JJC SystemsBook a Consultation
Microsoft Intune · Education

The endpoint estate in a federated institution

Institutions typically have less endpoint coverage than they believe, concentrated in devices owned by departments rather than by central IT.

PublishedMay 31, 2026
Length14 pages · 15 min read
SectorEducation
PlatformMicrosoft Intune
Service areaManaged IT & Security
Abstract

The endpoint estate in a federated institution

Summary

University estates are federated by nature. Departments buy equipment, research groups run specialist systems, and central IT has authority over some of it and influence over the rest.

This paper argues that the resulting coverage gap is a governance problem rather than a technical one, that the uncovered devices are disproportionately the interesting ones, and that the productive response is relationship-led rather than mandate-led. It also sets out why a single endpoint configuration across staff, shared and personal devices reliably satisfies nobody.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

Coverage is lower than institutions believe, and the gap is knowable

Device discovery from onboarded endpoints routinely finds systems nobody had recorded. The number is generally larger than expected and the finding is the point.

02

Three device populations need three configurations

One policy across staff, shared labs and personal devices is too restrictive for academics and too permissive for teaching spaces.

03

Research computing needs exclusions, and they must be scoped

Specialist software and long-running computation interact badly with real-time scanning. Exclusions are legitimate; global exclusions are not.

04

Coverage drifts continuously, so it needs a standing metric

Departments keep buying equipment. Without a monthly measure the position degrades within a year regardless of how good the initial deployment was.

Analysis

The argument in full

Why the federated model produces the gap

Departments and research groups purchase equipment with their own budgets for their own reasons, and both practices are defensible academically. The consequence is an endpoint estate whose true size central IT does not know.

The devices outside the managed estate are not randomly distributed. They cluster in research computing, in departments with technical staff of their own, and in specialist teaching facilities — which is to say, in the places holding the most valuable and most sensitive material.

Mandating central control rarely works and frequently damages a relationship the institution needs for the rest of the programme. The productive approach establishes the position first, presents it as a finding rather than a failure, and negotiates coverage department by department.

Designing for three populations

Staff devices are assigned, trusted and managed like a corporate estate with conditional access and compliance policy. Shared student devices need fast user switching, no persistent local state and aggressive cleanup between sessions. Personal devices reaching institutional data should be handled with application protection rather than device management, because enrolment is a fight the institution does not need to have.

Assessment configuration is a fourth case and the highest-stakes one. A policy that half-applies on the morning of an exam is a genuine crisis, and the protections are procedural rather than technical: deploy well ahead, verify on the actual hardware in the actual room, and never let a policy apply for the first time on the day.

  • Staff: assigned, Entra joined, conditional access and compliance policy applied
  • Shared student: shared device mode, cleanup between sessions, redirected storage
  • Personal: application protection without enrolment, with selective wipe
  • Assessment: separate profile, device-scoped, deployed and verified ahead of the window
  • Research: semi-automated response with scoped exclusions and a named risk owner

Provisioning as the operational constraint

A large institution replaces or rebuilds devices continuously, and doing it by hand consumes a skilled team whose time has better uses.

Autopilot registration handled at the point of purchase means devices arrive ready, including loan equipment issued directly to students. This is a purchasing process change as much as a technical one, and it is the single largest operational saving available in most institutional estates.

The test is straightforward. Time a replacement from unboxing to a working, compliant device. If the answer is measured in days, provisioning is the constraint rather than the budget.

Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

Federated endpoint governance

Five stages. The first is diagnostic and the last is what keeps it true.

1

Discover

Run device discovery for a fortnight and reconcile against inventory. Present the gap as a finding.

2

Segment

Create device groups before onboarding so devices land in the right policy on arrival.

3

Negotiate

Approach departmental and research owners with the position, not with a mandate.

4

Provision

Move registration to the point of purchase. Time a replacement end to end as a baseline.

5

Measure

Report coverage monthly including the discovered-but-not-onboarded count.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the CIO

For research computing leadership

For the CISO

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
Device discovery in Microsoft Defender for Endpoint
02
Windows Autopilot documentation
03
Shared device mode and shared PC configuration
04
App protection policies
05
Take a Test and assessment configuration

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

We will run device discovery and produce a coverage map with the gap quantified, which is usually the fastest way to turn an internal argument about control into a shared plan.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

d365-sales
education12 pages

The economics of the enrolment funnel

The students who disappear between deposit and registration had already chosen you. Something in the following weeks made the decision reversible again.

December 21, 2025 · 12 pages · 13 min readRead
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.