University Configurations and Automation (Intune)
Below are the configurations, automation, and compliance checks managed by Stanford University IT, which apply to nearly every device enrolled in Intune at Stanford.
Distributed IT administrators may apply additional configurations and automation.
Create a request or ask a question
Our commitment to your privacy
Stanford University respects your privacy. Intune is a device management service, not monitoring or surveillance software. Stanford configures Intune to collect only the information required to keep university-connected devices secure, healthy, and compliant with Stanford's Minimum Security Standards.
- Access to data collected by Intune is limited to legitimate operational purposes, consistent with Administrative Guide 6.1.1, Privacy and Access to Electronic Information, and 6.2.1, Computer and Network Usage Policy.
- Access to the Intune system configuration is limited to the University Intune service administration team.
- Actions administrators take in Intune are recorded in audit logs.
What Intune cannot see
Regardless of device ownership or enrollment type, Intune never gives Stanford access to:
- Browsing history
- Calling and text message history
- Personal email messages, contacts, and calendars
- Passwords
- Photos, including what's in the Photos app or camera roll
- The contents of your personal files and documents
- On personally owned Android devices, Stanford manages only the separate work profile. Personal apps and data on the device are not visible to Stanford.
For Microsoft's own reference, see What info can your organization see when you enroll your device?.
What we collect
- User information: who the device belongs to, such as your name, email address, and system-generated account identifiers.
- Device data: identifiers and service details for the device itself, such as its Intune and Microsoft Entra IDs, network information, and storage space.
- Hardware inventory: basic facts about the hardware, such as device name, manufacturer, model, serial number, operating system and version, and IP address.
- Application inventory: the names of the application versions installed on your device, not their contents.
- For personally owned Windows devices, only the names of the Stanford ("managed") apps that Stanford deploys; your personal apps are not listed.
- Cellular data: SIM identifiers and phone number
For the complete and official list, see Data collection in Intune on Microsoft Learn.
Note: iOS and iPadOS devices are not enrolled in Intune at Stanford; Apple devices are managed with Jamf.
What we configure
Stanford applies a standard set of configuration policies and profiles to enrolled devices to keep them secure and consistent with the Minimum Security Standards.
On Windows, these cover settings such as event logging and account auditing, biometric sign-in, and BitLocker disk encryption with recovery keys escrowed to Microsoft Entra ID. On Android, they connect devices to the Stanford Wi-Fi network and keep Stanford data separated from personal data through the work profile. Applying these settings does not give Stanford access to the contents of your files.
For configurations and what each one does, see the dedicated page for your platform: Windows [Configuration Policies (Windows)] or Android [Configuration Profiles (Android)].
What we can do
What a management system could do in theory is broad, so this section focuses on what Stanford actually does. Day to day, the service uses a small set of remote actions:
- Sync a device to refresh its policies and inventory
- Remotely lock a device
- Reset the work-profile passcode (Android)
- Retire a device (remove university data): removes Stanford accounts, apps, and the work profile without touching personal data
- Wipe (factory reset) a device, for example, if it is lost or stolen
- Restart a university-owned Windows device
- Retrieve BitLocker recovery keys to help you recover your own encrypted data (Windows)
- Update system software
- Update application software
- Collect diagnostic logs for troubleshooting (Windows); this gathers system logs, not personal files
For the extent and limits of what Intune is capable of, see Microsoft's documentation on remote device actions.
How do you know any of this is happening?
Windows computers
On the computer itself:
- Settings > Accounts > Access work or school > select your Stanford account > Info: shows the areas managed by Stanford and the most recent sync
- Company Portal app: shows your device's status and what is managed
In the Microsoft Intune admin center (service administrators):
- Device record > Device configuration: per-policy assignment and status
- Device record > Device actions status: pending, failed, and completed actions
- Tenant administration > Audit logs: a record of actions administrators take
Android mobile devices
On the device itself:
- Work profile apps appear with a briefcase badge
- Settings > Security & privacy > Device admin apps (path varies by manufacturer and Android version)
- Company Portal or Microsoft Intune app: shows what is managed and your compliance status
Questions?
If you have questions, suggestions, or feedback, please submit a Help request.
