Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all corporate-owned Windows 11 devices. The organization has specific compliance requirements that align with industry best practices for Windows security. The administrator wants to use a standardized, pre-configured set of security settings provided by Microsoft. Which Intune feature should the administrator use?

  1. ACustom configuration profile (OMA-URI)
  2. BSecurity baselines
  3. CDevice restrictions profile
  4. DPowerShell scripts
Show answer & explanation

Correct answer: B. Security baselines

Intune's Security Baselines are pre-configured groups of Windows settings recommended by Microsoft to meet common industry best practices for security, making them ideal for deploying standardized security configurations.

Why the other options are wrong

  • A. Custom OMA-URI profiles are for unique settings not covered by templates, not for deploying a broad, standardized baseline.
  • C. Device restrictions profiles offer some security settings but are not comprehensive pre-configured baselines.
  • D. PowerShell scripts could apply settings but lack the centralized management and reporting of Intune's built-in baselines.

Intune Security Baselines

Pre-configured groups of Microsoft-recommended security settings that can be deployed to Windows devices to help meet industry best practices and compliance requirements.

  • Developed by Microsoft security engineers.
  • Includes settings for Windows, Defender, Edge, etc.
  • Simplifies the deployment of comprehensive security configurations.

Memory trick: Security Baselines are Microsoft's 'pre-built fortress' for Windows.

More Manage devices and apps (55-60%) questions