1Security
Screens

Devices

See every device touching your data - including the ones Microsoft never told you about - and answer whether your information is being accessed from machines you don't control.

Devices

The Devices screen answers a question most organizations can't: "What is actually touching our data - and do we trust it?" It brings every device in your environment into one view, from fully managed corporate laptops to personal phones, and even devices you didn't know existed.

What You Can Achieve

Find devices you didn't know about

Microsoft shows you registered and managed devices. 1Security also surfaces unregistered and 'shadow' devices - ones seen in sign-ins or data activity without ever enrolling in your directory.

Answer 'who accessed this, from what?'

A sensitive file was downloaded. Was it a compliant company laptop, or someone's personal phone on public Wi-Fi? Every device links to its users, locations, and activity.

Clean up your attack surface

Stale, orphaned, and disabled devices are easy wins for an attacker and easy misses for IT. Quick filters surface them instantly.

Tighten offboarding

Find the lingering devices of a departed employee that still hold access - before they become a breach.

Registered, Unregistered, and Shadow Devices

Attackers do not break in any more, they log in - and once they hold a valid token, the account behaves exactly like the account. Every log line is legitimate, because the credential is legitimate. The one part of the story that does not fit is the machine using it, which is why the device layer is where most identity attacks first become visible, and why device security is no longer an IT hygiene task but a security control.

Not every device politely registers itself with Microsoft. 1Security classifies every device it sees so nothing slips through:

  • Registered - properly enrolled in Entra ID / Intune, with full posture information.
  • Unregistered - a device that is not in your directory at all, however we discovered it - from sign-in events or from data activity. Unmanaged access you'd otherwise be blind to.
  • Shadow - the riskiest subset of unregistered: a device observed accessing data with no observed authentication at all. Think "a sensitive document was opened from a machine that never signed in the normal way."

Because devices are reconstructed from real activity - not just the directory

  • the Devices screen reflects how your data is actually being reached, which is often broader than the official device inventory.

Working With Intune, Not Against It

1Security integrates natively with Entra ID and Intune: compliance, management state, ownership, and trust type are read straight from Microsoft, so the posture you see here always agrees with your MDM. On top of that foundation, 1Security adds what Intune structurally can't see:

  • Devices that never enrolled. Intune's model starts at enrollment - unregistered and shadow devices are invisible to it by definition.
  • A real last-seen signal. Entra's activity timestamp updates only about every two weeks, and only on certain authentications; 1Security's last-seen comes from actual activity logs.
  • The data types. Which files, users, and locations a device has touched - Intune has no data-access view at all.

None of this requires special licensing: a Business Basic tenant is enough for every insight 1Security produces itself - discovery, activity statistics, locations, and the data linkage. An Intune license enriches the same rows with Intune's own posture fields (compliance, management state, ownership) and unlocks remediation: when you find a device to wipe, retire, or disable, you do it in Intune or Entra - 1Security tells you exactly which ones deserve it.

Quick Filters

An always-visible chip row above the list puts the security-relevant cuts one click away, each with a live count:

  • Shadow and Unregistered - the discovery classes described above.
  • Unmanaged - not under Intune (or any MDM) management.
  • Non-compliant - failing its compliance policy.
  • Rooted - jailbroken or rooted devices.
  • Compliance expired - the device's compliance certification has lapsed.
  • No activity in the last year - stale devices; prime cleanup and attack-surface candidates.
  • Personal - BYOD: personal devices used for work.
  • Disabled - device accounts turned off.

Chips combine with each other and with the full filter drawer - they're one mechanism - so Unmanaged + Personal is the classic "BYOD that nobody controls" view, one click away.

The Device List

Each row summarizes a device at a glance - its name, operating system, how it's joined to your network (Trust Type), whether it's compliant and managed (e.g. by Intune), whether it's company-owned or personal, its account status, when it was first and last seen, its most recent IP, and the users associated with it.

Because devices are reconstructed from activity, each one also carries statistics no directory can give you: how many sign-ins it has made, and how many distinct users, applications, and IP addresses it has been seen with. A device shared by four users across twelve apps and nine IPs reads very differently from a one-user laptop - alongside hardware identity (manufacturer, model) and browser, that context is often what turns a row into a lead.

Click any device to open its detail drawer for the full story.

The Locations Tab

Inside a device's drawer, the Locations tab shows a travel timeline: every place that device has been seen active - country, city, and network - newest first, with how many events came from each and when it was first and last seen there. Click a location to jump straight to that device's activity from it.

This makes questions like "has this device suddenly started connecting from a datacenter or a foreign country?" answerable in seconds. See Location Intelligence for how these places are resolved.

Filtering In Depth

A full filter drawer narrows the list to exactly what you're investigating - by registration status (registered, unregistered, shadow), management and compliance state, rooted/jailbroken status, orphaned indicators (no recent activity, no assigned users), account status, compliance expiration, operating system, trust type, ownership, registration and last-seen date ranges, and the specific users a device belongs to.

A powerful investigative pattern: combine Unmanaged + Personal ownership + a recent last-seen range to find exactly the unmanaged, personal devices that have been touching your environment lately.

On this page