CybrOakStart free

Guides

How to turn Microsoft Intune into a SOC 2 & CIS compliance report

Intune knows whether your devices are compliant. Auditors want that proven against named controls. Here's how to bridge the gap — manually, or in one click.

Updated June 2026 · 6 min read

The gap: “compliant in Intune” is not “evidence for an auditor”

Microsoft Intune does a good job telling you whether a device meets your compliance policy — Compliant, Not compliant, In grace period. What it does not do is express that posture as evidence against the controls an auditor actually tests: SOC 2 Trust Services Criteria, CIS Controls v8, or ISO/IEC 27001 Annex A. When a SOC 2 auditor asks “show me that every production endpoint is encrypted and running endpoint protection,” a screenshot of the Intune compliance blade is not a clean answer.

The good news: Intune (via Microsoft Graph) already holds almost every signal you need. The work is in mapping those signals to controls and packaging them as evidence.

What auditors actually want from your endpoints

Across SOC 2, CIS v8 and ISO 27001, the endpoint questions are remarkably consistent. For each managed device, you need to demonstrate:

  • Disk encryption is enabled (BitLocker).
  • Endpoint protection / anti-malware is active (Microsoft Defender).
  • Host firewall is on.
  • Security patches are current (no missing critical updates / known-exploited CVEs).
  • The device is actively managed (checking in, not stale, supported OS).

Mapping Intune signals to controls

Every one of those is a field Intune already reports. Here is the mapping CybrOak uses out of the box:

Intune signalCIS v8SOC 2ISO 27001
BitLocker encryption3.6CC6.1A.8.24
Defender antivirus10.1CC6.8A.8.7
Firewall enabled4.5CC6.6A.8.20
Missing security patches (CVEs)7.3CC7.1A.8.8
OS end-of-life2.2CC7.1A.8.8
Stale / non-compliant device1.1 / 4.1CC6.1 / CC7.1A.5.9 / A.8.9

The manual way (and why it hurts)

You can assemble this yourself. Export device compliance from the Intune admin center, pull CVE data from Microsoft Defender Vulnerability Management, and use Microsoft Purview Compliance Manager for control mapping. It works, but three things make it painful:

  • It’s spread across three consoles — Intune, Defender, and Purview — each with its own export.
  • The high-value pieces are E5-gated. Defender Vulnerability Management’s richest data and Purview’s premium framework templates effectively require Microsoft 365 E5 or add-ons. Teams on E3 / Business Premium are left stitching spreadsheets.
  • The output is an Excel snapshot, not a clean, branded, point-in-time evidence document an auditor (or your client) can accept as-is.

The fast way

CybrOak reads the same Intune data via read-only Graph consent — no agent, no E5 — maps every device to the controls above, and generates a single audit-ready PDF evidence pack (plus CSV). MSPs can produce one per client, white-labeled. Setup is about 60 seconds; the first report is one click.

FAQ

Does Intune alone prove SOC 2 compliance?

No. Intune enforces and reports device compliance, but SOC 2 requires evidence mapped to the Trust Services Criteria over an audit period. You need a layer that translates Intune posture into control-level evidence.

Do I need Microsoft 365 E5?

Not for the device-posture-to-control mapping described here. The core signals (encryption, antivirus, firewall, OS version, compliance state) are available on base Intune in E3 and Business Premium. CybrOak is built to work without an E5 upgrade.

What about third-party application vulnerabilities?

Intune-metadata CVE detection covers operating-system patch level well. For deep third-party application and firmware CVE scanning, a sensor-based tool (e.g. Microsoft Defender Vulnerability Management) sees a broader surface — a useful complement to endpoint posture evidence.

Generate this report from your own Intune — in 60 seconds

CybrOak maps your fleet to CIS, SOC 2 & ISO 27001 and produces an audit-ready evidence pack. No agent, no E5 required.

Start free
← All guides·Home