Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all corporate-owned Windows 11 devices. The organization has specific compliance requirements that align with industry best practices for Windows security. The administrator wants to use a standardized, pre-configured set of security settings provided by Microsoft. Which Intune feature should the administrator use?
- ACustom configuration profile (OMA-URI)
- BSecurity baselines
- CDevice restrictions profile
- DPowerShell scripts
Show answer & explanationAnswer & explanation
Correct answer: B. Security baselines
Intune's Security Baselines are pre-configured groups of Windows settings recommended by Microsoft to meet common industry best practices for security, making them ideal for deploying standardized security configurations.
Why the other options are wrong
- A. Custom OMA-URI profiles are for unique settings not covered by templates, not for deploying a broad, standardized baseline.
- C. Device restrictions profiles offer some security settings but are not comprehensive pre-configured baselines.
- D. PowerShell scripts could apply settings but lack the centralized management and reporting of Intune's built-in baselines.
Intune Security Baselines
Pre-configured groups of Microsoft-recommended security settings that can be deployed to Windows devices to help meet industry best practices and compliance requirements.
- Developed by Microsoft security engineers.
- Includes settings for Windows, Defender, Edge, etc.
- Simplifies the deployment of comprehensive security configurations.
Memory trick: Security Baselines are Microsoft's 'pre-built fortress' for Windows.