I believe Intune would be required "to see" what a user is doing. I used it extensively at my old company, any company phone, tablet or laptop had it. It will show what the admin has access to though. It was used for remote administration around the device being lost. I don't believe anything in M365 has that level of control so not much to worry about using a corporate subscription on a personal device.
|