Endpoint protection and patching

What percentage of endpoints have EDR deployed?

A percentage looks like a fact. It is actually two numbers, and the one nobody states is where the exposure lives.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier wants a coverage figure for endpoint detection and response across the estate. The implicit question is what you counted. Enrolled devices, or every device that can reach corporate data? Servers, or only workstations? Contractors, or only employees?

Why it is underwritten

Attackers do not distribute across your fleet evenly. They arrive at whatever is reachable and weakest, which is disproportionately the uncovered remainder. A carrier with claims experience knows that the gap between ninety-five and a hundred percent contains most of the risk, so the follow-up questions are about the missing devices rather than about the covered ones.

Where the answer lives in Microsoft 365, Entra ID, and Azure

The numerator comes from your endpoint console. The denominator is the harder number and it benefits from sources the console does not have.

PlatformWhere the setting livesWhat has to be true
Entra IDRegistered and joined device inventoryA directory-side device count to compare against the endpoint console, since the two rarely agree
Microsoft 365Intune enrolled device count and compliance stateEnrolment coverage, and the population of devices that access corporate data without being enrolled
AzureVirtual machine inventory across subscriptions, and endpoint protection extension stateThe server-side denominator, including machines outside the standard deployment pipeline
Endpoint consoleAgent count, health state, and unmanaged device discoveryDevices seen on the network without an agent, which is the most useful discovery output for this answer
Asset inventoryWhatever authoritative asset list existsA reconciliation between inventory, directory, and console. Attested
Reconcile three sources, not one

The endpoint console, the directory, and the asset inventory each know about a different set of machines. The union is your real denominator, and the differences between the three lists are the most interesting security finding most organisations can produce in an afternoon.

What a defensible yes requires

  • The figure states both numerator and denominator, and where the denominator came from.
  • Servers, cloud workloads, and non-Windows devices are included or explicitly excluded with a reason.
  • Unmanaged device discovery has been run, so the denominator is not simply the console inventory.
  • The uncovered remainder is identified by name rather than left as a percentage.
  • There is a dated plan for the remainder, which is what turns a gap into a trajectory.

How this answer goes wrong

Organisations report the console's own coverage percentage, which is calculated against devices the console knows about and is therefore close to a hundred by construction. It is not a wrong number; it answers a different question from the one asked. The moment an incident starts on a device outside that inventory, the difference becomes the whole story.

Frequently asked

What figure is good enough?

Carriers look for the high nineties and react most to how the number was derived. An explained ninety-six with named exceptions beats an unexplained hundred.

Should servers be in the same number?

Give both. Workstation and server coverage often differ substantially, and the aggregate hides the difference that matters.

What about personal devices?

If they reach corporate data they belong in the analysis, usually handled through application protection rather than an agent. Explain the control rather than excluding the population silently.

How often should we recount?

Before every renewal at minimum, and ideally continuously. Coverage decays as devices are added, and it decays fastest during growth and after acquisitions.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture