The summary.
COMPLIANCE COMBINED WITH CONDITIONAL ACCESS IS THE POINT
Access granted only from devices in a known good state is the capability worth building toward.
TEST EVERY POLICY ON A PILOT GROUP FIRST
A policy applied to everyone incorrectly affects everyone immediately.
ESCROW ENCRYPTION KEYS
Without it, an encrypted device that cannot be unlocked is unrecoverable.
Use update rings so a problematic update does not reach every device at once.
RESTRICTING LOCAL ADMINISTRATIVE RIGHTS PREVENTS A SUBSTANTIAL PROPORTION OF INCIDENTS
Provide a route to temporary elevation instead of leaving rights permanently.
APPLICATION PROTECTION WITHOUT DEVICE MANAGEMENT IS WHAT MAKES PERSONAL DEVICES WORKABLE
Selective wipe removes organisational data without touching the owner's content.
Tell users plainly what the organisation can and cannot see — the assumption otherwise is that everything is visible, and it blocks adoption.
EXCESSIVE RESTRICTION PRODUCES WORSE OUTCOMES THAN MODERATE RESTRICTION
People forward to personal mail and photograph screens instead.
WATCH FOR DEVICES NOT SEEN RECENTLY
It may mean lost, stolen, or held by someone who left.