Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all Windows 11 devices to enforce a standardized set of security configurations recommended by Microsoft. The baseline should cover settings like password policies, firewall rules, and Defender configurations. Which Intune feature should the administrator use?

  1. ACompliance policies
  2. BSecurity baselines
  3. CDevice configuration profiles
  4. DEndpoint security policies > Antivirus
Show answer & explanation

Correct answer: B. Security baselines

Security baselines in Intune are pre-configured groups of Windows settings recommended by Microsoft security teams. They provide a quick and easy way to deploy a standardized, robust security posture across devices, covering various aspects like password, firewall, and Defender settings.

Why the other options are wrong

  • A. Compliance policies define requirements for device health and compliance but do not actively configure security settings.
  • C. Device configuration profiles allow granular control over individual settings but do not offer a pre-packaged, Microsoft-recommended security configuration.
  • D. Endpoint security policies for Antivirus focus only on Defender settings, not the broader range of baseline security configurations.

Intune Security Baselines

Pre-configured groups of Windows security settings recommended by Microsoft, designed to quickly deploy a robust security posture across managed devices within Microsoft Intune.

  • Based on Microsoft's security guidance.
  • Covers various security areas (e.g., password, firewall, Defender).
  • Simplifies the implementation of secure configurations.

Memory trick: Security Baselines Offer Great Compliance.

More Manage devices and apps (55-60%) questions