What can Intune or MDM actually do to your computer?

If I accidentally clicked ‘Allow my organization to manage my device,’ what does that actually mean? Can they see everything on my computer? Does it give them admin control? I also noticed that my BitLocker key is saved to their account. Does that mean they had access to my device at some point? I’m feeling pretty anxious about this and would love to understand what they can and cannot do. Thanks in advance!

Short version: they can do almost anything.

For more details, check this: Run remote actions on devices with Microsoft Intune | Microsoft Learn

LogicLuminary said:
Short version: they can do almost anything.

For more details, check this: Run remote actions on devices with Microsoft Intune | Microsoft Learn

Yep, they have a lot of control. Always assume the worst when it comes to stuff like this.

LogicLuminary said:
Short version: they can do almost anything.

For more details, check this: Run remote actions on devices with Microsoft Intune | Microsoft Learn

So, for example, if this was a school account I added for online classes during COVID, does that mean they could access my files or personal data?

@oliviamartin
Yes, it’s possible.

EricJohnson3 said:
@oliviamartin
Yes, it’s possible.

You’ve just given me a mini heart attack!

oliviamartin said:

EricJohnson3 said:
@oliviamartin
Yes, it’s possible.

You’ve just given me a mini heart attack!

If it’s your personal device, they would need to admit to invading your privacy if they did something like that. You might even have grounds for legal action.

At work, we’ve seen cases where they could do a full forensic copy of your system. That means every file, every program, and even websites you visited could be visible to them.

How much they monitor depends on the organization and local laws. I’ve dealt with everything from no monitoring at all to handing over forensic evidence to law enforcement.

@NexusShade4
In my case, it was a school account for online learning during COVID. To use school-approved Teams, I had to add the account and might have clicked ‘Allow my organization to manage my device.’ Could they really have accessed all my personal files or data?

@oliviamartin
If you gave them permission to manage your device, they could’ve set policies like restricting USB drives or even locking certain settings. They could monitor a lot, depending on how they configured it.

If you ever see an option to allow only specific applications, always choose that instead of full management.

@Campbell
This was about three years ago, and I can’t remember what I clicked. But could a middle school administrator actually monitor everything on my device? The account hasn’t been used since COVID, and it might even be deleted now, but I’m anxious about what could’ve happened back then. Also, I noticed the BitLocker key for my laptops is saved under that account. Does that mean they had control at some point, or is just logging into Teams enough for the key to be saved?