Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have a specific set of security configurations applied consistently. These configurations are based on Microsoft's recommended security baselines for Windows 11. Which Intune feature should the administrator use to deploy these configurations?

  1. ASecurity baselines
  2. BCustom configuration profiles
  3. CAdministrative Templates
  4. DDevice restrictions
Show answer & explanation

Correct answer: A. Security baselines

Intune's 'Security baselines' are pre-configured groups of Microsoft-recommended security settings designed to help secure Windows devices. They provide a quick and effective way to deploy a comprehensive set of security configurations consistently across devices.

Why the other options are wrong

  • B. Custom configuration profiles are for settings not available in templates, requiring manual OMA-URI input, which is more complex than needed for recommended baselines.
  • C. Administrative Templates deploy ADMX-backed settings, which can be part of a baseline, but baselines offer a curated, comprehensive set of security settings directly.
  • D. Device restrictions are a specific type of configuration profile for common device limitations, not a comprehensive set of security best practices as a whole.

Intune Security Baselines

Pre-configured groups of Microsoft-recommended security settings in Intune, designed to quickly and consistently apply security best practices to Windows devices.

  • Microsoft-recommended settings.
  • Comprehensive security configuration.
  • Ensures consistent security posture.
  • Regularly updated by Microsoft.

Memory trick: Baselines are the bedrock of consistent security.

More Manage devices and apps (55-60%) questions