Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium

An organization uses Microsoft Intune to manage its Windows 11 devices. A new security baseline has been released by Microsoft, and the security team wants to apply it to all corporate devices. Which Intune feature should the administrator use to quickly deploy and manage these recommended security settings?

  1. ADevice compliance policies
  2. BSecurity baselines
  3. CCustom OMA-URI settings
  4. DConfiguration policies
Show answer & explanation

Correct answer: B. Security baselines

Security baselines in Intune are pre-configured groups of Windows settings that help secure devices according to best practices recommended by Microsoft and security teams, making them ideal for deploying new security standards.

Why the other options are wrong

  • A. Device compliance policies define requirements but don't deploy the settings themselves.
  • C. Custom OMA-URI settings are for deploying settings not available in Intune's native templates and are not for quick deployment of a whole baseline.
  • D. Configuration policies offer granular control but require manual configuration of each setting.

Intune Security Baselines

Pre-configured groups of settings for Windows devices that align with security best practices recommended by Microsoft, designed for easy deployment.

  • Simplifies deployment of security configurations.
  • Based on Microsoft's security recommendations.
  • Can be customized and assigned to groups.

Memory trick: Baselines are the bedrock of security, pre-built for stability.

More Manage identity and compliance (10-15%) questions