With the release of Microsoft Intune 1901 we finally got MDM security baseline, the first time Microsoft talked public about this was at Ignite 2018, everybody I have talked to since has been waiting for this feature, in the waiting time we have been using other security baseline like the one from NCSC.
When doing Windows management today we need to look at the security part of hardening Windows. MDM security baseline is build based on Windows Security baseline it is more and more important to remove local administrator rights and create a baseline for securing your Windows Desktop. You don’t need to follow the Microsoft Security baseline, but it is a great starting point, then you can add or remove settings so that your users can still do there work and you line of business applications are working as expected.

This baseline is built as a generic infrastructure that allows IT admins to eventually import other security baselines based on CIS, NIST, and other standards. Currently, it’s available for Windows and will eventually include iOS and Android.

After Intune service release 1901 Security Baseline is in public preview for all tenants – so there is no excuse not to start testing it.

start using intune securitybaseline - 00


How to configure Windows 10 Security baseline in Intune

  1. Click on Security Baseline (Preview)

start using intune securitybaseline - 01

  1. Click on MDM Security Baseline for October 2018 (This security baseline is for Windows 10 1809)

start using intune securitybaseline - 02

  1. Click Create profile

start using intune securitybaseline - 03

  1. Enter a Name : Windows MDM Security Baseline for October 2018
  2. Click to expand settings

start using intune securitybaseline - 04

Then you can go expand all the category and see if all the settings is as you want.
Many of the settings are also to be found in other Intune profiles but many are also ADMX based policy settings that are now in the GUI in the security baseline an example is Internet explorer

start using intune securitybaseline - 05a

There is other settings that are not configured that you maybe want to to use an example is in Windows Defender – if you are running 3 part. anti malware solution you may change some of the default configuration

start using intune securitybaseline - 05

If you are running Windows Defender you may to change Defender cloud block level from Not Configured

start using intune securitybaseline - 06

To Zero tolerance

start using intune securitybaseline - 07

When you have made your change so that the security baseline match your requirements you need to assign it.

  1. Click Policies created
  2. Click on the policy you just created

start using intune securitybaseline - 10

  1. Click Assignments
  2. Click Select groups to include and find your test group

start using intune securitybaseline - 11

How to monitor you security baseline

Like all other policies in Intune there is a overview when you have deploy a policy, in the security baseline case there is 4 state that a policy can be in:

  • Matches baseline
  • Does not match baseline
  • Misconfigured
  • Not applicable

start using intune securitybaseline - 20

On the device it self in Intune you got a new monitor area – Security baseline:

  1. Select the Security baseline
  2. Click Preview: MDM Security Baseline for October 2018

start using intune securitybaseline - 21

Then you can see all the settings name and you can expand them.
The easy way is to filter on the state so you are only looking for the settings that are not working as expected

start using intune securitybaseline - 22

Then you can expand the setting name

  1. Find the settings name that you want to see
  2. Only look for the Misconfigured in this case

start using intune securitybaseline - 23

You can also look at it from the security baseline policy it self in the monitor section

Start using Intune SecurityBaseline - 30.png

When you are looking in the Per-setting status it is easy to sort the setting after the status:

In this case after conflict

first look intune security baseline - 24

In this case error

first look intune security baseline - 25

in this case not applicable

first look intune security baseline - 26

Then you can start changing you baseline or find the Intune profile where you have the setting configured.

At my first test on a AzureAD joined device with out any changes to the security baseline I was not able to login.

start using intune securitybaseline - 24


Happy testing 🙂

Read more:

Create a Windows 10 security baseline in Intune