Endpoint Compliance Drift
Compliance drift < 3% workspace-wide
Endpoint compliance decays. New employee's laptop meets baseline; three months later they've disabled the screensaver-lock "just for this presentation" and never re-enabled it, installed unapproved software, granted admin rights to some contractor, opted out of updates. MDM shows green-across-the-board because it's checking against a policy the user quietly worked around. Every quarter someone runs a manual audit, finds 40 machines drifted, and the loop starts again.
An hour-by-hour walkthrough.
Step by step.
- 01
Scan the fleet on 4-hour cadence
Full compliance check across every managed device: policy vs. actual state per compliance dimension. Read from MDM + EDR + agent-reported inventory.
Jamf · Intune · Kandji · CrowdStrike · SentinelOne · Fleet - 02
Detect + classify drift by severity
Low: user-fixable, non-critical (screensaver timeout). Medium: security-relevant, user-influenced (unapproved software). High: security-critical, auto-remediate (encryption off, EDR uninstalled, admin escalation).
Compliance policy · Severity matrix - 03
Route to user for low/medium; auto-remediate high
Low/medium: user DM with specific drift + one-click remediation or exemption-request. High: auto-remediate immediately + file incident for security review.
Slack · Teams · MDM policy push · Incident tracker - 04
Nudge + escalate on non-response
User has 48 hours to respond or Sig auto-remediates + notifies user. Repeat drift patterns (same user, same setting, 3+ times) escalate to manager as coaching moment.
Slack · Manager escalation · Coaching queue - 05
Weekly security digest + policy tuning
Drift-by-category trend, top-offending users, common exemption requests (informs policy updates), compliance-score fleet health. Sanctioned-software list updated from common exemption asks.
Analytics · Slack digest · Policy tuning
What you connect to make this run.
Jamf · Intune · Kandji · Workspace ONE
read+writeMDM as source of policy + fleet state. Write policy re-enforcement, remediation profiles. Read: compliance status per device per policy dimension.
CrowdStrike · SentinelOne · EDR
read+writeEDR agent health + tamper detection. Missing EDR heartbeat is a high-severity drift; user cannot uninstall or disable.
Sanctioned-software list · App catalog
read+writeApproved software list. Common exemption requests feed additions or investigations; a widely-used unapproved tool may be a policy gap rather than a violation.
Slack · Teams · Manager registry
read+writeUser DM for low/medium drift. Manager escalation for repeat patterns. Never surprises users — always the specific drift + specific fix.
Before and after, honestly.
Playbooks that pair with this one.
Proactive Device Health
Health telemetry and compliance drift overlap; unified DM to user.
SOC2 / Vanta Evidence Collection
Endpoint compliance is a SOC 2 control; evidence feeds from this scan.
Lost Device → Remote Lock
Missing EDR + no check-in signals is often the first lost-device indicator.
Answers about this playbook.
What if a user needs to install unapproved software for a specific task?
Exemption request flow. User justifies the need; Sig routes to security for one-time approval or catalog addition. Approved: exemption logged with expiry (usually 30 days for one-off, permanent for catalog add).
How does it handle BYOD or contractor devices?
BYOD compliance limited to what MDM policy covers. Corporate data isolation checks (email, VPN, doc apps) rather than full-device compliance. Different severity thresholds per device class.
What about developers who need local admin for their work?
Local admin allowed per role (engineering, IT ops), tracked with justification. Only extra-local-admin accounts flag; sanctioned admin roles pass compliance.
How does it handle offline devices (long air travel, remote area)?
Devices without check-in for 7+ days flag as "unknown compliance state" — not compliant, not violating. On next check-in, scan runs and any drift addressed.
Can we exempt specific device populations (lab, kiosks)?
Yes — device-class tags with class-specific compliance policies. Lab devices may skip screensaver-lock (shared use); kiosks have their own strict policy. Enterprise class always follows full policy.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.