<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Songeziwe Fayindlala</title>
    <description>The latest articles on DEV Community by Songeziwe Fayindlala (@songeziwe).</description>
    <link>https://dev.to/songeziwe</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3949173%2Ff7fa676b-cf6f-4093-92c1-5cbbabc5c068.png</url>
      <title>DEV Community: Songeziwe Fayindlala</title>
      <link>https://dev.to/songeziwe</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/songeziwe"/>
    <language>en</language>
    <item>
      <title>South Africa Accounts for 92% of Africa’s Ransomware Detections. Here’s What IT Teams Should Learn From It</title>
      <dc:creator>Songeziwe Fayindlala</dc:creator>
      <pubDate>Mon, 31 Aug 2026 20:48:12 +0000</pubDate>
      <link>https://dev.to/songeziwe/south-africa-accounts-for-92-of-africas-ransomware-detections-heres-what-it-teams-should-learn-1ef1</link>
      <guid>https://dev.to/songeziwe/south-africa-accounts-for-92-of-africas-ransomware-detections-heres-what-it-teams-should-learn-1ef1</guid>
      <description>&lt;p&gt;South Africa has become a major focal point in Africa’s ransomware landscape.&lt;/p&gt;

&lt;p&gt;According to INTERPOL’s &lt;em&gt;African Cyberthreat Assessment Report 2026&lt;/em&gt;, South Africa accounted for &lt;strong&gt;92% of ransomware detections recorded across Africa in 2025&lt;/strong&gt;, based on TrendAI telemetry. That figure is striking, but it needs context: it represents &lt;strong&gt;detections&lt;/strong&gt;, not proof that 92% of all ransomware attacks on the continent occurred in South Africa.&lt;/p&gt;

&lt;p&gt;Even with that distinction, the signal is impossible to ignore.&lt;/p&gt;

&lt;p&gt;South African organizations are operating in an environment where highly connected businesses, government institutions and critical services are attractive targets. And the most useful lessons are not found in the percentage itself. They are found in the incidents behind it.&lt;/p&gt;

&lt;p&gt;Recent attacks against organizations such as the &lt;strong&gt;National Health Laboratory Service (NHLS)&lt;/strong&gt; and the &lt;strong&gt;South African Weather Service (SAWS)&lt;/strong&gt; demonstrate that ransomware is no longer simply an endpoint-security problem.&lt;/p&gt;

&lt;p&gt;It is a &lt;strong&gt;business continuity problem&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The 92% Statistic Is a Warning, Not the Whole Story
&lt;/h2&gt;

&lt;p&gt;A common reaction to a statistic like this is to ask why South Africa is being targeted more heavily than other African countries.&lt;/p&gt;

&lt;p&gt;There is a more useful question for IT leaders:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why do some attacks become business crises while others remain contained security incidents?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;South Africa's highly connected digital economy means attackers have access to valuable systems and data, while organizations often depend heavily on technology to deliver essential services.&lt;/p&gt;

&lt;p&gt;INTERPOL's latest assessment also highlights a wider cyber-threat environment involving phishing, business email compromise, vulnerabilities and increasingly automated attacks. South Africa accounted for &lt;strong&gt;70% of Africa's business email compromise detections in 2025&lt;/strong&gt;, according to the same TrendAI telemetry.&lt;/p&gt;

&lt;p&gt;The lesson is that ransomware rarely exists in isolation.&lt;/p&gt;

&lt;p&gt;It often begins with the things security teams already worry about: a stolen credential, a phishing message, an exposed vulnerability or excessive privileges.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Incidents Behind the Headline
&lt;/h2&gt;

&lt;p&gt;The &lt;strong&gt;NHLS ransomware attack in June 2024&lt;/strong&gt; is one of the clearest examples of how a cyber incident can quickly become an operational emergency.&lt;/p&gt;

&lt;p&gt;The attack encrypted systems used by the National Health Laboratory Service, affecting internet and intranet services, the laboratory information system and access to historical laboratory data. Because NHLS provides diagnostic pathology services to more than 80% of South Africa's population, the disruption extended far beyond an internal IT environment.&lt;/p&gt;

&lt;p&gt;The important lesson is not simply that healthcare was attacked.&lt;/p&gt;

&lt;p&gt;It is that &lt;strong&gt;critical services continued to depend on systems that were suddenly unavailable&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The South African Weather Service experienced a similar reality after a &lt;strong&gt;January 2025 cyberattack&lt;/strong&gt; that affected most of its systems. Its annual report records that data recovery continued while the organization used alternative mechanisms to distribute severe-weather warnings and information.&lt;/p&gt;

&lt;p&gt;That is what ransomware resilience ultimately looks like.&lt;/p&gt;

&lt;p&gt;Not preventing every incident.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Continuing to operate when prevention fails.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Attack Path Is More Important Than the Ransom Note
&lt;/h2&gt;

&lt;p&gt;Ransomware tends to receive attention when files are encrypted and a ransom demand appears.&lt;/p&gt;

&lt;p&gt;Defenders should be looking much earlier.&lt;/p&gt;

&lt;p&gt;A simplified attack path looks like this:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Initial Access → Identity Compromise → Lateral Movement → Privilege Escalation → Data Access → Encryption/Disruption&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The important part is the middle.&lt;/p&gt;

&lt;p&gt;An attacker who reaches the encryption stage has often already succeeded at several earlier stages.&lt;/p&gt;

&lt;p&gt;That means an organization's security programme cannot depend entirely on detecting ransomware at the endpoint. It needs visibility into the behaviors that often precede it.&lt;/p&gt;

&lt;p&gt;Unusual sign-ins. Suspicious privilege changes. Unexpected remote administration. Abnormal PowerShell activity. Attempts to disable security tools. Large-scale access to files. Unusual movement between systems.&lt;/p&gt;

&lt;p&gt;These signals can provide defenders with something incredibly valuable: &lt;strong&gt;time.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And in ransomware response, time is often the difference between isolating one compromised machine and recovering an entire environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Identity Has Become a Critical Security Boundary
&lt;/h2&gt;

&lt;p&gt;For organizations using Microsoft 365, Entra ID, Intune and Defender, identity deserves particular attention.&lt;/p&gt;

&lt;p&gt;A compromised account can provide an attacker with a much easier path into an environment than attacking every endpoint individually.&lt;/p&gt;

&lt;p&gt;That makes strong authentication, Conditional Access, privileged-access management and identity monitoring essential parts of ransomware defense.&lt;/p&gt;

&lt;p&gt;Multi-factor authentication is important, but it should not be treated as the finish line.&lt;/p&gt;

&lt;p&gt;IT teams should also ask whether privileged accounts are separated from normal user accounts, whether dormant accounts are removed, whether service identities are properly governed, and whether suspicious authentication behavior is being investigated quickly.&lt;/p&gt;

&lt;p&gt;The objective is simple:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A compromised account should not automatically become enterprise-wide access.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Backups Are Not the Same as Recovery
&lt;/h2&gt;

&lt;p&gt;Ransomware conversations often end with the phrase:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“We have backups.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is not enough.&lt;/p&gt;

&lt;p&gt;The better question is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can we still recover if the attacker compromises an administrator account and discovers our backup infrastructure?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is why immutable, isolated and offline recovery mechanisms matter.&lt;/p&gt;

&lt;p&gt;The South African Weather Service's post-incident procurement requirements provide a useful example. Its specifications called for capabilities including &lt;strong&gt;immutable and air-gapped backups, anomaly detection, malware scanning and Zero Trust controls&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The broader lesson is that backup security must be designed around an attacker who is already inside the environment.&lt;/p&gt;

&lt;p&gt;And backups must be tested.&lt;/p&gt;

&lt;p&gt;A backup that has never been restored successfully is an assumption, not a recovery strategy.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Biggest Gap May Be Business Continuity
&lt;/h2&gt;

&lt;p&gt;The NHLS incident exposed another important problem: traditional downtime procedures are not necessarily designed for a cyberattack.&lt;/p&gt;

&lt;p&gt;A ransomware event can simultaneously affect applications, authentication, network access, files and internal communications.&lt;/p&gt;

&lt;p&gt;That makes cyber resilience fundamentally different from planning for a normal infrastructure outage.&lt;/p&gt;

&lt;p&gt;IT teams should be able to answer:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens when our primary identity service is compromised?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens when our file servers cannot be trusted?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens when users cannot access normal collaboration tools?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which business services must be restored first?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;These are not purely technical questions.&lt;/p&gt;

&lt;p&gt;They require IT, security, operations and business leaders to agree on priorities before the incident occurs.&lt;/p&gt;

&lt;h2&gt;
  
  
  From Reaction to Resilience
&lt;/h2&gt;

&lt;p&gt;The biggest mistake South African organizations could make is treating the 92% figure as another alarming cybersecurity headline.&lt;/p&gt;

&lt;p&gt;The better response is to use it as a design challenge.&lt;/p&gt;

&lt;p&gt;Assume that a credential will eventually be compromised.&lt;/p&gt;

&lt;p&gt;Assume that an endpoint will eventually be breached.&lt;/p&gt;

&lt;p&gt;Assume that an attacker will eventually bypass one of your controls.&lt;/p&gt;

&lt;p&gt;Then ask what happens next.&lt;/p&gt;

&lt;p&gt;Can the attacker move laterally?&lt;/p&gt;

&lt;p&gt;Can they obtain privilege?&lt;/p&gt;

&lt;p&gt;Can they reach the backup environment?&lt;/p&gt;

&lt;p&gt;Can they disable security controls?&lt;/p&gt;

&lt;p&gt;Can you detect them before encryption begins?&lt;/p&gt;

&lt;p&gt;Can you isolate affected systems quickly?&lt;/p&gt;

&lt;p&gt;Can the business continue operating?&lt;/p&gt;

&lt;p&gt;Can you restore the most critical services in the correct order?&lt;/p&gt;

&lt;p&gt;Those questions reveal far more about an organization's ransomware resilience than the number of security products it owns.&lt;/p&gt;

&lt;h2&gt;
  
  
  What South African IT Teams Should Do Now
&lt;/h2&gt;

&lt;p&gt;The practical response does not need to begin with buying another security platform.&lt;/p&gt;

&lt;p&gt;Start by understanding &lt;strong&gt;where one compromised identity or device could cause disproportionate damage&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Prioritize privileged identities. Strengthen authentication. Reduce unnecessary administrative access. Patch externally exposed systems quickly. Segment critical services. Protect backup infrastructure from ordinary administrative paths. Centralize security telemetry. Define clear isolation procedures. Test recovery.&lt;/p&gt;

&lt;p&gt;Most importantly, run an exercise that assumes the attackers have already bypassed the first layer of defense.&lt;/p&gt;

&lt;p&gt;The objective should not be to prove that the security controls work.&lt;/p&gt;

&lt;p&gt;It should be to discover &lt;strong&gt;what happens when they do not&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Real Meaning of 92%
&lt;/h2&gt;

&lt;p&gt;South Africa accounting for 92% of Africa's ransomware detections is a statistic worth paying attention to.&lt;/p&gt;

&lt;p&gt;But the percentage is not the most important part of the story.&lt;/p&gt;

&lt;p&gt;The more important story is what recent incidents have demonstrated: when ransomware succeeds, the consequences can move rapidly from &lt;strong&gt;compromised credentials and encrypted systems to disrupted public services, delayed operations and difficult recovery decisions&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;That changes the question IT leaders should be asking.&lt;/p&gt;

&lt;p&gt;Not:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“How do we stop ransomware?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;But:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“How do we make ransomware less capable of stopping us?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is the difference between cybersecurity and cyber resilience.&lt;/p&gt;

&lt;p&gt;And for South African IT teams, it may be the most important lesson behind the 92%.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ransomware</category>
      <category>cyberresilience</category>
      <category>informationsecurity</category>
    </item>
    <item>
      <title>Building Compliance Dashboards in Power BI from the Microsoft Intune Data Warehouse</title>
      <dc:creator>Songeziwe Fayindlala</dc:creator>
      <pubDate>Sun, 23 Aug 2026 20:31:10 +0000</pubDate>
      <link>https://dev.to/songeziwe/building-compliance-dashboards-in-power-bi-from-the-microsoft-intune-data-warehouse-4fc</link>
      <guid>https://dev.to/songeziwe/building-compliance-dashboards-in-power-bi-from-the-microsoft-intune-data-warehouse-4fc</guid>
      <description>&lt;h2&gt;
  
  
  Introduction
&lt;/h2&gt;

&lt;p&gt;Managing thousands of corporate devices through Microsoft Intune creates an enormous amount of operational data.&lt;/p&gt;

&lt;p&gt;Every day, organizations collect information about devices, users, operating systems, compliance policies, configuration profiles, applications and enrollment activity. The challenge is no longer simply collecting the data. The real challenge is turning that information into something that administrators, security teams and management can understand and act upon.&lt;/p&gt;

&lt;p&gt;This is where &lt;strong&gt;Microsoft Intune Data Warehouse and Power BI&lt;/strong&gt; become particularly useful.&lt;/p&gt;

&lt;p&gt;The Intune Data Warehouse provides an analytics-oriented view of Intune data, exposed through the OData protocol and organized into related entities. Microsoft describes the model as a &lt;strong&gt;star schema&lt;/strong&gt;, with fact-style activity data connected to dimensions such as devices, users, policies and dates. The warehouse also maintains historical information through daily snapshots, which makes it particularly useful for analyzing trends rather than looking only at the current state.&lt;/p&gt;

&lt;p&gt;Power BI then provides the visualization and analytical layer that turns this information into dashboards.&lt;/p&gt;

&lt;p&gt;Instead of asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“How many devices are compliant?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;we can start asking more useful questions:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Is compliance improving?”&lt;/p&gt;

&lt;p&gt;“Which platforms have the highest non-compliance rate?”&lt;/p&gt;

&lt;p&gt;“Which policies are causing the most failures?”&lt;/p&gt;

&lt;p&gt;“Are there device groups consistently falling behind?”&lt;/p&gt;

&lt;p&gt;“Where should the endpoint team focus first?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is the difference between reporting data and using data to make decisions.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is the Intune Data Warehouse?
&lt;/h2&gt;

&lt;p&gt;The &lt;strong&gt;Microsoft Intune Data Warehouse (IDW)&lt;/strong&gt; is a reporting and analytics service that exposes Intune information in a machine-readable format.&lt;/p&gt;

&lt;p&gt;Microsoft documents the Data Warehouse API as an &lt;strong&gt;OData v4.0&lt;/strong&gt; service that can be consumed by analytics tools and custom applications. Authentication uses Microsoft Entra ID and OAuth 2.0.&lt;/p&gt;

&lt;p&gt;The Data Warehouse contains information across areas such as enrolled devices, device properties and inventory, applications, app protection, configuration policies and compliance policies.&lt;/p&gt;

&lt;p&gt;One of its most valuable characteristics is historical context.&lt;/p&gt;

&lt;p&gt;Intune takes a &lt;strong&gt;daily snapshot at midnight UTC&lt;/strong&gt; and stores that information in the Data Warehouse. Retention varies between fact tables, with some holding approximately seven days of information, others around 30 days, and some datasets retaining longer historical periods.&lt;/p&gt;

&lt;p&gt;This distinction is important.&lt;/p&gt;

&lt;p&gt;The Intune Data Warehouse should not be treated as a real-time monitoring platform. It is better understood as a &lt;strong&gt;historical analytics source&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;That makes it particularly useful for Power BI dashboards where the objective is to identify trends, measure changes and understand the overall health of an endpoint environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Use Power BI for Intune Compliance?
&lt;/h2&gt;

&lt;p&gt;The Microsoft Intune admin center already provides valuable reporting capabilities.&lt;/p&gt;

&lt;p&gt;However, an organization often needs something more tailored to its environment.&lt;/p&gt;

&lt;p&gt;A security manager might want a single page showing the overall compliance percentage, non-compliant device count, top failed policies and compliance trend.&lt;/p&gt;

&lt;p&gt;An endpoint administrator might need a much more detailed view showing specific devices, operating systems, ownership types and policy states.&lt;/p&gt;

&lt;p&gt;Management may not want to see thousands of rows of endpoint information at all. They may simply want to know whether compliance is improving, declining or remaining unchanged.&lt;/p&gt;

&lt;p&gt;Power BI makes it possible to build these different perspectives from the same underlying data.&lt;/p&gt;

&lt;p&gt;Microsoft itself documents Power BI as a supported way to consume the Intune Data Warehouse and create custom reports. The current Microsoft guidance recommends the &lt;strong&gt;OData Feed connector&lt;/strong&gt; for connecting Power BI to the Intune Data Warehouse.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Architecture
&lt;/h2&gt;

&lt;p&gt;The architecture is conceptually simple:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Intune → Intune Data Warehouse → OData → Power BI → Compliance Dashboard&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The important part is understanding what happens between each layer.&lt;/p&gt;

&lt;p&gt;Intune remains the operational management platform.&lt;/p&gt;

&lt;p&gt;The Data Warehouse provides the historical reporting dataset.&lt;/p&gt;

&lt;p&gt;OData provides the standardized interface through which Power BI accesses that dataset.&lt;/p&gt;

&lt;p&gt;Power BI then transforms, models and visualizes the information.&lt;/p&gt;

&lt;p&gt;The result is a reporting layer that can sit above the endpoint management platform.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5azjh3thwl0ajfuh0m3a.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5azjh3thwl0ajfuh0m3a.png" alt="Intune Data Warehouse to Power BI architecture" width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Connecting Power BI to the Intune Data Warehouse
&lt;/h2&gt;

&lt;p&gt;The first practical step is getting the tenant's Data Warehouse connection information.&lt;/p&gt;

&lt;p&gt;In the Microsoft Intune admin center, Microsoft currently documents the following location:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Reports → Intune Data warehouse → Data warehouse&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;From there, administrators can retrieve the custom OData feed URL for the tenant.&lt;/p&gt;

&lt;p&gt;The URL exposes the Data Warehouse service for the tenant.&lt;/p&gt;

&lt;p&gt;In Power BI Desktop, the connection can then be created through:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Get Data → OData Feed&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The tenant-specific OData URL is entered, and authentication is performed using an appropriate Microsoft Entra identity. Microsoft documents OAuth 2.0 authentication and notes that access is controlled through Microsoft Entra credentials and Intune RBAC.&lt;/p&gt;

&lt;p&gt;This is important from a security perspective.&lt;/p&gt;

&lt;p&gt;Power BI is not simply connecting anonymously to a database.&lt;/p&gt;

&lt;p&gt;Access to the Data Warehouse is governed by identity and authorization.&lt;/p&gt;

&lt;h2&gt;
  
  
  An Important Change: The Old Connector
&lt;/h2&gt;

&lt;p&gt;One of the most important considerations when building a new dashboard today is choosing the right connection method.&lt;/p&gt;

&lt;p&gt;Microsoft states that the &lt;strong&gt;Intune Data Warehouse beta connector in Power BI, commonly referred to as connector v1, is being retired&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Microsoft recommends migrating existing reports to the &lt;strong&gt;Intune connector v2 or the OData Feed connector&lt;/strong&gt;. Reports created after November 2025 already use connector v2 and are not affected by the retirement of connector v1.&lt;/p&gt;

&lt;p&gt;For a new custom reporting solution, the OData Feed is therefore a strong option because Microsoft explicitly identifies it as the recommended connector for custom Power BI reporting.&lt;/p&gt;

&lt;p&gt;This is one of those details that can easily be missed when following older Intune reporting tutorials.&lt;/p&gt;

&lt;p&gt;A dashboard built successfully several years ago may not be the architecture you want to reproduce today.&lt;/p&gt;

&lt;h2&gt;
  
  
  Understanding the Data Model Before Building Visuals
&lt;/h2&gt;

&lt;p&gt;One of the easiest mistakes to make in Power BI is connecting to a data source and immediately starting to create charts.&lt;/p&gt;

&lt;p&gt;The better approach is to understand the data model first.&lt;/p&gt;

&lt;p&gt;The Intune Data Warehouse uses a &lt;strong&gt;star-schema model&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;In simple terms, fact tables contain measurements or activities, while dimension tables provide context for those measurements.&lt;/p&gt;

&lt;p&gt;A date dimension tells us &lt;strong&gt;when&lt;/strong&gt; something happened.&lt;/p&gt;

&lt;p&gt;A device dimension tells us &lt;strong&gt;which device&lt;/strong&gt; was involved.&lt;/p&gt;

&lt;p&gt;A policy dimension tells us &lt;strong&gt;which policy&lt;/strong&gt; was involved.&lt;/p&gt;

&lt;p&gt;A user dimension provides context about &lt;strong&gt;who&lt;/strong&gt; is associated with the device or activity.&lt;/p&gt;

&lt;p&gt;Microsoft designed the model specifically so analytics tools such as Power BI can work with the relationships between these entities.&lt;/p&gt;

&lt;p&gt;This is where Power BI becomes considerably more powerful.&lt;/p&gt;

&lt;p&gt;Instead of treating every dataset as an isolated table, the model allows us to ask questions across the environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Data That Matters for Compliance Reporting
&lt;/h2&gt;

&lt;p&gt;Several Intune Data Warehouse entities are particularly useful when designing compliance dashboards.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;devices&lt;/strong&gt; entity contains information such as device identifiers, operating system, Microsoft Entra device ID, ownership, enrollment information and compliance state references.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;complianceStates&lt;/strong&gt; entity provides the recognized compliance states, including values such as Compliant, Noncompliant, and InGracePeriod.&lt;/p&gt;

&lt;p&gt;For policy-level reporting, the &lt;strong&gt;compliancePolicyStatusDeviceActivities&lt;/strong&gt; entity provides daily counts for states such as compliant, non-compliant, unknown, not applicable, error and devices in a grace period.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;compliancePolicyStatusDevicePerPolicyActivities&lt;/strong&gt; entity goes a step further by allowing compliance status to be analyzed per policy.&lt;/p&gt;

&lt;p&gt;This distinction is extremely useful.&lt;/p&gt;

&lt;p&gt;A dashboard that only shows overall compliance might tell you that compliance is 92%.&lt;/p&gt;

&lt;p&gt;A dashboard that also shows compliance per policy can explain &lt;strong&gt;why the other 8% are not compliant&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;That turns a number into an investigation starting point.&lt;/p&gt;

&lt;h2&gt;
  
  
  Designing the Dashboard Around Questions
&lt;/h2&gt;

&lt;p&gt;A good compliance dashboard should not be designed around the question:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“What charts can I create?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It should be designed around:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“What decisions should this dashboard help someone make?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That change in thinking has a major effect on the final product.&lt;/p&gt;

&lt;p&gt;For example, an executive dashboard could start with five core indicators:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Total Devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliant Devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Non-Compliant Devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance Percentage&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Devices Requiring Attention&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;These metrics should immediately answer whether the environment is healthy.&lt;/p&gt;

&lt;p&gt;Below those indicators, a compliance trend can show whether the organization is moving in the right direction.&lt;/p&gt;

&lt;p&gt;A platform comparison can show whether Windows, iOS/iPadOS, Android or other device populations are behaving differently.&lt;/p&gt;

&lt;p&gt;A policy analysis can identify the policies responsible for the greatest number of failures.&lt;/p&gt;

&lt;p&gt;And finally, a detailed device view can provide the operational information needed to investigate individual machines.&lt;/p&gt;

&lt;h2&gt;
  
  
  Measuring Compliance Percentage Correctly
&lt;/h2&gt;

&lt;p&gt;One of the most important design decisions is how the compliance percentage is calculated.&lt;/p&gt;

&lt;p&gt;A simple calculation could be:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Compliance % =
Compliant Devices / Devices Evaluated
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But the definition of &lt;strong&gt;Devices Evaluated&lt;/strong&gt; matters.&lt;/p&gt;

&lt;p&gt;It may include or exclude devices that are unknown, not applicable or in a grace period depending on the organization's reporting policy.&lt;/p&gt;

&lt;p&gt;This means two dashboards can use the same source data and produce different compliance percentages while both calculations appear mathematically correct.&lt;/p&gt;

&lt;p&gt;The metric therefore needs a documented business definition.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Compliance percentage represents the proportion of devices evaluated as compliant, excluding devices marked Not Applicable.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Another organization may choose to treat devices in a grace period differently.&lt;/p&gt;

&lt;p&gt;The calculation is not only a Power BI problem.&lt;/p&gt;

&lt;p&gt;It is a governance decision.&lt;/p&gt;

&lt;h2&gt;
  
  
  Creating Useful Power BI Measures
&lt;/h2&gt;

&lt;p&gt;Once the Data Warehouse has been loaded into Power BI, the next layer is the semantic model.&lt;/p&gt;

&lt;p&gt;This is where DAX measures become valuable.&lt;/p&gt;

&lt;p&gt;For example, a simple compliant-device measure could conceptually look like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Compliant Devices =
CALCULATE(
    DISTINCTCOUNT(devices[deviceKey]),
    devices[complianceStatus] = "Compliant"
)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A compliance percentage could then be calculated from the relevant compliant and evaluated populations.&lt;/p&gt;

&lt;p&gt;The exact DAX implementation will depend on the entities and relationships chosen for the model.&lt;/p&gt;

&lt;p&gt;The important principle is to centralize the logic.&lt;/p&gt;

&lt;p&gt;Do not create the same calculation independently on five different visuals.&lt;/p&gt;

&lt;p&gt;Create the measure once and reuse it.&lt;/p&gt;

&lt;p&gt;That makes the dashboard easier to maintain and greatly reduces the risk of inconsistent numbers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Building the Compliance Trend
&lt;/h2&gt;

&lt;p&gt;One of the strongest advantages of the Data Warehouse is historical analysis.&lt;/p&gt;

&lt;p&gt;A single compliance percentage is useful.&lt;/p&gt;

&lt;p&gt;A 30-day compliance trend is more useful.&lt;/p&gt;

&lt;p&gt;For example, suppose the organization reports:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;January: 87%&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;February: 89%&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;March: 91%&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That tells a different story from an isolated 91%.&lt;/p&gt;

&lt;p&gt;The trend demonstrates that the environment is improving.&lt;/p&gt;

&lt;p&gt;The opposite can also happen.&lt;/p&gt;

&lt;p&gt;A team might report 95% compliance today, but if the trend has fallen from 98% over several weeks, the situation deserves investigation.&lt;/p&gt;

&lt;p&gt;The date dimension and daily snapshots make this type of analysis possible. Microsoft specifically documents the Data Warehouse as a historical view of the changing Intune environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Identifying the Policies Causing Non-Compliance
&lt;/h2&gt;

&lt;p&gt;This is where the dashboard can become genuinely valuable to an endpoint engineering team.&lt;/p&gt;

&lt;p&gt;Instead of showing:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;401 non-compliant devices&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;the dashboard can show:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;BitLocker policy — 148 affected devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;OS version requirement — 97 affected devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security configuration — 76 affected devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Password policy — 52 affected devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Other — 28 affected devices&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Now the security or endpoint team has something actionable.&lt;/p&gt;

&lt;p&gt;The compliance policy activity entities in the Data Warehouse are specifically designed to provide counts by compliance state and, for certain entities, by policy.&lt;/p&gt;

&lt;p&gt;This allows Power BI to move from "How many?" to "Which policy?" and ultimately "What should we fix?"&lt;/p&gt;

&lt;p&gt;That progression is what makes a dashboard useful.&lt;/p&gt;

&lt;h2&gt;
  
  
  Drill-Down: From Management to Endpoint
&lt;/h2&gt;

&lt;p&gt;A well-designed Power BI solution should allow the user to move between levels of detail.&lt;/p&gt;

&lt;p&gt;At the highest level, management may see:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;92.4% Overall Compliance&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Clicking that figure could lead to:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance by Platform&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;From there:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance by Device Group&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Then:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance by Policy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And eventually:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Affected Devices&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the principle of &lt;strong&gt;progressive detail&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The dashboard starts with the answer and allows the user to investigate the reason.&lt;/p&gt;

&lt;p&gt;That is much better than forcing the reader to navigate through pages of raw device data.&lt;/p&gt;

&lt;h2&gt;
  
  
  Using Filters Without Making the Dashboard Complicated
&lt;/h2&gt;

&lt;p&gt;Power BI slicers can make an Intune dashboard dramatically more useful.&lt;/p&gt;

&lt;p&gt;Typical filters could include:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Operating System&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Ownership Type&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Device Category&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance State&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Policy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;User Group&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Date&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;But there is a balance.&lt;/p&gt;

&lt;p&gt;A dashboard with twenty slicers may technically be flexible while being practically unusable.&lt;/p&gt;

&lt;p&gt;The goal should be to provide only the filters that support real analytical questions.&lt;/p&gt;

&lt;p&gt;A good dashboard makes the important information visible first and places deeper analysis behind sensible filtering and drill-through.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Dashboard Should Tell a Story
&lt;/h2&gt;

&lt;p&gt;This is one of the biggest lessons I have taken from building technical dashboards.&lt;/p&gt;

&lt;p&gt;A dashboard is not a screenshot of data.&lt;/p&gt;

&lt;p&gt;It is a story.&lt;/p&gt;

&lt;p&gt;A useful sequence could be:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How healthy is the environment?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Then:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is it getting better or worse?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Then:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where is the problem?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Then:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why is the problem happening?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And finally:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which devices need attention?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That sequence creates a natural analytical journey.&lt;/p&gt;

&lt;p&gt;It also aligns with the way different teams consume information.&lt;/p&gt;

&lt;p&gt;An executive sees the first page.&lt;/p&gt;

&lt;p&gt;A security analyst goes deeper.&lt;/p&gt;

&lt;p&gt;An endpoint administrator reaches the device-level detail.&lt;/p&gt;

&lt;h2&gt;
  
  
  Power BI Performance Matters
&lt;/h2&gt;

&lt;p&gt;A dashboard can be visually impressive and still fail operationally if it takes too long to load.&lt;/p&gt;

&lt;p&gt;This is particularly important when working with endpoint data because device populations can become large.&lt;/p&gt;

&lt;p&gt;The Data Warehouse contains fact-style activity tables that can grow significantly, while some datasets have relatively limited retention windows. Microsoft's documentation notes that fact tables can become large and commonly have shorter retention periods than dimension tables.&lt;/p&gt;

&lt;p&gt;This makes data modelling important.&lt;/p&gt;

&lt;p&gt;Instead of bringing every available entity into Power BI, only load the information that contributes to the reporting objectives.&lt;/p&gt;

&lt;p&gt;Keep relationships deliberate.&lt;/p&gt;

&lt;p&gt;Use appropriate measures.&lt;/p&gt;

&lt;p&gt;Avoid unnecessary calculated columns.&lt;/p&gt;

&lt;p&gt;Filter historical data where the business requirement allows it.&lt;/p&gt;

&lt;p&gt;And design the semantic model before building dozens of visuals.&lt;/p&gt;

&lt;p&gt;Power BI performance is often won in the model long before the report page is created.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security and Access Control
&lt;/h2&gt;

&lt;p&gt;The Data Warehouse contains operational information about an organization's devices and users, so security cannot be an afterthought.&lt;/p&gt;

&lt;p&gt;Microsoft states that Intune Data Warehouse access is controlled through Microsoft Entra credentials and Intune RBAC. Intune administrators have access by default, while additional users can be granted appropriate Data Warehouse permissions through Intune roles. Microsoft also documents user-less application authentication for supported scenarios.&lt;/p&gt;

&lt;p&gt;This means the Power BI solution should be designed with least privilege in mind.&lt;/p&gt;

&lt;p&gt;Not everyone who can view a compliance percentage needs access to device-level information.&lt;/p&gt;

&lt;p&gt;A management audience may only need aggregated metrics.&lt;/p&gt;

&lt;p&gt;An endpoint team may require device details.&lt;/p&gt;

&lt;p&gt;A security team may require more granular investigation capability.&lt;/p&gt;

&lt;p&gt;The Power BI access model should reflect those requirements rather than simply giving everybody access to everything.&lt;/p&gt;

&lt;h2&gt;
  
  
  Refresh Strategy
&lt;/h2&gt;

&lt;p&gt;The refresh strategy needs to reflect the characteristics of the Data Warehouse.&lt;/p&gt;

&lt;p&gt;Because the warehouse uses daily snapshots, a dashboard built on top of it should not be presented as a real-time endpoint monitoring solution.&lt;/p&gt;

&lt;p&gt;That does not make it less valuable.&lt;/p&gt;

&lt;p&gt;It simply means the dashboard is designed for a different purpose.&lt;/p&gt;

&lt;p&gt;Power BI can answer questions such as:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;How has compliance changed?&lt;/p&gt;

&lt;p&gt;Which policies have consistently caused problems?&lt;/p&gt;

&lt;p&gt;Are non-compliance rates improving?&lt;/p&gt;

&lt;p&gt;Which platforms are underperforming?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For real-time or near-real-time endpoint investigation, a different data source may be more appropriate.&lt;/p&gt;

&lt;p&gt;Understanding the difference prevents a common reporting mistake: using a historical analytics source as though it were a live monitoring system.&lt;/p&gt;

&lt;h2&gt;
  
  
  Turning the Dashboard Into an Operational Tool
&lt;/h2&gt;

&lt;p&gt;The best outcome is not a beautiful dashboard.&lt;/p&gt;

&lt;p&gt;The best outcome is a dashboard that changes behavior.&lt;/p&gt;

&lt;p&gt;Imagine an endpoint team beginning the week by opening the Power BI report.&lt;/p&gt;

&lt;p&gt;The first page shows compliance has dropped from 94% to 90%.&lt;/p&gt;

&lt;p&gt;The trend identifies that the decline started approximately one week earlier.&lt;/p&gt;

&lt;p&gt;The policy view reveals that most failures involve one compliance requirement.&lt;/p&gt;

&lt;p&gt;The platform analysis shows that the majority of affected devices are Windows endpoints.&lt;/p&gt;

&lt;p&gt;The drill-through page identifies the specific devices.&lt;/p&gt;

&lt;p&gt;The engineering team can now move from:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data → Analysis → Investigation → Action&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;without manually exporting spreadsheets from the Intune portal.&lt;/p&gt;

&lt;p&gt;That is the real value of combining Intune Data Warehouse with Power BI.&lt;/p&gt;

&lt;h2&gt;
  
  
  Example Dashboard Structure
&lt;/h2&gt;

&lt;p&gt;A practical report could contain several pages.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;Executive Overview&lt;/strong&gt; provides total devices, compliance percentage, compliant versus non-compliant devices, and the overall trend.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;Compliance Analysis&lt;/strong&gt; page focuses on policy-level compliance, platform differences and the distribution of compliance states.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;Non-Compliance Analysis&lt;/strong&gt; page identifies the most common causes, affected device groups and policies requiring attention.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;Device Detail&lt;/strong&gt; page provides searchable device information for operational investigation.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;Trends &amp;amp; History&lt;/strong&gt; page focuses on historical movement, allowing teams to identify improvement, deterioration and recurring patterns.&lt;/p&gt;

&lt;p&gt;The exact number of pages is not important.&lt;/p&gt;

&lt;p&gt;The logical flow is.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Dashboard Should Not Do
&lt;/h2&gt;

&lt;p&gt;A compliance dashboard should not attempt to replace Intune.&lt;/p&gt;

&lt;p&gt;Intune remains the endpoint management platform.&lt;/p&gt;

&lt;p&gt;Power BI is the analytical layer.&lt;/p&gt;

&lt;p&gt;The dashboard should therefore help people understand the environment rather than become another place where administrators attempt to manage devices.&lt;/p&gt;

&lt;p&gt;This separation of responsibilities is healthy.&lt;/p&gt;

&lt;p&gt;Intune manages.&lt;/p&gt;

&lt;p&gt;The Data Warehouse preserves reporting-oriented information.&lt;/p&gt;

&lt;p&gt;Power BI analyses.&lt;/p&gt;

&lt;p&gt;The people operating the environment make decisions and take action.&lt;/p&gt;

&lt;h2&gt;
  
  
  Common Mistakes
&lt;/h2&gt;

&lt;p&gt;One mistake is building visuals before understanding the Data Warehouse schema.&lt;/p&gt;

&lt;p&gt;Another is calculating compliance without defining what "compliant" actually means.&lt;/p&gt;

&lt;p&gt;Another is treating daily warehouse data as real-time information.&lt;/p&gt;

&lt;p&gt;A further mistake is loading every available table simply because it is available.&lt;/p&gt;

&lt;p&gt;And perhaps the most common mistake is building a dashboard for the person who created it instead of the person who needs to make decisions from it.&lt;/p&gt;

&lt;p&gt;A dashboard should answer real questions.&lt;/p&gt;

&lt;p&gt;If a visual does not help someone understand the environment or decide what to do next, it probably does not belong on the main page.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Recommended Approach
&lt;/h2&gt;

&lt;p&gt;I would approach an Intune Power BI project in four broad stages.&lt;/p&gt;

&lt;p&gt;First, define the questions the dashboard must answer.&lt;/p&gt;

&lt;p&gt;Second, understand the Intune Data Warehouse entities and relationships that can answer those questions.&lt;/p&gt;

&lt;p&gt;Third, build a clean semantic model and reusable measures in Power BI.&lt;/p&gt;

&lt;p&gt;Finally, design the report around the decisions the target audience needs to make.&lt;/p&gt;

&lt;p&gt;This approach avoids a common trap where the project becomes:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Let's import Intune data into Power BI and see what we can build."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Instead, it becomes:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Let's solve a reporting problem using Intune data and Power BI."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is a much stronger starting point.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Building compliance dashboards from the Intune Data Warehouse is a great example of how endpoint administration and data analytics can complement one another.&lt;/p&gt;

&lt;p&gt;Intune already contains valuable information.&lt;/p&gt;

&lt;p&gt;The challenge is making that information understandable.&lt;/p&gt;

&lt;p&gt;The Data Warehouse provides the historical, structured foundation.&lt;/p&gt;

&lt;p&gt;OData provides a standard access layer.&lt;/p&gt;

&lt;p&gt;Power BI provides the modelling, calculations and visualization.&lt;/p&gt;

&lt;p&gt;Together, they can create a reporting solution that helps security and endpoint teams move beyond static numbers and toward meaningful analysis.&lt;/p&gt;

&lt;p&gt;The most important lesson is that a dashboard should not simply tell you what happened.&lt;/p&gt;

&lt;p&gt;It should help you understand:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happened?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why did it happen?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is it getting better or worse?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where is the problem?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What should we do next?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is where Power BI becomes more than a visualization tool.&lt;/p&gt;

&lt;p&gt;It becomes a decision-support platform for endpoint security and management.&lt;/p&gt;

&lt;p&gt;I remain learning, testing and improving my understanding of Microsoft Intune, Power BI and the broader Microsoft security ecosystem. Every dashboard, query and solution is another opportunity to turn technical data into something practical and useful.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;We learn. We build. We improve.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>microsoftintune</category>
      <category>powerbi</category>
      <category>odatafeed</category>
    </item>
    <item>
      <title>Rolling Out LAPS in a Hybrid AD and Entra ID Environment</title>
      <dc:creator>Songeziwe Fayindlala</dc:creator>
      <pubDate>Sun, 16 Aug 2026 00:20:40 +0000</pubDate>
      <link>https://dev.to/songeziwe/rolling-out-laps-in-a-hybrid-ad-and-entra-id-environment-1lm7</link>
      <guid>https://dev.to/songeziwe/rolling-out-laps-in-a-hybrid-ad-and-entra-id-environment-1lm7</guid>
      <description>&lt;h2&gt;
  
  
  &lt;strong&gt;Introduction&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Local administrator accounts are one of those things that every Windows administrator needs, but few security teams are comfortable leaving unmanaged.&lt;/p&gt;

&lt;p&gt;In many organizations, devices still contain powerful local accounts such as &lt;code&gt;Administrator&lt;/code&gt;, &lt;code&gt;admin&lt;/code&gt;, or a dedicated support account. When the same password is used across hundreds or thousands of machines, that convenience can quickly become a security problem. A compromised password on one workstation can become a stepping stone to other systems.&lt;/p&gt;

&lt;p&gt;This is where Windows Local Administrator Password Solution, better known as Windows LAPS, comes in.&lt;/p&gt;

&lt;p&gt;Windows LAPS is Microsoft's built-in capability for automatically managing local administrator passwords on supported Windows devices. It can generate and rotate passwords automatically, control how long passwords remain valid, and securely back up those credentials to either Windows Server Active Directory or Microsoft Entra ID.&lt;/p&gt;

&lt;p&gt;For organizations running a hybrid identity environment, however, deploying LAPS is not simply a matter of switching on a policy. The real challenge is deciding where passwords should be stored, how administrators should retrieve them, how permissions should be controlled, and how the rollout should be introduced without disrupting support operations.&lt;/p&gt;

&lt;p&gt;This article walks through that problem from an infrastructure and security perspective.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fx34ywxgn78ai1kspsacf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fx34ywxgn78ai1kspsacf.png" alt="Image diagram" width="799" height="469"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;What Windows LAPS Actually Solves&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;The fundamental problem LAPS addresses is password reuse.&lt;/p&gt;

&lt;p&gt;Imagine an organization with 1,000 Windows computers. Each computer has a local administrator account called &lt;code&gt;Administrator&lt;/code&gt;, and all 1,000 machines use the same password.&lt;/p&gt;

&lt;p&gt;That might make life easier for IT support, but from a security perspective it creates a large blast radius.&lt;/p&gt;

&lt;p&gt;If an attacker obtains that password from one machine, the same credential may work on hundreds of others. The attacker does not necessarily need to compromise a domain administrator account. A local administrator credential can provide enough access to move laterally, deploy malware, disable security controls, dump credentials, or establish persistence.&lt;/p&gt;

&lt;p&gt;LAPS changes this model.&lt;/p&gt;

&lt;p&gt;Instead of maintaining one shared password, each device receives its own unique local administrator password. Windows LAPS automatically manages that password and periodically rotates it according to the policy configured by the organization.&lt;/p&gt;

&lt;p&gt;The result is a much smaller security blast radius.&lt;/p&gt;

&lt;p&gt;A compromised password becomes a problem for one machine rather than an organization-wide reusable credential.&lt;/p&gt;

&lt;p&gt;That is the most important security benefit of LAPS.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Why Hybrid Environments Make LAPS More Interesting&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;A traditional Active Directory environment is relatively straightforward. Devices are domain joined, Group Policy is readily available, and administrators are accustomed to working with Active Directory as the source of identity and device information.&lt;/p&gt;

&lt;p&gt;Modern enterprises are rarely that simple.&lt;/p&gt;

&lt;p&gt;Many organizations now operate a hybrid environment where devices are joined to on-premises Active Directory while also being registered as Microsoft Entra hybrid joined devices. Intune may be managing endpoint policies while Active Directory continues to provide traditional domain services.&lt;/p&gt;

&lt;p&gt;This creates an important architectural decision:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where should the LAPS password be stored?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Microsoft supports Windows LAPS backups to either Windows Server Active Directory or Microsoft Entra ID. A hybrid-joined device can use either destination, but it cannot back up the same LAPS password to both at the same time.&lt;/p&gt;

&lt;p&gt;That one design decision has consequences for administration, recovery, security and troubleshooting.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Understanding the Two Storage Models&lt;/strong&gt;
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Windows Server Active Directory as the LAPS Password Store
&lt;/h3&gt;

&lt;p&gt;With the Active Directory model, the managed password is stored against the computer object in on-premises Active Directory.&lt;/p&gt;

&lt;p&gt;This approach fits organizations that still rely heavily on traditional domain infrastructure and have their support processes built around Active Directory.&lt;/p&gt;

&lt;p&gt;Administrators can use Windows LAPS PowerShell commands such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Get-LapsADPassword&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Identity&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;COMPUTERNAME&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-AsPlainText&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Microsoft also provides specific PowerShell commands for configuring the required Active Directory permissions. For example, computer accounts need appropriate permissions to update their own LAPS information, while designated administrators or support groups should receive controlled password-read permissions.&lt;/p&gt;

&lt;p&gt;The major advantage is operational familiarity.&lt;/p&gt;

&lt;p&gt;Your existing infrastructure team can continue using Active Directory-based workflows, while access to passwords can be delegated to a dedicated security or help-desk group instead of giving everyone Domain Admin privileges.&lt;/p&gt;

&lt;p&gt;This model is particularly attractive when machines must continue operating reliably in environments where on-premises Active Directory remains critical.&lt;/p&gt;

&lt;h3&gt;
  
  
  Microsoft Entra ID as the LAPS Password Store
&lt;/h3&gt;

&lt;p&gt;The second model is to back up LAPS credentials to Microsoft Entra ID.&lt;/p&gt;

&lt;p&gt;This is particularly useful for organizations moving toward cloud-managed endpoints and Microsoft Intune. Intune can configure Windows LAPS, rotate the password and provide an administrative interface for viewing password information where the administrator has sufficient permissions.&lt;/p&gt;

&lt;p&gt;Microsoft also provides the &lt;code&gt;Get-LapsAADPassword&lt;/code&gt; PowerShell cmdlet for retrieving credentials stored in Microsoft Entra ID.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Get-LapsAADPassword&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Identity&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;COMPUTERNAME&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Microsoft Entra provides granular permissions for LAPS retrieval. A custom role can be granted permission to read LAPS metadata without necessarily giving it permission to retrieve the password itself. The password-reading permission is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;microsoft.directory/deviceLocalCredentials/password/read
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;while the metadata-only permission is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;microsoft.directory/deviceLocalCredentials/standard/read
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is important because the ability to see that a password exists is very different from the ability to retrieve the actual credential.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The Architecture I Would Use in a Hybrid Environment&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;There is no universal answer for every organization.&lt;/p&gt;

&lt;p&gt;The correct design depends on where endpoint management is heading.&lt;/p&gt;

&lt;p&gt;If an organization is heavily dependent on on-premises Active Directory, traditional domain support and on-premises administrative workflows, backing up LAPS passwords to Active Directory is a logical choice.&lt;/p&gt;

&lt;p&gt;If the organization is moving toward Intune, Microsoft Entra ID and cloud-first endpoint management, using Microsoft Entra ID as the backup directory can provide a cleaner long-term architecture.&lt;/p&gt;

&lt;p&gt;The important point is not to configure both.&lt;/p&gt;

&lt;p&gt;A hybrid-joined device can back up its LAPS password either to Active Directory or Microsoft Entra ID, but not to both.&lt;/p&gt;

&lt;p&gt;For a modern hybrid organization, I would make the decision based on the target operating model rather than simply copying the existing infrastructure.&lt;/p&gt;

&lt;p&gt;If the long-term strategy is "Active Directory forever", AD-backed LAPS makes sense.&lt;/p&gt;

&lt;p&gt;If the long-term strategy is "cloud-managed Windows endpoints", Entra-backed LAPS becomes more attractive.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;LAPS Is More Than Password Rotation&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;One misconception about LAPS is that it simply changes the Administrator password every 30 days.&lt;/p&gt;

&lt;p&gt;That is only part of the solution.&lt;/p&gt;

&lt;p&gt;Windows LAPS supports password length, password complexity, password age and post-authentication actions. It can also manage the local account itself on supported newer Windows releases.&lt;/p&gt;

&lt;p&gt;Post-authentication actions are particularly interesting.&lt;/p&gt;

&lt;p&gt;An administrator might use the LAPS password to perform emergency maintenance on a device. After authentication, Windows LAPS can provide a defined grace period and subsequently reset the password. Depending on the configured policy, it can also sign out the account or restart the computer.&lt;/p&gt;

&lt;p&gt;That means the security model becomes:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;retrieve credential → perform required administrative task → credential becomes invalid again&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;rather than:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;retrieve credential → continue using the same credential indefinitely&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is a much stronger approach.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;A Practical Password Policy&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;A LAPS deployment should not be designed around the shortest possible password that passes a compliance check.&lt;/p&gt;

&lt;p&gt;The password should be long enough to resist offline and automated attacks while remaining compatible with operational requirements.&lt;/p&gt;

&lt;p&gt;Windows LAPS supports configurable password length, complexity and password age. It also supports passphrase-based configuration.&lt;/p&gt;

&lt;p&gt;For example, an organization might decide that the local administrator password should rotate every 7 days, or use another interval based on its risk profile.&lt;/p&gt;

&lt;p&gt;The exact value should not be copied blindly from another organization.&lt;/p&gt;

&lt;p&gt;A highly restricted environment may choose a shorter rotation period.&lt;/p&gt;

&lt;p&gt;A large enterprise with thousands of devices may prefer a longer interval combined with strong passwords and aggressive post-authentication controls.&lt;/p&gt;

&lt;p&gt;The important point is to treat password lifetime as a risk decision rather than an arbitrary number.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The Account Itself Matters&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Another area that deserves attention is the local administrator account.&lt;/p&gt;

&lt;p&gt;Many organizations already have accounts named:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Administrator
admin
SupportAdmin
LocalAdmin
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;LAPS can manage a specified local administrator account. It can also support automatic account management on supported versions of Windows 11 and Windows Server, allowing organizations to simplify the management of the built-in account or a custom account.&lt;/p&gt;

&lt;p&gt;This creates an opportunity to standardise endpoint administration instead of continuing to maintain several unmanaged local administrator accounts.&lt;/p&gt;

&lt;p&gt;One important limitation is that Windows LAPS manages one local administrator account per device at a time. Changing the account targeted by the policy means the previous account is no longer managed by that LAPS policy.&lt;/p&gt;

&lt;p&gt;That is something that should be considered before deployment.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Permissions Are More Important Than the Password&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;A technically correct LAPS deployment can still be insecure if too many people can retrieve the passwords.&lt;/p&gt;

&lt;p&gt;This is where least privilege becomes critical.&lt;/p&gt;

&lt;p&gt;An organization should not give the entire IT department unrestricted access to every local administrator password.&lt;/p&gt;

&lt;p&gt;Instead, access should be delegated according to operational responsibility.&lt;/p&gt;

&lt;p&gt;For example, a service desk team might have permission to retrieve passwords for workstation devices, while a server administration team might have access to server OUs.&lt;/p&gt;

&lt;p&gt;With Active Directory-backed LAPS, Microsoft provides commands such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Set-LapsADReadPasswordPermission&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;to delegate password-query permissions to specific principals. Microsoft also distinguishes between reading the password and having the necessary permission to decrypt encrypted passwords stored in Active Directory.&lt;/p&gt;

&lt;p&gt;The same principle applies in Microsoft Entra ID.&lt;/p&gt;

&lt;p&gt;Microsoft Entra supports separate permissions for reading LAPS metadata and reading the actual password, which makes custom least-privilege administrative roles possible.&lt;/p&gt;

&lt;p&gt;The password is valuable, but the ability to retrieve thousands of passwords is even more valuable to an attacker.&lt;/p&gt;

&lt;p&gt;That permission therefore deserves the same level of attention as other privileged access.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Active Directory LAPS and Entra LAPS: The Security Comparison&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;From a security perspective, neither storage location should be treated as automatically "more secure" simply because it is cloud or on-premises.&lt;/p&gt;

&lt;p&gt;The question is where the organization can enforce the strongest access controls and monitoring.&lt;/p&gt;

&lt;p&gt;An Active Directory implementation can be strong when administrative access is tightly delegated, LAPS passwords are protected with the appropriate encryption controls, and the relevant OUs are carefully secured.&lt;/p&gt;

&lt;p&gt;An Entra implementation can be strong when Microsoft Entra RBAC, Intune RBAC, privileged identity management, logging and conditional access controls are properly implemented.&lt;/p&gt;

&lt;p&gt;The weak point is usually not the technology.&lt;/p&gt;

&lt;p&gt;The weak point is excessive administrative access.&lt;/p&gt;

&lt;p&gt;A LAPS password that is rotated every seven days but can be retrieved by dozens of unnecessary administrators is still a security problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Rolling LAPS Out Without Breaking the Environment&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;A large LAPS deployment should be treated as an infrastructure change, not simply an Intune policy.&lt;/p&gt;

&lt;p&gt;The rollout should begin with discovery.&lt;/p&gt;

&lt;p&gt;Before creating the production policy, determine which Windows versions are actually deployed, which devices are hybrid joined, which devices are Entra joined, which devices are domain joined, which local administrator accounts exist, which devices are already using legacy Microsoft LAPS, and which administrative teams currently depend on shared local passwords.&lt;/p&gt;

&lt;p&gt;This discovery phase often reveals the real complexity.&lt;/p&gt;

&lt;p&gt;For example, an organization may discover that some machines use &lt;code&gt;Administrator&lt;/code&gt;, others use &lt;code&gt;admin&lt;/code&gt;, and others have a custom support account.&lt;/p&gt;

&lt;p&gt;Trying to deploy a single LAPS policy without understanding those differences is how migrations become messy.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Pilot Before Production&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;The next stage should be a controlled pilot.&lt;/p&gt;

&lt;p&gt;A small group of test devices should receive the LAPS policy first.&lt;/p&gt;

&lt;p&gt;The goal is not simply to verify that the password changes.&lt;/p&gt;

&lt;p&gt;The goal is to verify the entire process.&lt;/p&gt;

&lt;p&gt;The device should receive the policy, generate or set the password, successfully back up the credential to the selected directory, allow the correct support team to retrieve it, allow the administrator to use it, rotate the password, and record the appropriate events.&lt;/p&gt;

&lt;p&gt;Windows LAPS processes policy periodically, and administrators can trigger policy processing with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Invoke-LapsPolicyProcessing&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This makes testing much easier because administrators do not always need to wait for the next processing cycle.&lt;/p&gt;

&lt;p&gt;For an Active Directory deployment, administrators can verify successful updates through Windows LAPS events, including event ID 10018 for successful password updates to Active Directory.&lt;/p&gt;

&lt;p&gt;For Microsoft Entra-backed deployments, event ID 10029 can be used to verify successful password backup activity.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The Production Rollout&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Once the pilot is successful, rollout should happen in controlled waves.&lt;/p&gt;

&lt;p&gt;A good production deployment is not "deploy to 5,000 machines and see what happens".&lt;/p&gt;

&lt;p&gt;Instead, begin with a small production OU or Intune device group, review compliance and password-backup success, then expand to additional device groups.&lt;/p&gt;

&lt;p&gt;This also makes troubleshooting easier.&lt;/p&gt;

&lt;p&gt;If a deployment suddenly shows hundreds of failures, administrators need to be able to identify what changed between the successful and unsuccessful groups.&lt;/p&gt;

&lt;p&gt;Phased rollout makes that possible.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;What Happens When a Device Is Offline?&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;This is one of the practical questions that usually comes up during a hybrid LAPS deployment.&lt;/p&gt;

&lt;p&gt;The answer depends on which backup directory and management mechanism are being used, as well as the device's connectivity.&lt;/p&gt;

&lt;p&gt;A device does not need to be permanently connected to the corporate network simply because it uses LAPS. However, the device must be able to process its policy and successfully communicate with the directory used for password backup.&lt;/p&gt;

&lt;p&gt;This is one of the reasons why the backup-directory decision should be made together with the endpoint connectivity and support model.&lt;/p&gt;

&lt;p&gt;The architecture should reflect how users actually work, not how the environment looked five years ago.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Monitoring the Deployment&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;A LAPS deployment should be monitored like any other security control.&lt;/p&gt;

&lt;p&gt;The important question is not simply:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Is LAPS enabled?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The better questions are:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Are passwords rotating?"&lt;/p&gt;

&lt;p&gt;"Are passwords being successfully backed up?"&lt;/p&gt;

&lt;p&gt;"Who is retrieving them?"&lt;/p&gt;

&lt;p&gt;"Are there devices that have stopped updating?"&lt;/p&gt;

&lt;p&gt;"Are any devices still using unmanaged local administrator passwords?"&lt;/p&gt;

&lt;p&gt;"Are administrators using the retrieved credentials for longer than necessary?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Microsoft provides monitoring options through Intune, event logs, Active Directory attributes and PowerShell. Intune can also show password rotation information and device-level account details to administrators who have the required RBAC permissions.&lt;/p&gt;

&lt;p&gt;This is where LAPS becomes part of the organization's broader identity and endpoint security strategy rather than just another configuration policy.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;LAPS and Security Monitoring&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;LAPS should also be considered alongside Microsoft Defender, Microsoft Sentinel and endpoint logging.&lt;/p&gt;

&lt;p&gt;A local administrator account suddenly being used on dozens of machines is suspicious.&lt;/p&gt;

&lt;p&gt;A password retrieval event followed by privileged activity, remote connections or attempts to disable security tooling may deserve investigation.&lt;/p&gt;

&lt;p&gt;The more mature approach is to combine LAPS with endpoint telemetry.&lt;/p&gt;

&lt;p&gt;For example, LAPS can control the credential while Defender for Endpoint identifies suspicious activity performed using that credential.&lt;/p&gt;

&lt;p&gt;Neither system replaces the other.&lt;/p&gt;

&lt;p&gt;They work better together.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;What About Legacy Microsoft LAPS?&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Organizations that already use the older Microsoft LAPS implementation should plan a migration rather than running the legacy solution indefinitely.&lt;/p&gt;

&lt;p&gt;Microsoft recommends migrating existing environments to Windows LAPS. Windows LAPS can coexist temporarily with legacy LAPS, but the policies need to target different local accounts for side-by-side operation.&lt;/p&gt;

&lt;p&gt;Microsoft documents two main migration approaches.&lt;/p&gt;

&lt;p&gt;The first is an immediate transition where the legacy policy is removed and Windows LAPS is introduced.&lt;/p&gt;

&lt;p&gt;The second is a temporary side-by-side deployment using a different local account before the legacy configuration is eventually retired.&lt;/p&gt;

&lt;p&gt;Whichever approach is chosen, the migration should be tested before the legacy deployment is removed from production.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Common Mistakes During a LAPS Deployment&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;The biggest mistake is treating LAPS as a password-change tool.&lt;/p&gt;

&lt;p&gt;It is actually an identity security control.&lt;/p&gt;

&lt;p&gt;Another common mistake is giving too many people permission to retrieve credentials.&lt;/p&gt;

&lt;p&gt;A third is deploying the policy before identifying the actual local administrator accounts in the organization.&lt;/p&gt;

&lt;p&gt;Another problem is failing to decide where passwords belong before deployment.&lt;/p&gt;

&lt;p&gt;Hybrid environments make this especially important because Microsoft allows hybrid-joined devices to back up passwords to either Active Directory or Microsoft Entra ID, but not both.&lt;/p&gt;

&lt;p&gt;A final mistake is failing to test the recovery process.&lt;/p&gt;

&lt;p&gt;A password that rotates successfully but cannot be retrieved by the help desk is not a successful deployment.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;My Recommended Hybrid Strategy&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;For an organization that is still heavily dependent on on-premises Active Directory, I would normally start with Active Directory-backed Windows LAPS, provided the organization can properly delegate password access and protect the relevant OUs.&lt;/p&gt;

&lt;p&gt;For organizations that are already strongly invested in Intune and are deliberately moving toward cloud-managed endpoints, Microsoft Entra-backed LAPS is a compelling long-term architecture.&lt;/p&gt;

&lt;p&gt;The important part is to make the decision based on the organisation's target state rather than its current state.&lt;/p&gt;

&lt;p&gt;LAPS should form part of the migration toward stronger endpoint security, not become another legacy dependency.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;A Simple Rollout Model&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;The deployment can be thought of as a sequence rather than a single change.&lt;/p&gt;

&lt;p&gt;First, assess the current environment.&lt;/p&gt;

&lt;p&gt;Then decide whether Active Directory or Microsoft Entra ID will be the authoritative LAPS password store.&lt;/p&gt;

&lt;p&gt;Next, define the local account that LAPS will manage and design the password and rotation policy.&lt;/p&gt;

&lt;p&gt;After that, configure the required permissions and test password retrieval.&lt;/p&gt;

&lt;p&gt;The pilot should then validate the complete lifecycle from policy deployment to password rotation and administrative recovery.&lt;/p&gt;

&lt;p&gt;Only after that should the organization expand the deployment into production in controlled waves.&lt;/p&gt;

&lt;p&gt;Finally, monitoring should become part of normal security operations.&lt;/p&gt;

&lt;p&gt;This approach dramatically reduces the risk of introducing an endpoint security policy without understanding its operational consequences.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;The Bigger Security Picture&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;LAPS does not solve every local administrator problem.&lt;/p&gt;

&lt;p&gt;It does something more specific and arguably more important: it removes the need for organizations to rely on shared, static local administrator passwords.&lt;/p&gt;

&lt;p&gt;That single change can significantly reduce lateral-movement risk.&lt;/p&gt;

&lt;p&gt;The real value of LAPS appears when it is combined with the rest of the Microsoft security stack.&lt;/p&gt;

&lt;p&gt;Microsoft Entra ID provides identity and role-based access control.&lt;/p&gt;

&lt;p&gt;Intune provides policy management.&lt;/p&gt;

&lt;p&gt;Windows LAPS manages privileged local credentials.&lt;/p&gt;

&lt;p&gt;Microsoft Defender provides endpoint visibility.&lt;/p&gt;

&lt;p&gt;Microsoft Sentinel can provide broader security monitoring and correlation.&lt;/p&gt;

&lt;p&gt;Together, these controls create a much stronger security architecture than any single product could provide.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;strong&gt;Final Thoughts&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Rolling out LAPS in a hybrid Active Directory and Microsoft Entra environment is not difficult because the technology is complicated.&lt;/p&gt;

&lt;p&gt;It is difficult because the environment itself is complicated.&lt;/p&gt;

&lt;p&gt;The organization has to make decisions about identity, endpoint management, administrative permissions, password storage, help-desk access, monitoring and migration.&lt;/p&gt;

&lt;p&gt;Windows LAPS gives administrators the technology needed to solve the local administrator password problem.&lt;/p&gt;

&lt;p&gt;The architecture and governance determine whether that technology becomes a real security improvement.&lt;/p&gt;

&lt;p&gt;For organizations still using shared local administrator passwords, LAPS should not be viewed as an optional optimization.&lt;/p&gt;

&lt;p&gt;It should be viewed as one of the foundational controls for securing Windows endpoints.&lt;/p&gt;

&lt;p&gt;The goal is simple:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Every device should have a strong local administrator credential.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;That credential should be unique.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It should rotate automatically.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Only authorized administrators should be able to retrieve it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;And the organization should know when and where that credential is being used.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is the real value of Windows LAPS.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>windowslaps</category>
      <category>microsoftintune</category>
      <category>endpointsecurity</category>
    </item>
  </channel>
</rss>
