A laptop or phone is lost or stolen

Usually a question you can close in minutes if the device was managed and encrypted, and a notification decision if it was not. The hour is spent cutting the device off, proving what protection it had, and writing that proof down before anybody asks for it.

Trigger. A user reports a missing laptop, phone or tablet that could reach company mail, files or systems.

The first 60 minutes2 of 5 expire
030 min60
  1. 01

    Revoke the user's sessions and cut the device off

    by 10 minexpires

    Revoke sign-in sessions, disable the device object in the identity platform, and remove it from certificate-based, Wi-Fi and VPN access. The user can carry on working from another device.

  2. 02

    Record the device's protection state, with a timestamp

    by 20 minexpires

    Encryption status and whether the recovery key is escrowed (BitLocker, FileVault), last check-in, OS version, screen lock policy and compliance state. Export it or screenshot it. This is the evidence the notification decision rests on.

  3. 03

    Then lock or wipe, and note whether it arrived

    by 30 min

    Lock first if there is a realistic chance of getting it back, wipe if not. A device that has not checked in since it went missing has not received the command, so record the command and watch for its delivery.

  4. 04

    Establish what was on it and what it could reach

    by 50 min

    Synced mailboxes, offline files, cached credentials, saved browser passwords and any local data exports. For a phone, whether it was somebody's MFA device or received one-time codes.

  5. 05

    Watch for use

    by 60 min

    Sign-ins from the device, or with the user's credentials from new places, over the following days. An attempt to use it is the strongest sign the theft was about the data rather than the hardware.