Free web appCompliance mapping

Compliance mapping

Map your exported Intune settings to compliance frameworks in the web app.

When an auditor, a cyber insurer or a customer questionnaire asks you to prove that your devices enforce encryption, screen lock or patching, the answer is already in your Intune configuration. The Compliance Evidence view in the web app maps that configuration to a framework and shows, requirement by requirement, which policies, settings, values and assignments support it. You can then download the result as a PDF report.

It uses the same data you already collected for your documentation. Nothing extra is read and nothing is stored on our servers.

Evidence, not a certificate

The report states the technical evidence found in your Intune tenant. It never claims you are compliant, because only your auditor can decide that. Requirements that Intune configuration cannot prove, such as organizational or governance requirements, stay marked for manual assessment.

Supported frameworks

The web app supports these frameworks:

  • ASD Essential Eight, with target Maturity Levels 1, 2 and 3
  • ISO/IEC 27001
  • SOC 2
  • HIPAA Security Rule
  • NIST SP 800-53
  • NIST CSF 2.0
  • BSI IT-Grundschutz (the report is in German)
  • Def Stan 05-138, with the Cyber Risk Profile levels at which each control applies
  • Cyber Essentials
  • NIST SP 800-171 Rev. 2 (select this one for CMMC 2.0 Level 2)
  • NIST SP 800-171 Rev. 3

The desktop app adds the NIS2 Directive, a one-page management report with month-over-month change, and the option to import your own CIS crosswalk for ISO/IEC 27001 and NIS2.

See a sample first

Every framework has a free sample report generated from the fictional tenant Contoso Ltd. It is the quickest way to see what your auditor will receive. Browse them on the sample reports page.

Review evidence for a framework

Load your configuration

Sign in and let the collection finish. See Get started with the web app. If you want checks for MFA and access requirements, turn on Conditional Access in Settings first.

Open Compliance Evidence

Select Compliance Evidence in the sidebar. You see Choose a compliance framework with a tile for each framework. Select one.

To switch later, open the framework menu at the top and select another one, or Show all frameworks.

Set the scope

Under Platforms in scope, tick the platforms this assessment covers: Windows, macOS, iOS / iPadOS, Android and Tenant. Requirements on platforms you leave out are shown as Outside selected scope.

Some frameworks have one more choice:

  • ASD Essential Eight: choose the Essential Eight target maturity level. The default is Level 1. The tool shows evidence against the target you choose. It does not calculate an achieved maturity level.
  • Def Stan 05-138: choose the Def Stan Cyber Risk Profile level, or leave All levels (scope not selected).

Read the results

Three summary cards count the individual setting checks: Matches expected value, Different value and Missing. These count setting comparisons, not passed requirements.

Below them, each requirement of the framework is listed with a status. Expand a requirement to see the checks behind it: the policy, the setting, the expected value, the actual value and the assignment.

What the statuses mean

StatusMeaning
Configuration evidenceA recognized setting is configured with the value that enforces the requirement, on an assigned policy.
Partial configuration evidenceSome of the required settings are in place, or the evidence only supports the requirement.
Mixed policy evidencePolicies disagree. For example, one enforces BitLocker and another explicitly disables it. Counter-evidence is reported as a risk, never as coverage.
No recognized configuration evidenceNo Intune setting that supports this requirement was found. The PDF report lists the settings that could provide it.
Not assessedThe requirement needs evidence that Intune configuration cannot provide, or the data needed was not collected.
Outside selected scopeThe requirement applies only to platforms or levels you did not select.

Unassigned policies are flagged instead of counted, and a policy that only mentions a topic is not treated as evidence.

Collection incomplete

If part of the collection failed, a notice says so. Checks that need the missing data are affected; all other checks still run. If Conditional Access was not collected, turn it on in Settings, complete sign-in or consent, and refresh.

Download the evidence

You have two downloads, both generated in your browser:

  • Download report (PDF) creates the full, requirement-level evidence report for the selected framework and scope. It is built as an audit deliverable, with a table of contents, a data-basis section that states which policies were assessed, an evidence register with references, key findings and gap guidance. The BSI IT-Grundschutz report is fully in German and includes fields for your manual assessment.
  • Download evidence record (JSON) saves the same assessment as structured data, for your GRC tool or audit trail.

You can also add a short compliance evidence section to your configuration document with the Include compliance evidence preview option. See Export your configuration.

Next steps

On this page