Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator needs to deploy a security baseline to all Windows 11 devices to enforce a standardized set of security configurations recommended by Microsoft. The baseline should cover settings like password policies, firewall rules, and Defender configurations. Which Intune feature should the administrator use?
- ACompliance policies
- BSecurity baselines
- CDevice configuration profiles
- DEndpoint security policies > Antivirus
Show answer & explanationAnswer & explanation
Correct answer: B. Security baselines
Security baselines in Intune are pre-configured groups of Windows settings recommended by Microsoft security teams. They provide a quick and easy way to deploy a standardized, robust security posture across devices, covering various aspects like password, firewall, and Defender settings.
Why the other options are wrong
- A. Compliance policies define requirements for device health and compliance but do not actively configure security settings.
- C. Device configuration profiles allow granular control over individual settings but do not offer a pre-packaged, Microsoft-recommended security configuration.
- D. Endpoint security policies for Antivirus focus only on Defender settings, not the broader range of baseline security configurations.
Intune Security Baselines
Pre-configured groups of Windows security settings recommended by Microsoft, designed to quickly deploy a robust security posture across managed devices within Microsoft Intune.
- Based on Microsoft's security guidance.
- Covers various security areas (e.g., password, firewall, Defender).
- Simplifies the implementation of secure configurations.
Memory trick: Security Baselines Offer Great Compliance.