no encryption requirement, no update deadline, and no consequence if a device falls out of line.</p>
<p>These are the five settings I check first whenever I look at a small business tenant. None require extra licences, and most take less than an hour to configure.</p>
<h2>1. What happens to devices with no compliance policy?</h2>
<p>By default, Microsoft Intune treats a device with no compliance policy assigned as compliant. Any device you forget to target therefore passes every Conditional Access check. Changing this tenant-wide setting to "Not compliant" means an unassigned device is blocked rather than quietly trusted, which closes one of the easiest gaps to miss.</p>
<p>You will find it in Microsoft Intune under <strong>Devices &gt; Compliance &gt; Compliance settings</strong>.</p>
<p>Before you change it, make sure each device group has at least one compliance policy assigned. Otherwise, users will lose access at the next check-in. A basic Windows policy requiring BitLocker, Secure Boot, a minimum operating system version and Microsoft Defender Antivirus is a sensible starting point.</p>
<p>The setting only has teeth if a Conditional Access policy requires a compliant device. Without that, non-compliance is just a label in a report.</p>
<h2>2. Is BitLocker enforced, and where are the recovery keys?</h2>
<p>Every company laptop should have its drive encrypted with BitLocker, enforced through a Microsoft Intune disk encryption policy rather than left to individual users. Just as important is where the recovery keys end up. Back them up to Microsoft Entra ID so an administrator can retrieve one quickly when a device locks.</p>
<p>An unencrypted laptop left on a train can quickly become a reportable data breach. An encrypted one is a replacement hardware cost.</p>
<p>Configure encryption under <strong>Endpoint security &gt; Disk encryption</strong>. Choose silent encryption so users are not prompted, and require recovery keys to be stored in Microsoft Entra ID before encryption begins. Then spot-check a few devices to confirm the keys are actually there. It is far better to find a missing key now than when a director is locked out on a Monday morning.</p>
<h2>3. Do your Windows updates have a deadline?</h2>
<p>Update rings in Microsoft Intune control when Windows devices install quality and feature updates. Many tenants set a deferral period but no deadline, so users can postpone restarts almost indefinitely. Adding a deadline and a short grace period ensures security patches install within days, rather than whenever someone finally decides to reboot.</p>
<p>A simple structure works well for most small businesses:</p>
<ul>
<li><p><strong>Pilot ring:</strong> a handful of confident users who receive updates with no deferral</p>
</li>
<li><p><strong>Broad ring:</strong> everyone else, with a deferral of a few days so any problems surface in the pilot group first</p>
</li>
</ul>
<p>Set a deadline of two to three days and a grace period of one to two days. This matters for Cyber Essentials too, which expects critical and high-risk security updates to be installed within 14 days of release.</p>
<h2>4. Who has local administrator rights?</h2>
<p>Staff should work on standard user accounts, not local administrator accounts. Administrator rights make it much easier for malware to install itself, disable protections, and spread. Microsoft Intune can manage the built-in administrator account with Windows LAPS, giving every device a unique, rotating password that IT can retrieve when support is needed.</p>
<p>Two patterns keep coming up in small businesses. The first is that whoever set up a laptop made themselves an administrator and never changed it back. The second is a single shared local administrator password used on every machine, so one compromised device exposes them all.</p>
<p>Both can be fixed under <strong>Endpoint security &gt; Account protection</strong>. Use a Windows LAPS policy for the built-in account, and a local user group membership policy to control exactly who sits in the Administrators group.</p>
<h2>5. Are personal phones protected without being managed?</h2>
<p>App protection policies let Microsoft Intune protect company data inside apps such as Outlook, Teams and OneDrive on personal phones, without enrolling the whole device. You can require a PIN, stop data being copied into personal apps, and remove only company data if the phone is lost or the employee leaves.</p>
<p>Staff are understandably reluctant to hand control of their own phones to their employer. App protection avoids that argument entirely because IT manages only the work apps, not the device.</p>
<p>Pair the policy with a Conditional Access rule that requires an app protection policy on iOS and Android. That way, unprotected mail apps cannot connect to company accounts at all.</p>
<h2>Where to start</h2>
<p>If you only have an afternoon, work through the first three in order: the compliance default and a basic compliance policy, then BitLocker with key backup, then update deadlines. These deliver the biggest improvement for the least disruption.</p>
<p>Local administrator rights and app protection change day-to-day work, so you need a short conversation with staff before they go live.</p>
<p>Whatever you change, test it on a pilot group first. A policy that blocks access is best discovered on the IT lead's laptop, not the finance director's.</p>
]]></content:encoded></item></channel></rss>