A laptop or phone is lost or stolen
Usually a question you can close in minutes if the device was managed and encrypted, and a notification decision if it was not. The hour is spent cutting the device off, proving what protection it had, and writing that proof down before anybody asks for it.
- 01
Revoke the user's sessions and cut the device off
by 10 minexpiresRevoke sign-in sessions, disable the device object in the identity platform, and remove it from certificate-based, Wi-Fi and VPN access. The user can carry on working from another device.
- 02
Record the device's protection state, with a timestamp
by 20 minexpiresEncryption status and whether the recovery key is escrowed (BitLocker, FileVault), last check-in, OS version, screen lock policy and compliance state. Export it or screenshot it. This is the evidence the notification decision rests on.
- 03
Then lock or wipe, and note whether it arrived
by 30 minLock first if there is a realistic chance of getting it back, wipe if not. A device that has not checked in since it went missing has not received the command, so record the command and watch for its delivery.
- 04
Establish what was on it and what it could reach
by 50 minSynced mailboxes, offline files, cached credentials, saved browser passwords and any local data exports. For a phone, whether it was somebody's MFA device or received one-time codes.
- 05
Watch for use
by 60 minSign-ins from the device, or with the user's credentials from new places, over the following days. An attempt to use it is the strongest sign the theft was about the data rather than the hardware.