What Should a Board See in a Microsoft 365 Device Report?

What Should a Board See in a Microsoft 365 Device Report?

A microsoft 365 device control board report shows device custody, data-removal, backup, and exception risk under HIPAA.

LakeRidge Team
July 18, 2026
9 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

A microsoft 365 device control board report should show whether the organization can account for devices and media containing sensitive data, protect information before equipment moves or is retired, and resolve exceptions before they become reportable compliance risks. For a board, the report should emphasize control coverage, unresolved exposure, trend direction, management accountability, and the funding or policy decisions needed—not technical configuration detail. It should connect Microsoft 365 and Intune evidence to HIPAA Device and Media Controls at 45 CFR § 164.310(d)(1), including disposal, media re-use, accountability, and backup before equipment movement.

What do boards actually want to know about this control?

A board does not need a list of every laptop serial number or every Intune compliance policy. It needs confidence that management can answer four business questions: What assets may contain electronic protected health information (ePHI)? Who is responsible when those assets move, are reused, or leave service? Can data be recovered before a device is moved or replaced? Can the organization prove that data was removed or destroyed when a device or storage medium was disposed of?

HIPAA § 164.310(d)(1) requires policies and procedures governing the receipt, removal, and movement of hardware and electronic media containing ePHI. The related implementation specifications make disposal and media re-use required controls. Accountability for movements and retrievable backup before equipment movement are addressable, meaning the organization must implement them when reasonable and appropriate or document an alternative approach and its rationale. A board report should therefore show both the control result and the evidence management retains.

  • Coverage: How many in-scope devices are enrolled in Microsoft Intune, encrypted, assigned to an accountable owner, and reporting recently?
  • Custody: Are new, transferred, loaned, repaired, and retired devices recorded in an asset register or service-management workflow?
  • Disposition: Were devices wiped, destroyed, or returned to a vendor with evidence of completion before leaving organizational control?
  • Data protection: Were recoverable backups or cloud-synchronized records confirmed before a device was moved, rebuilt, or retired?
  • Exceptions: Which risks remain open, who accepted them, when do they expire, and what would it cost to close them?

Microsoft 365 supplies valuable evidence, but it does not replace a physical custody process. Intune can show device enrollment, compliance, encryption status, last check-in, ownership, and retirement actions. Microsoft Entra ID can show the assigned user and sign-in activity. Microsoft Purview can support retention and eDiscovery for cloud-held records. None of those services, by themselves, proves that a removed solid-state drive was physically destroyed or that a USB drive was transferred between offices. The board should expect management to combine Microsoft 365 evidence with asset records, help-desk tickets, vendor certificates of destruction, and signed chain-of-custody records.

What should a one-slide microsoft 365 device control board report contain?

The most useful board slide fits on one page and leads with a conclusion, not a dashboard. It should distinguish a control operating effectively with manageable exceptions from a control that is merely being monitored. The slide below is a practical format a COO or finance leader can use to ask for a consistent quarterly update.

CONTROL: HIPAA Device and Media Controls — 45 CFR § 164.310(d)
OVERALL STATUS: AMBER — Core endpoint coverage is strong; retirement evidence is incomplete.

1. BUSINESS RISK
   8 retired or transferred devices lack completed disposal or custody evidence.
   Estimated affected population: 8 of 126 in-scope endpoints (6.3%).

2. CONTROL PERFORMANCE THIS QUARTER
   • Intune-enrolled and active within 30 days: 122 / 126 (96.8%)
   • BitLocker encryption confirmed: 121 / 122 active Windows devices (99.2%)
   • Retirement tickets with wipe/destruction evidence: 19 / 27 (70.4%)
   • Equipment moves with backup confirmation: 14 / 15 (93.3%)

3. TREND AND ACCOUNTABILITY
   Retired-device evidence improved from 52% last quarter to 70%.
   Owner: Director of Operations
   Open exceptions: 8; oldest exception: 41 days

4. MANAGEMENT ACTION / BOARD DECISION
   Approve $4,800 annual certified destruction and asset-reconciliation service.
   Management target: 95% documented disposition evidence by next quarter.

The status should be based on a defined threshold. For example, an organization may classify the control as green only when at least 95% of in-scope endpoints are actively managed, 100% of retired devices have disposition evidence within 30 days, and no high-risk unassigned device has been inactive for more than 14 days. A percentage without a threshold encourages false reassurance; 98% encryption coverage may still mean one unencrypted laptop with ePHI is missing.

At Harbor Point Orthopedics, a 42-person practice with three clinics, management uses Microsoft 365 Business Premium, Intune-managed Windows laptops, iPads used for patient intake, and a cloud-based electronic health record system. When a front-desk laptop is replaced, the office manager opens a retirement ticket, confirms that the device’s user data is synchronized or otherwise recoverable, records the asset tag and assigned employee, and attaches the Intune wipe confirmation or the destruction vendor certificate. The board does not need the ticket details; it needs the quarterly count of completed versus overdue records and the reason for any overdue items.

How should technical findings be translated into board risk language?

A useful board report for Microsoft 365 device controls translates a setting failure into its operational consequence, compliance implication, and management response. This helps the board decide whether a gap is a routine remediation item, an accepted risk, or a budget priority.

Technical finding Board-ready risk statement Management response
Four devices have not checked in to Intune for more than 30 days. Management cannot confirm the location, encryption, or current user of four assets that may have accessed ePHI. Contact assigned users, suspend access where appropriate, and escalate missing devices under the incident process.
A retired laptop was removed from Entra ID, but no wipe record or destruction certificate is attached to its asset ticket. The organization cannot demonstrate final disposition of potential ePHI on one retired device, creating audit and breach-assessment exposure. Locate the device or obtain vendor evidence; if it cannot be located, perform a documented security incident assessment.
BitLocker recovery-key escrow is missing for one managed Windows device. A device failure or transfer could make business records inaccessible and complicate a controlled rebuild or replacement. Escrow the key, confirm backup status, and prevent device transfer until evidence is complete.
USB removable-media use is permitted without a documented exception or custody record. Data may leave controlled systems on media that cannot be tracked, wiped, or verified at disposal. Restrict removable storage through Intune device-control policy and require approved, encrypted exceptions.

The language should remain precise. Do not say that a missing Intune record proves a breach. Say what management cannot verify, how long the uncertainty has existed, whether ePHI was likely accessible, and what the documented response is. That distinction gives the board an accurate risk picture without overstating an incident.

Which metrics should a board trend over time?

Trend reporting is more valuable than a one-time compliance score because it reveals whether the organization is improving its control discipline or accumulating unresolved custody risk. Keep the denominator stable and explain changes. If the organization acquires a practice, opens a site, or adds shared iPads, identify the new in-scope population rather than allowing percentages to conceal it.

Metric Q1 Q2 Q3 Q4 target What the board should infer
In-scope devices enrolled and active in Intune within 30 days 114 / 121 (94.2%) 118 / 124 (95.2%) 122 / 126 (96.8%) ≥ 97% Inventory and management coverage are improving, but four devices still require investigation.
Active Windows devices with BitLocker confirmed 109 / 114 (95.6%) 116 / 118 (98.3%) 121 / 122 (99.2%) 100% Encryption risk is nearly closed; the remaining exception should have a named owner and date.
Retirements with wipe or destruction evidence within 30 days 11 / 21 (52.4%) 16 / 24 (66.7%) 19 / 27 (70.4%) ≥ 95% The principal weakness is administrative evidence and vendor workflow, not endpoint configuration.
Equipment moves with backup confirmation 8 / 12 (66.7%) 12 / 14 (85.7%) 14 / 15 (93.3%) 100% The process is maturing; one missing record should be closed before the next reporting cycle.
Open exceptions older than 30 days 9 7 8 0 Risk is not yet being resolved consistently; aging exceptions deserve executive escalation.

For a small organization, avoid metrics that reward volume rather than control quality. “Tickets closed” is not meaningful unless the closure includes the required evidence. Likewise, a device being deleted from Intune is not proof of sanitization. The stronger metric is the percentage of retirement events with a linked asset record, a documented disposition method, date, responsible person, and supporting wipe confirmation or certificate.

A second worked example illustrates the financial value of this approach. Cedar Ridge Imaging, with 28 employees, two locations, Microsoft 365 Business Premium, and shared diagnostic-workstation accessories, found that 13 older tablets had been removed from Intune during an office move but only seven had vendor destruction certificates. Its Microsoft 365 device report correctly showed fewer managed devices, but its physical asset register showed an unresolved disposition gap. Management reported six open assets, assigned the operations manager as owner, spent $1,150 on certified collection and destruction, and closed the exceptions within 21 days. The board received a short exception update rather than an inventory export.

How should management prepare for likely board questions?

“Are all devices containing ePHI covered?”

Answer with a number, a denominator, and known exclusions: “Of 126 devices in scope, 122 are active in Intune. The remaining four are under investigation; none is approved as an unmanaged exception.” Also identify categories that Microsoft 365 may not see automatically, such as removable drives, specialty equipment, or vendor-managed systems.

“How do we know retired equipment does not retain patient information?”

Explain the evidence chain: an asset retirement ticket identifies the device and custodian; Intune provides a retire or wipe action record when applicable; the disposal vendor provides a certificate of destruction when physical destruction is used; and management reconciles all records to the asset register. If evidence is missing, it remains an open exception rather than being treated as complete.

“What would make this a reportable event?”

A missing device or missing disposal evidence triggers a documented security assessment. Management evaluates whether ePHI was present, whether encryption and access controls were effective, whether the device can be located or remotely wiped, and whether notification obligations apply. The board should receive the conclusion and material impact, not speculative technical detail.

“What are we being asked to fund?”

Frame requests as risk reduction: asset-management workflow integration, certified destruction services, replacement of unsupported devices, or staff time for quarterly reconciliation. The decision should state the expected reduction in overdue disposition records and the consequence of deferring the investment.

Ask management to bring a quarterly board-level device-control report that names the control owner, shows aging exceptions, and ties every unresolved gap to a funded remediation plan or a formally accepted risk.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.