The company should have known better than to trust their IT infrastructure to Microslop. This is their own fault.
What alternative to Intune and, hell, the entire Office 365 suite that it is in, do you have?
Gsuite + Slack I guess. lmao. As if that is better.
Looking forward to your reply.
My 95% bet is that the attacker just gained access to an account with suitable privileges and then went on to use existing automation. The fact that it’s intune is largely irrelevant - I’m not aware of any safeguards that any provider would implemen.
So the options here are MDM or no MDM and that’s a hard choice. No MDM means that you have to trust all people to get things as basic as FDE or a sane password policy right. No option to wipe or lock lost devices. No option to unlock devices where people forgot their password. Using an MDM means having a privileged attack vector into all machines.