August 6, 2026
Your Baby’s Not Ugly. It Could Just Be Smarter.
The old lady who swallowed a fly
There's an old nursery rhyme about a woman who swallows a fly. To catch the fly, she swallows a spider. To catch the spider, she swallows a bird. Then a cat. Then a dog. Eventually she swallows a horse. She dies, of course.
It's an escalating joke for kids, but it's also the exact shape of enterprise endpoint security over the last decade.
Someone needed to manage corporate data on mobile devices, so they deployed MDM. MDM couldn't see inside apps, so they added MAM. MAM didn't catch device-level compromise, so they layered in MTD. None of that stopped a legitimate, enrolled, "healthy" device from being the wrong place for sensitive data to sit, so Conditional Access came in to referee all of it: location, device state, risk score, sign-in behavior, in real time, for every app, every user, every session.
Each layer solved a real problem. Each layer also created a new gap that needed the next layer. Now you've got a security architecture built out of forty-plus Conditional Access policies, three overlapping agents on every device, and a full-time function whose job is just keeping the stack from contradicting itself.
Nobody set out to build the horse. It just happened, one reasonable fly at a time.
We're not here to tell you your baby is ugly
If you're the person who built that stack, this isn't an intervention. Conditional Access, done well, is genuinely good work. It's granular, it's adaptive, it's saved your organization from real incidents. The instinct that built it (don't trust a signal in isolation, layer your defenses) was the right instinct.
The problem was never the policies. The problem is what the policies are compensating for: data sitting on the endpoint in the first place.
Every one of those layers (MDM's device compliance checks, MAM's app-wrapping, MTD's on-device threat scoring, Conditional Access's location and risk rules) exists because there's something on that phone or laptop worth protecting. Take the data off the device, and a whole category of those rules stops having a job to do. Not because you turned off security. Because you removed the thing the security was defending.
Start with a number, not a philosophy
Before any conversation about architecture, there's a diagnostic question worth answering: how many of your Conditional Access policies exist solely to manage data at rest on the endpoint?
Not your total policy count. That number includes plenty of policies doing legitimate, permanent work (MFA enforcement, guest access, admin protections). The number that matters is the subset that exists only because sensitive data physically lives on a device you don't fully control. Geo-fencing rules written because a smartphone might leave the country with cached attachments on it. Compliant-device requirements gating access to data that, once synced, is on that device for good. App protection policies trying to prevent copy-paste, screenshot, and local caching of things that should never have been cacheable in the first place.
Organizations running policy audits (through Entra's own Conditional Access insights workbook, or community tools like Jon Hope's open-source CA Policy Analyzer, which runs roughly fifty automated checks against a live policy set) are often surprised by how much of their ruleset falls into that bucket. Fifteen policies. Twenty. A third of the total, sometimes more.
That number is your target. Not because those policies are bad, but because they're the ones that can disappear entirely (not get simplified, disappear) the moment the data they're protecting is no longer sitting on the device.
The olive branch: keep what you built, shrink what you need it for
This is the actual pitch, and it's a narrower one than "replace Intune":
Keep Conditional Access. Keep your identity fabric. Keep Intune managing the devices and apps you're not ready to touch. Move your highest-risk workflows (the ones driving that subset of endpoint-focused policies) into a zero-data-on-device environment instead. With Hypori, nothing renders or caches locally; the device receives a pixel stream, not a copy of the data. Screenshots, clipboard exfiltration, local storage, offline extraction: the attack surface those policies were written to catch simply isn't there anymore, because there's no data on the endpoint to catch it from.
The policies that existed to protect that data can be scoped down or retired, one at a time, as confidence builds. Nobody has to declare Conditional Access a failure. Nobody has to migrate off Intune on day one, or ever, if they don't want to. The stack gets smaller because its job got smaller, not because someone ripped it out from under you.
That's the difference between "your baby is ugly" and "your baby could be smarter." You're not being told the thing you built was wrong. You're being shown that the hardest 20% of what it's doing doesn't need to be done anymore.
What smaller actually looks like
Fewer endpoint-driven policies means fewer conflicting rules to reason about when something breaks. Fewer exceptions means fewer "why was I blocked" helpdesk tickets. Fewer policies overall means your identity team spends less time on maintenance and more time on the parts of Conditional Access that were never about compensating for on-device data, the parts that were good ideas all along.
You don't have to swallow the horse. You can just stop needing one.
Recent articles
July 30, 2026
The Silicon Squeeze: Why Rising Memory Costs Are About to Change How You Buy Devices
Memory prices are surging, driven by AI's appetite for high-bandwidth DRAM, and it's already reshaping device pricing and specs across the industry.
Security
July 24, 2026
The Stern Report: FIPS-Validated Cryptography
FIPS validated does not mean one thing. See why Hypori's narrow cryptographic claim differs from Intune MAM's borrowed, older-standard FIPS 140-2 certification.
July 23, 2026
What Real Secure Messaging Looks Like and Why Your Organization Needs It
Enterprise messaging tools are a growing attack surface. Encryption moves the problem to the endpoint — it doesn't solve it. Virtual mobile infrastructure keeps organizational data inside a controlled environment, off the device entirely, with no residue when the session ends.
