We allow employees to use personal iOS and Android phones in our Microsoft 365 environment. These devices can access Outlook and Teams and are registered with Microsoft Entra. An upcoming audit requires an inventory of mobile devices that are actually being used to access company resources, not just every device registered to a user. What's the best way to identify and verify those devices?
4 Answers
Also review the Entra audit and sign-in logs, along with Conditional Access reporting. Use a defined time window for the audit and document the filters you used—Teams and Outlook, iOS and Android, and successful sign-ins. That gives you a defensible distinction between devices that are merely registered and devices that have actually accessed company resources.
Use the Microsoft 365 usage reports for user-level activity, since they can distinguish mobile use from desktop use. For device-level detail, combine those results with Entra sign-in logs and, if needed, Exchange Online mobile-device data such as the output from Get-MobileDevice. The reports show activity, while the sign-in and Exchange data help identify the actual devices.
Start by exporting the users’ Entra-registered devices, filtering the device list by join type so you exclude fully joined and hybrid-joined devices. Then compare that list with Entra sign-in logs filtered for Teams and Outlook on iOS or Android. That cross-reference should give you a practical list of registered BYOD devices that have recently accessed those apps.
Be careful: registered devices and active devices aren’t necessarily the same thing. If Conditional Access doesn’t require a registered or managed device, users may be able to sign in from unmanaged phones that won’t appear in your inventory. In that case, sign-in logs are your best evidence of access, but you may only see the user, operating system, application, and sign-in details rather than a reliably discoverable device record.

For BYOD, mobile application management can be a better fit than requiring full device management. It protects company data inside Teams and Outlook without giving the organization control over the entire personal phone.