Now in the dashboard
Turn your Intune documentation into audit evidence
When an auditor, a cyber insurer, or a customer questionnaire asks you to prove that your devices enforce encryption, screen lock, and patching, the answer is usually days of screenshots. Intune Documentation already knows your tenant configuration. Compliance reports map it to the frameworks your auditor actually references, with the policy names, settings, values, and assignments as evidence.
Supported frameworks
ASD Essential Eight (Maturity Levels 1, 2 and 3)
Choose a target maturity level in the dashboard. All eight strategies are included, with 48, 107 and 149 requirement entries for Levels 1, 2 and 3 respectively, based on ASD’s November 2023 model. Supporting Intune evidence is mapped to 3, 8 and 10 requirements respectively. Other requirements remain explicitly unassessed; the tool does not calculate an achieved maturity level.
ISO/IEC 27001:2022
Selected Annex A technology controls are mapped to managed-device configuration evidence by control number.
SOC 2
Selected Trust Services Criteria are mapped to managed-device configuration evidence by criterion ID.
NIST SP 800-53 (Rev. 5)
Technical evidence for controls such as SC-28 (protection of information at rest), SI-3 (malicious code protection), and IA-5 (authenticator management).
NIST Cybersecurity Framework 2.0
Evidence for Protect and Detect subcategories, from PR.DS-01 (data-at-rest protection) to DE.CM-09 (endpoint monitoring).
UK MOD Def Stan 05-138 (Issue 4)
Selected Objective B controls for defence suppliers under DEFCON 658, referenced by control identifier with the Cyber Risk Profile levels at which each applies.
NCSC Cyber Essentials
The five control themes (firewalls, secure configuration, security update management, user access control, malware protection) mapped to managed-device configuration evidence.
NIST SP 800-171 (Rev. 2)
Supporting Intune evidence for 12 of 110 published requirements in the revision used by CMMC Level 2. Covers selected encryption, authentication, hardening and malware protections. This is not a complete CMMC assessment or an SPRS score.
NIST SP 800-171 (Rev. 3)
Supporting Intune evidence for 11 of 97 published requirements in the May 2024 revision, including MFA, application control, storage encryption and malicious code protection. Organization-defined parameters and remaining requirements need separate assessment. Revision 2 remains separately available for CMMC Level 2.
BSI IT-Grundschutz
Requirement-level mapping (A-Anforderungen) for the client Bausteine SYS.2.2.3, SYS.2.4, SYS.3.2.1, and SYS.3.2.2, verified against the Kompendium Edition 2023, with Basis, Standard, and erhöhter Schutzbedarf tiers. Only technically assessable requirements are mapped; organizational requirements remain a manual assessment.
Inside every report
The downloadable reports are built as audit deliverables, not data dumps: table of contents with page numbers, grayscale-safe status markers, and the structure an assessor expects.
Document control and provenance
Report ID, revision, ruleset version, classification, and a data-basis section stating exactly which policy families and how many policies were assessed, so the report can stand in an audit trail.
Evidence register with citations
Every unique piece of evidence appears once in an appendix with the policy, setting, value, and assignment; controls cite it by reference (E-001 style) the way an auditor expects to verify it.
Results overview and key findings
Outcomes grouped by BSI requirement tier or framework control family, with assigned deviations and unassigned configurations flagged up front.
Grundschutz-Check ready
The BSI report is fully German and includes manual assessment fields (Umsetzungsstatus, Verantwortlich, Zieltermin, Bemerkung) for each requirement, so consultants can complete their review directly on the document.
Gap guidance
Every requirement without evidence lists the exact Intune settings that could provide it, turning the report into a remediation worklist.
Built for people who face auditors
Real evidence, not keyword matching
A control only counts as covered when a recognized Intune setting is configured with the value that actually enforces it, on a policy that is assigned. Policies that merely mention a topic are ignored.
Counter-evidence is surfaced
A policy that explicitly disables BitLocker is reported as a risk, never as coverage. Unassigned policies are flagged instead of counted.
Honest by design
The report states evidence, partial evidence, or no evidence. It never claims you are compliant, because only your auditor can. Organizational requirements are listed for manual assessment.
Your data stays yours
Assessment runs on the same tenant export as your documentation. Your configuration is processed in your browser session and is not stored on our servers.
See your compliance evidence now
The compliance evidence view is available in the dashboard for every signed-in user. Review framework controls and download full requirement-level reports as PDF. For ASD Essential Eight, select Maturity Level 1, 2 or 3 to review evidence against that target and include it in your PDF report and JSON evidence record.
Open the dashboardCompliance reports state technical evidence found in your Intune tenant. They are not a certification and do not replace an audit. ISO/IEC 27001 and SOC 2 criteria are referenced by identifier with original summaries. NIST publications are used with their public-domain status; BSI IT-Grundschutz is referenced from the freely published Kompendium. Def Stan 05-138 is referenced by control identifier with original summaries. Cyber Essentials content is used under the Open Government Licence v3.0, and evidence never indicates certification. Essential Eight requirement text is attributed to the Australian Signals Directorate, © Commonwealth of Australia 2026, under CC BY 4.0. Local requirement identifiers and evidence mappings are additions by Intune Documentation. ASD maturity model · CC BY 4.0 licence.