SOC2 Intune Endpoint Security Overhaul

Job ID: 40127746

Budget: $25 – $50 USD

I need to raise our overall security posture before a forthcoming SOC 2 audit and the fastest way there is to tighten every endpoint. Our fleet is an even split of MacBooks and Windows laptops, all licensed for Microsoft 365 Business Premium. Intune is switched on but only lightly configured—my goal is to make it the single source of truth for MDM, with full macOS support, rock-solid Windows policies, and seamless Defender integration.

Alongside the Microsoft stack we already use NinjaRMM for monitoring and HaloPSA for ticketing, so any solution has to fit neatly into that workflow. A background in an MSP environment will help you understand the operational pressure and documentation detail I expect.

Key outcomes I’m after:
• A SOC 2-aligned hardening baseline applied through Intune for both macOS and Windows
• Conditional Access, compliance, encryption, and patching policies that leave every device showing “Compliant” in the portal
• Clean integration with NinjaRMM/HaloPSA so alerts and tickets flow automatically
• Evidence-ready documentation and runbooks my internal team can follow

Acceptance is simple: every device enrolls smoothly, reports compliant, and the documentation packet maps each control directly to the SOC 2 criteria. Once that’s done, a brief hand-off session will close the project.