All baseline controls
Endpointhigh priority

MDM-enrolled devices are encrypted

Disk encryption on MDM-enrolled devices. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Disk encryption on MDM-enrolled devices

A device enrolled in mobile device management should have disk encryption enabled — an unencrypted, MDM-managed laptop is a data-breach waiting for a lost bag.

Interpret the result in context

An encryption-state fact does not establish recovery-key availability. Confirm recovery arrangements and platform requirements before changing encryption settings.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Identify enrolled devices reporting encryption as disabled.

  2. 02

    Check recovery-key handling and apply the approved encryption policy.

  3. 03

    Verify encryption completion and refresh the device evidence.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access