Evidence for Secure Windows Devices (no MDM Solution)

Last updated: April 21, 2026

Mycroft's Mobile Device Management (MDM) solution acts as your "silent auditor," automatically verifying that devices meet encryption, password, and update standards.

However, when employees use personal devices (BYOD) without MDM enrolment, the burden of proof shifts.

To maintain security compliance (such as SOC2 or HIPAA), employees must provide manual snapshots of system settings to verify that these "unmanaged" devices aren't creating vulnerabilities.

Missing evidence from an employee may result in a Request for Evidence/Samples, or potentially an exception on an audit report if not provided on time.


Windows - Evidence for Protected Device

  1. Go to  Settings on your Windows Device.

  2. Select Accounts Sign-in options

  3. Show you have a secure way of logging in ie) password enabled, fingerprint enabled, etc.

  4. Ensure your name is visible and take a screenshot

Screenshot 2026-04-21 at 8.41.40 AM.pngScreenshot 2026-04-21 at 9.04.09 AM.png

Windows - Evidence for Hardware Encryption

In the Settings app  on your Windows device:

  1. Select Privacy security Device encryption

  2. Turn Device Encryption On

  3. Take a screenshot ensuring your name is visible

Screenshot 2026-04-21 at 8.46.12 AM.pngimage (58).png

Windows - Built-In Anti-Virus Evidence

  1. Open the Windows Security app (search "Windows Security" in the start menu).

  2. Click on Virus & threat protection.

  3. Ensure Real-time protection is toggled "On".

  4. Check under Manage providers to confirm Microsoft Defender is active.

  5. Send a screenshot ensuring your name is visible

Screenshot 2026-04-21 at 8.54.59 AM.png

Why Manual Collection is Necessary

While we strongly recommend enrolling in our corporate MDM for automated reporting, we recognize that privacy concerns or device ownership often lead to personal hardware remaining unmanaged. In these cases, manual evidence collection is the only way to:

  • Validate Encryption: Ensure BitLocker (Windows) is active.

  • Confirm Patching: Verify the OS version is up to date against known exploits.

  • Verify Access Control: Document that screen locks and complex passwords are enforced.

Visit our article for Mac Devices: Evidence for Secure Mac Devices (no MDM Solution)