Skip to lesson
Exit
Fleet, MDM & Device Trust Deep Dive1 / 2

1 min lesson

Inventory and patch cadence as standing practice

Talk this through in your own words: "A fully remote engineer is terminated. Walk through what should happen to their device and access and the one failure mode you're most guarding against." Finish with the next move.

Step 1 of 2

Inventory and patch cadence as standing practicethe unglamorous half of the job

  • Inventory as source of truth. Live counts, current assignment, compliance state and lifecycle stage per device - reconciled against MDM, not hand-maintained.
  • Patch and vulnerability cadence. A regular rhythm for OS and critical-app updates across all four platforms, with deferral windows but a hard backstop so nothing rots unpatched.
  • Audit-ready reporting. Encryption coverage, patch compliance and assignment reports that regenerate on demand for SOC 2 / ISO 27001 evidence.
  • Reclaim and reuse. Recovered hardware re-enters the pool clean, so spend tracks headcount instead of drifting upward.
Watch out

The classic offboarding gap is the unreturned remote-worker laptop. If your only offboarding plan assumes the device comes back to a desk, a remote leaver leaves a live, unwiped machine in the wild. The answer is remote lock/wipe tied to the leaver event plus a documented recovery-or-remote-destroy path - and saying so unprompted shows you've run real offboarding, not just read the runbook.

Verify it actually happened

"Offboarded" is a claim until you confirm it. A mature process verifies each leaver: account disabled, sessions killed, SaaS deprovisioned, device locked/wiped and inventory updated - ideally as an automated check that flags any half-finished offboarding. An access review that surfaces a terminated employee with a still-active token is the exact finding a SOC 2 auditor lives for.