After each platform went live, I wrote a post-implementation assessment for my team: a terms of reference setting the scope, then a printed checklist where every check had an owner, evidence and a manager's signature. I did this for Defender, SentinelOne, Darktrace and Zscaler.
| # | Area | What good looks like | How verified | Owner | Evidence | Result | Remarks |
|---|---|---|---|---|---|---|---|
| 1 | Onboarding coverage | In-scope devices onboarded, compared with the asset inventory | Inventory export vs Defender device list | Endpoint team | EV-01 | ||
| 2 | Sensor health | Onboarded devices report an active sensor and recent telemetry | Device health report, filtered for inactive or impaired | Endpoint team | EV-02 | ||
| 3 | Real-time and cloud protection | Enabled everywhere and not overridable by users | Intune antivirus policy plus device sample | Endpoint team | EV-03 | ||
| 4 | Tamper protection | Enabled across the tenant | Portal setting plus device sample | Endpoint team | EV-04 | ||
| 5 | Attack surface reduction | ASR rules in block or audit mode as approved | Intune ASR policy vs approved rule list | Endpoint team | EV-05 | ||
| 6 | Firewall policy | Windows Firewall profiles enforced | Intune policy assignment report | Endpoint team | EV-06 | ||
| 7 | Device compliance | Compliance policy uses the Defender device risk level | Intune compliance policy settings | Intune admin | EV-07 | ||
| 8 | Conditional access | Non-compliant devices blocked from corporate apps | Entra conditional access policy | Identity team | EV-08 | ||
| 9 | Alerts reach the SIEM | A test detection on a lab device appears in the SIEM | Test alert plus SIEM search | SOC | EV-09 | ||
| 10 | Automated investigation | Automation level set as approved | Portal settings | SOC | EV-10 | ||
| 11 | Role-based access | Portal roles follow least privilege | Role assignment export review | Security admin | EV-11 | ||
| 12 | Vulnerability view | Secure Score and vulnerability findings reviewed, owners assigned | Score export and action list | Vulnerability team | EV-12 |