Skip to main content

University Configurations and Automation (Intune)

Below are the configurations, automation, and compliance checks managed by Stanford University IT, which apply to nearly every device enrolled in Intune at Stanford. 

Distributed IT administrators may apply additional configurations and automation. 

Create a request or ask a question 

Our commitment to your privacy 

Stanford University respects your privacy. Intune is a device management service, not monitoring or surveillance software. Stanford configures Intune to collect only the information required to keep university-connected devices secure, healthy, and compliant with Stanford's Minimum Security Standards. 

What Intune cannot see 

Regardless of device ownership or enrollment type, Intune never gives Stanford access to: 

  • Browsing history 
  • Calling and text message history 
  • Personal email messages, contacts, and calendars 
  • Passwords 
  • Photos, including what's in the Photos app or camera roll 
  • The contents of your personal files and documents 
  • On personally owned Android devices, Stanford manages only the separate work profile. Personal apps and data on the device are not visible to Stanford. 

For Microsoft's own reference, see What info can your organization see when you enroll your device?

What we collect 

  • User information: who the device belongs to, such as your name, email address, and system-generated account identifiers. 
  • Device data: identifiers and service details for the device itself, such as its Intune and Microsoft Entra IDs, network information, and storage space. 
  • Hardware inventory: basic facts about the hardware, such as device name, manufacturer, model, serial number, operating system and version, and IP address. 
  • Application inventory: the names of the application versions installed on your device, not their contents. 
    • For personally owned Windows devices, only the names of the Stanford ("managed") apps that Stanford deploys; your personal apps are not listed. 
  • Cellular data: SIM identifiers and phone number 

For the complete and official list, see Data collection in Intune on Microsoft Learn. 

Note: iOS and iPadOS devices are not enrolled in Intune at Stanford; Apple devices are managed with Jamf

What we configure 

Stanford applies a standard set of configuration policies and profiles to enrolled devices to keep them secure and consistent with the Minimum Security Standards. 

On Windows, these cover settings such as event logging and account auditing, biometric sign-in, and BitLocker disk encryption with recovery keys escrowed to Microsoft Entra ID. On Android, they connect devices to the Stanford Wi-Fi network and keep Stanford data separated from personal data through the work profile. Applying these settings does not give Stanford access to the contents of your files. 

For configurations and what each one does, see the dedicated page for your platform: Windows [Configuration Policies (Windows)] or Android [Configuration Profiles (Android)]. 

What we can do 

What a management system could do in theory is broad, so this section focuses on what Stanford actually does. Day to day, the service uses a small set of remote actions: 

  • Sync a device to refresh its policies and inventory 
  • Remotely lock a device 
  • Reset the work-profile passcode (Android) 
  • Retire a device (remove university data): removes Stanford accounts, apps, and the work profile without touching personal data 
  • Wipe (factory reset) a device, for example, if it is lost or stolen 
  • Restart a university-owned Windows device 
  • Retrieve BitLocker recovery keys to help you recover your own encrypted data (Windows) 
  • Update system software 
  • Update application software 
  • Collect diagnostic logs for troubleshooting (Windows); this gathers system logs, not personal files 

For the extent and limits of what Intune is capable of, see Microsoft's documentation on remote device actions

How do you know any of this is happening? 

Windows computers 

On the computer itself: 

  • Settings > Accounts > Access work or school > select your Stanford account > Info: shows the areas managed by Stanford and the most recent sync 
  • Company Portal app: shows your device's status and what is managed 

In the Microsoft Intune admin center (service administrators): 

  • Device record > Device configuration: per-policy assignment and status 
  • Device record > Device actions status: pending, failed, and completed actions 
  • Tenant administration > Audit logs: a record of actions administrators take 

Android mobile devices 

On the device itself: 

  • Work profile apps appear with a briefcase badge 
  • Settings > Security & privacy > Device admin apps (path varies by manufacturer and Android version) 
  • Company Portal or Microsoft Intune app: shows what is managed and your compliance status 

Questions? 

If you have questions, suggestions, or feedback, please submit a Help request.

Last modified