{"id":50454027,"url":"https://github.com/mizcausevic-dev/intune-device-compliance-ops","last_synced_at":"2026-06-01T01:05:34.704Z","repository":{"id":360560344,"uuid":"1250668421","full_name":"mizcausevic-dev/intune-device-compliance-ops","owner":"mizcausevic-dev","description":"Operator control plane for Microsoft Intune device compliance, stale sync risk, BYOD posture, and endpoint remediation readiness.","archived":false,"fork":false,"pushed_at":"2026-05-26T23:30:20.000Z","size":411,"stargazers_count":0,"open_issues_count":7,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-27T00:20:29.496Z","etag":null,"topics":["azure","byod","device-compliance","endpoint-compliance","intune","mdm","microsoft-365","platform-engineering","security-operations","typescript"],"latest_commit_sha":null,"homepage":"https://intune.kineticgain.com/","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mizcausevic-dev.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-26T21:24:20.000Z","updated_at":"2026-05-26T23:30:23.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/mizcausevic-dev/intune-device-compliance-ops","commit_stats":null,"previous_names":["mizcausevic-dev/intune-device-compliance-ops"],"tags_count":2,"template":false,"template_full_name":null,"purl":"pkg:github/mizcausevic-dev/intune-device-compliance-ops","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fintune-device-compliance-ops","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fintune-device-compliance-ops/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fintune-device-compliance-ops/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fintune-device-compliance-ops/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mizcausevic-dev","download_url":"https://codeload.github.com/mizcausevic-dev/intune-device-compliance-ops/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fintune-device-compliance-ops/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33755379,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-31T02:00:06.040Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["azure","byod","device-compliance","endpoint-compliance","intune","mdm","microsoft-365","platform-engineering","security-operations","typescript"],"created_at":"2026-06-01T01:05:34.605Z","updated_at":"2026-06-01T01:05:34.694Z","avatar_url":"https://github.com/mizcausevic-dev.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Intune Device Compliance Ops\n\n[![CI](https://github.com/mizcausevic-dev/intune-device-compliance-ops/actions/workflows/ci.yml/badge.svg)](https://github.com/mizcausevic-dev/intune-device-compliance-ops/actions/workflows/ci.yml)\n[![License: AGPL v3](https://img.shields.io/badge/License-AGPL_v3-blue.svg)](./LICENSE)\n[![Deploy](https://github.com/mizcausevic-dev/intune-device-compliance-ops/actions/workflows/pages.yml/badge.svg)](https://github.com/mizcausevic-dev/intune-device-compliance-ops/actions/workflows/pages.yml)\n\nOperator control plane for Microsoft Intune device compliance, stale sync risk, BYOD posture, encryption drift, and remediation readiness across endpoint fleets.\n\n## Why this exists\n\n- Endpoint operations teams need more than a raw `managedDevices` export when audits, rollout windows, and user-impacting compliance failures collide.\n- Intune operators need one surface that shows fleet risk, stale check-ins, jailbreak/root posture, missing encryption, and remediation sequencing.\n- Recruiters and buyers looking for `Azure / Microsoft 365 / Entra / Intune` proof should see a real endpoint-compliance dashboard, not a generic cloud keyword project.\n- Device compliance becomes more valuable when it is packaged as an operator system for security, platform, and IT operations teams.\n\n## Why this matters (KG Embedded tie-back)\n\nThis repo demonstrates the endpoint-compliance control-plane primitive for Microsoft tenant operations: fleet posture, stale device drift, encryption gaps, BYOD review, and remediation packets in one operator surface. Kinetic Gain Embedded extends this pattern into productized in-app dashboards where compliance, security, and device signals need to stay visible without exposing raw admin backends or tenant data. See [kineticgain.com/embedded](https://kineticgain.com/embedded).\n\n## What it shows\n\n- fleet-lane visibility for active Intune device cohorts and ownership posture\n- compliance-risk detection for noncompliant, jailbroken, unencrypted, stale, and orphaned devices\n- remediation packets for executive laptops, BYOD Android, shared kiosks, and stale macOS devices\n- offline-safe analysis of captured Microsoft Graph `deviceManagement/managedDevices` exports\n- recruiter-facing Microsoft endpoint operations proof that composes with Entra governance\n\n## Routes\n\n- `/`\n- `/fleet-lane`\n- `/compliance-risks`\n- `/remediation-posture`\n- `/verification`\n- `/docs`\n\n## API\n\n- `/api/dashboard/summary`\n- `/api/fleet-lane`\n- `/api/compliance-risks`\n- `/api/remediation-posture`\n- `/api/verification`\n- `/api/sample`\n\n## Screenshots\n\n![Overview](./screenshots/01-overview-proof.png)\n![Fleet lane](./screenshots/02-fleet-lane-proof.png)\n![Compliance risks](./screenshots/03-compliance-risks-proof.png)\n![Remediation posture](./screenshots/04-remediation-posture-proof.png)\n\n## CLI\n\n```powershell\nnpx intune-device-compliance \u003cexport.json\u003e `\n    --format json|markdown|summary `\n    --now 2026-05-27T08:00:00Z `\n    --stale-after-days 14 `\n    --fail-on-high `\n    --out report.md\n```\n\nInput is any of:\n- a single `managedDevice` object\n- an array of devices\n- a Microsoft Graph collection envelope: `{ \"value\": [ ... ] }`\n\n## Local Development\n\n```powershell\ncd intune-device-compliance-ops\nnpm install\nnpm run dev\n```\n\nOpen:\n- [http://127.0.0.1:5512/](http://127.0.0.1:5512/)\n- [http://127.0.0.1:5512/fleet-lane](http://127.0.0.1:5512/fleet-lane)\n- [http://127.0.0.1:5512/compliance-risks](http://127.0.0.1:5512/compliance-risks)\n- [http://127.0.0.1:5512/remediation-posture](http://127.0.0.1:5512/remediation-posture)\n- [http://127.0.0.1:5512/verification](http://127.0.0.1:5512/verification)\n\n## Validation\n\n- `npm run lint`\n- `npm run typecheck`\n- `npm run coverage`\n- `npm run build`\n- `npm run demo`\n- `npm run smoke`\n- `npm run prerender`\n- `npm run render:assets`\n\n## Production status\n\n| Aspect | Status |\n|--------|--------|\n| CI | Node 20 + 22 matrix — lint · typecheck · coverage · build · demo · smoke · `npm audit` |\n| License | [AGPL-3.0-or-later](./LICENSE) |\n| Deploy | Static prerender -\u003e **https://intune.kineticgain.com/** |\n| Data posture | Synthetic sample data only; no tenant credentials or live Graph tokens |\n| Suite | Part of the [Kinetic Gain Protocol Suite](https://suite.kineticgain.com/) operator portfolio · apex: [kineticgain.com](https://kineticgain.com) |\n\n## Docs\n\n- [Architecture](./docs/architecture.md)\n- [Origin](./docs/ORIGIN.md)\n- [Kinetic Gain Embedded tie-back](./docs/KINETIC_GAIN_EMBEDDED.md)\n- [Changelog](./CHANGELOG.md)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fintune-device-compliance-ops","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmizcausevic-dev%2Fintune-device-compliance-ops","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fintune-device-compliance-ops/lists"}