Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have the latest recommended security settings applied based on industry best practices. These settings should be automatically configured and monitored for compliance. Which Intune feature should be used?
- ADevice configuration policies
- BWindows Update rings
- CSecurity baselines
- DCustom OMA-URI profiles
Show answer & explanationAnswer & explanation
Correct answer: C. Security baselines
Security baselines in Intune are pre-configured groups of settings recommended by Microsoft security teams to help secure Windows devices according to industry best practices. They are designed for automatic configuration and compliance monitoring.
Why the other options are wrong
- A. Device configuration policies are for individual settings or custom groups, but not pre-packaged security best practices.
- B. Windows Update rings manage OS updates, not security configuration settings.
- D. Custom OMA-URI profiles are for specific, non-standard settings, not for broad sets of recommended security configurations.
Intune Security Baselines
Pre-configured groups of Windows settings recommended by Microsoft security teams to help secure devices according to industry best practices.
- Based on security best practices from Microsoft.
- Simplifies the deployment of recommended security settings.
- Monitors compliance with the baseline settings.
Memory trick: Baselines for best practices, custom for unique hacks.