Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all corporate-owned Windows 11 devices. The baseline must align with industry best practices for security and should be easily updated as new recommendations become available. Which Intune feature should be used?

  1. AEndpoint security baselines.
  2. BDevice compliance policies.
  3. CDevice configuration profiles with custom OMA-URI settings.
  4. DPowerShell scripts deployed via Intune.
Show answer & explanation

Correct answer: A. Endpoint security baselines.

Endpoint security baselines in Intune are pre-configured groups of settings based on industry best practices (e.g., CIS, Microsoft Security). They are designed for easy deployment and regular updates from Microsoft, making them ideal for this scenario.

Why the other options are wrong

  • B. Compliance policies define conditions for compliance, not the actual configuration of security settings.
  • C. Custom OMA-URI settings are for specific, granular configurations, not broad baselines that are easily updated.
  • D. PowerShell scripts can configure settings, but managing a full security baseline this way is cumbersome and doesn't offer easy updates.

Intune Security Baselines

Microsoft Intune security baselines are pre-configured groups of Windows security settings that are recommended by Microsoft security teams. They help secure devices by deploying industry best practices and are updated regularly.

  • Based on Microsoft/industry best practices (e.g., CIS).
  • Easily deployable and updateable.
  • Simplifies securing Windows devices without manual configuration of hundreds of settings.

Memory trick: Baselines: The 'Easy Button' for Best Practice Security.

More Manage devices and apps (55-60%) questions