Coverage is lower than institutions believe, and the gap is knowable
Device discovery from onboarded endpoints routinely finds systems nobody had recorded. The number is generally larger than expected and the finding is the point.
Institutions typically have less endpoint coverage than they believe, concentrated in devices owned by departments rather than by central IT.
University estates are federated by nature. Departments buy equipment, research groups run specialist systems, and central IT has authority over some of it and influence over the rest.
This paper argues that the resulting coverage gap is a governance problem rather than a technical one, that the uncovered devices are disproportionately the interesting ones, and that the productive response is relationship-led rather than mandate-led. It also sets out why a single endpoint configuration across staff, shared and personal devices reliably satisfies nobody.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
Device discovery from onboarded endpoints routinely finds systems nobody had recorded. The number is generally larger than expected and the finding is the point.
One policy across staff, shared labs and personal devices is too restrictive for academics and too permissive for teaching spaces.
Specialist software and long-running computation interact badly with real-time scanning. Exclusions are legitimate; global exclusions are not.
Departments keep buying equipment. Without a monthly measure the position degrades within a year regardless of how good the initial deployment was.
Departments and research groups purchase equipment with their own budgets for their own reasons, and both practices are defensible academically. The consequence is an endpoint estate whose true size central IT does not know.
The devices outside the managed estate are not randomly distributed. They cluster in research computing, in departments with technical staff of their own, and in specialist teaching facilities — which is to say, in the places holding the most valuable and most sensitive material.
Mandating central control rarely works and frequently damages a relationship the institution needs for the rest of the programme. The productive approach establishes the position first, presents it as a finding rather than a failure, and negotiates coverage department by department.
Staff devices are assigned, trusted and managed like a corporate estate with conditional access and compliance policy. Shared student devices need fast user switching, no persistent local state and aggressive cleanup between sessions. Personal devices reaching institutional data should be handled with application protection rather than device management, because enrolment is a fight the institution does not need to have.
Assessment configuration is a fourth case and the highest-stakes one. A policy that half-applies on the morning of an exam is a genuine crisis, and the protections are procedural rather than technical: deploy well ahead, verify on the actual hardware in the actual room, and never let a policy apply for the first time on the day.
A large institution replaces or rebuilds devices continuously, and doing it by hand consumes a skilled team whose time has better uses.
Autopilot registration handled at the point of purchase means devices arrive ready, including loan equipment issued directly to students. This is a purchasing process change as much as a technical one, and it is the single largest operational saving available in most institutional estates.
The test is straightforward. Time a replacement from unboxing to a working, compliant device. If the answer is measured in days, provisioning is the constraint rather than the budget.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five stages. The first is diagnostic and the last is what keeps it true.
Run device discovery for a fortnight and reconcile against inventory. Present the gap as a finding.
Create device groups before onboarding so devices land in the right policy on arrival.
Approach departmental and research owners with the position, not with a mandate.
Move registration to the point of purchase. Time a replacement end to end as a baseline.
Report coverage monthly including the discovered-but-not-onboarded count.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
We will run device discovery and produce a coverage map with the gap quantified, which is usually the fastest way to turn an internal argument about control into a shared plan.
The pattern that predicts withdrawal is visible in hindsight in almost every case. The question is whether anybody saw it while there was still time.
The students who disappear between deposit and registration had already chosen you. Something in the following weeks made the decision reversible again.
Describe the situation in your own words.