Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have a specific set of security configurations applied consistently. These configurations are based on Microsoft's recommended security baselines for Windows 11. Which Intune feature should the administrator use to deploy these configurations?
- ASecurity baselines
- BCustom configuration profiles
- CAdministrative Templates
- DDevice restrictions
Show answer & explanationAnswer & explanation
Correct answer: A. Security baselines
Intune's 'Security baselines' are pre-configured groups of Microsoft-recommended security settings designed to help secure Windows devices. They provide a quick and effective way to deploy a comprehensive set of security configurations consistently across devices.
Why the other options are wrong
- B. Custom configuration profiles are for settings not available in templates, requiring manual OMA-URI input, which is more complex than needed for recommended baselines.
- C. Administrative Templates deploy ADMX-backed settings, which can be part of a baseline, but baselines offer a curated, comprehensive set of security settings directly.
- D. Device restrictions are a specific type of configuration profile for common device limitations, not a comprehensive set of security best practices as a whole.
Intune Security Baselines
Pre-configured groups of Microsoft-recommended security settings in Intune, designed to quickly and consistently apply security best practices to Windows devices.
- Microsoft-recommended settings.
- Comprehensive security configuration.
- Ensures consistent security posture.
- Regularly updated by Microsoft.
Memory trick: Baselines are the bedrock of consistent security.