Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A company is managing Windows 11 devices with Microsoft Intune. They want to ensure that all devices have a specific set of security configurations enforced that align with industry best practices, such as disabling SMBv1 and enabling firewall rules, without having to manually configure each setting individually. Which Intune feature is designed for this purpose?
- AEndpoint security > Antivirus policies
- BEndpoint security > Security baselines
- CConfiguration profiles > Device restrictions
- DDevices > Windows > Update rings
Show answer & explanationAnswer & explanation
Correct answer: B. Endpoint security > Security baselines
Security baselines in Intune provide pre-configured sets of security settings recommended by Microsoft. They allow administrators to quickly deploy a comprehensive security posture that aligns with industry best practices without manually configuring each individual setting.
Why the other options are wrong
- A. Antivirus policies focus specifically on antivirus and anti-malware settings, not a broad range of security configurations like SMBv1 or firewall rules.
- C. Device restrictions are used for general device settings and limitations, but not for comprehensive, pre-configured security best practices across multiple security domains.
- D. Update rings manage the deployment of Windows updates, not the security configuration of devices.
Intune Security Baselines
Pre-configured groups of settings recommended by Microsoft for establishing a robust security posture on managed devices, aligning with industry best practices.
- Bundles multiple security configurations into a single deployable unit.
- Based on Microsoft's security guidance (e.g., CIS benchmarks, DISA STIG).
- Simplifies the deployment of comprehensive security settings.
Memory trick: Baselines Secure: Comprehensive, Pre-set, and Best Practices.