CTD-000177

Device enrolled in Intune but never synced

Medium
Entra ID Intune
Defense Evasion Initial Access
v6

Signature Identity

CTD-000177
Threat ID
6
Version
IOE
Indicator Type

Threat Description

When a device is successfully enrolled in Intune but never performs a compliance check-in, it may indicate one of the following: the management agent failed to initialize, the user uninstalled the MDM profile, or the device was enrolled solely to satisfy Conditional Access requirements and was subsequently abandoned or hidden from management.

MITRE ATT&CK: Attack Tactics

Defense Evasion Initial Access

D3FEND: Defend Tactics

D3-CM Configuration Monitoring D3-HCI Host-based Configuration Inspection

Remediation

  1. Notify the user that their device has not checked in within the expected time frame.
  2. Mark the device as non-compliant to trigger Conditional Access policies and revoke access to corporate resources.
  3. Enforce re-enrollment by requiring the device to re-enroll and successfully complete an MDM sync before access is restored.
  4. Review and update your compliance policies to ensure the Mark devices without a compliance policy setting is configured as Not compliant.

Frequently Asked Questions

What does Device enrolled in Intune but never synced mean?

Device enrolled in Intune but never synced indicates that a device has been successfully enrolled in Microsoft Intune, but it has not performed a compliance check-in within the expected time frame. This can be due to a management agent failure or user uninstallation of the MDM profile.

Device enrolled in Intune but never synced is rated medium severity because it allows attackers to maintain persistence and gather information about the environment through reconnaissance, ultimately supporting future malicious operations.

Attackers can use a device enrolled in Intune but never synced as an entry point for gathering information about the environment and planning future attacks. This is possible because the device's non-compliance status allows it to remain connected to the network without valid credentials, enabling persistence.

Cayosoft Guardian detects Device enrolled in Intune but never synced by continuously monitoring the compliance status of devices within Microsoft Intune. When a device is found to be non-compliant, Guardian flags it as a security issue and provides visibility for administrators to take action.

Cayosoft Guardian helps reduce the risk by alerting administrators to take action, such as notifying users and revoking access to corporate resources. Guardian also supports ongoing monitoring to ensure that devices remain compliant, show change history, and assist response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Intune
Themes
Endpoint Protection
Attack Tactics
Defense Evasion Initial Access
Defend Tactics
D3-CM Configuration Monitoring D3-HCI Host-based Configuration Inspection
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical