SCCM / Intune Healthcare (behavioral health)

How a behavioral health practice secured client data on remote team laptops with Intune

Client records now live only on enrolled, compliant devices, and the practice can cut access cleanly the moment someone leaves.

A behavioral health practice
Healthcare (behavioral health)
25 users plus offshore assistants
Phased rollout
At a glance

MStack360 secured a behavioral health practice whose remote assistants were signing into client records from personal laptops the practice had never seen. We enrolled every device in Microsoft Intune, then layered Conditional Access and Data Loss Prevention. Offboarding is now instant. Company data lives only on devices the practice controls, and access can be cut the same day someone leaves.

  • Company data reachable only from enrolled, compliant devices. A wipe removes company data and never touches an assistant's personal files
  • Clean, same day offboarding. A departing assistant loses access the moment they leave
  • A phased rollout, tested on a pilot group first. Nobody got locked out of their work part way through the day
What this story covers
  1. The exposure
  2. How we secured it
  3. Every device compliant
  4. What we delivered
  5. The payoff
The Challenge

Client records sat on laptops the practice had never seen

This behavioral health practice ran a partly remote team. Virtual assistants and contractors, several of them offshore, signed into email, files, and sensitive client records every day. They were good at their jobs. The problem was where they worked. Every one of them signed in from a personal laptop the practice had never seen. There was no device management, no data loss prevention, and no clean way to remove access when someone moved on.

The owner knew this quietly, the way most owners do. Client data sat on machines nobody controlled. An offboarding meant hoping a former assistant would simply stop opening files. With protected health information in the mix, that was a risk the practice could no longer carry. They wanted it fixed the week before a scare, not the week after.

The risk was not a hacker. It was protected health information living on personal laptops the practice could neither see nor switch off.

What They Needed

Control over where the data lives, without locking the team out

  • Company data reachable only from devices the practice could trust
  • A way to remove company data from a lost or departing laptop without touching the owner's personal files
  • Sign in checks that account for who is signing in, from where, and on what device
  • Protection against sensitive client records and card numbers leaving by accident
  • A clear measure of where the tenant stood on security, with gaps documented and closed
  • Trustworthy admin access, given the sensitivity of the data
  • A rollout that would not lock anyone out of their work part way through the day
Our Approach

We read the Secure Score live, then closed the gaps in phases

Reviewed the Secure Score live

We started with a short call and looked at the tenant's Secure Score together. It took minutes, and it was eye opening. A vague worry became a concrete, prioritized list.

Delivered a plain language gap list

We wrote up what was risky, what it would cost to fix, and what could wait. No jargon, just decisions the owner could make.

Enrolled devices in Intune

We set company data to be reachable only from enrolled, compliant devices. Every machine became wipeable for company data, without reaching personal files.

Layered Conditional Access

We added sign in policies that check the person, the location, and the device. This is the layer that makes multi factor authentication actually effective.

Turned on Data Loss Prevention

We configured policies so sensitive client records and card numbers cannot leave by accident. Then we hardened the tenant with Defender and closed every gap the Secure Score surfaced. Each improvement was documented.

Rolled out in phases with a pilot group

We tested every policy with a small pilot group first, so nobody got locked out of work as the changes spread to the full team.

The promise on screen

Every device enrolled, compliant, and recoverable

Once a device is enrolled in Intune, every check has to pass before it touches company data. The same rules that let an assistant work also let the practice cut off a lost or departing laptop cleanly. A wipe removes only company information and leaves personal photos, files, and apps alone. This is the compliance posture every managed device now reports.

Getting the tenant right is the foundation that makes all of this hold. Want to check where your own email domain stands? Our free DMARC record generator shows you in minutes.

What We Ran Into

The real world snags of a remote team, all handled

Assistants worried about a wipe touching personal files

Personal laptops made people nervous about enrollment.We configured Intune to separate company data from personal data. A remote wipe removes only company information and leaves personal photos, files, and apps alone.

Offshore devices the practice had never seen

Several machines were unmanaged and out of reach.We enrolled them remotely. Then we set company data to be reachable only from enrolled, compliant devices before allowing any access.

Risk of locking the team out part way through the day

New sign in and device policies can break people's work.We tested every policy with a small pilot group first and only widened the rollout once real sign ins passed cleanly.

Sensitive records leaving by accident

Client data and card numbers could slip out through email or sharing.We turned on Data Loss Prevention policies that catch and stop that sensitive data before it leaves.

What We Delivered

A measured, controlled tenant the practice could trust

Intune device management

Company data only on enrolled, compliant devices. A remote wipe of company data never touches an assistant's personal files.

Conditional Access

Sign ins evaluated by user, location, and device before access is granted.

Data Loss Prevention

Guardrails that stop sensitive client and payment data from leaving by accident.

Defender and Secure Score hardening

A measured tenant with gaps closed and improvements written down.

A trust first engagement

Least privilege admin access, a signed NDA, and no stored credentials.

A readable handover

Documentation that auditors, insurers, or clients can actually read.

Results

The payoff for the practice

Controlled
Company data only on devices the practice controls. Unmanaged personal laptops no longer hold client records
Same day
Offboarding. Access and company data are removed the moment someone leaves
Zero
Work stoppages during rollout. The pilot group caught issues before the full team felt them

"Our assistants were logging into client files from laptops we had never seen. Now company data only lives where we can control it, and when someone leaves we can cut it off the same day. It is the first time we have slept easy about this."

Practice owner, a behavioral health company

The solution behind this story

Microsoft 365 Security, Compliance & Intune

We secure your Microsoft 365 using the tools your license already includes or can add affordably. It is built on Zero Trust principles, so company data stays on devices you control. No new vendor, no tools you do not need.

Intune device management Conditional Access Data Loss Prevention
Common Questions

What people ask about this kind of project

If you manage our assistants' laptops, can you see or wipe their personal files?

No. Intune separates company data from personal data. A remote wipe removes the company information without touching personal photos, files, or apps on the device.

We are a small team. Are we really a target?

The risk is not about size. Your assistant already has client data on an unmanaged personal laptop, which is the exposure that matters. We close that gap regardless of headcount.

Does this make us HIPAA compliant?

It makes your tenant meaningfully more secure and hardened, which is foundational. A formal HIPAA or PCI compliance program is separate, additional work. We scope that honestly, rather than overstating what tenant hardening alone covers.

A note on scope

We say this plainly, because honesty is the point

Tenant hardening is not the same as a formal HIPAA or PCI compliance program. Those programs involve additional work. We scope them separately and honestly, rather than implying that turning on these controls makes a practice formally compliant. What this engagement does is give the practice real control over where its client data lives, plus the ability to cut it off cleanly. That control is the foundation everything else is built on.

Google review

"Omar and Ahmed got my business email and Defender up and running again in no time. Would recommend them all the time."

Darrin Lepore Google review See all our reviews on Google

Worried about where your client data actually lives?

Let us read your Secure Score with you and lay out the gaps in plain language. The first call is on us.

Book a call