CIS Microsoft Intune Benchmark

Secure configuration guidelines for Microsoft Intune Mobile Device Management

v2.0.0 March 2025

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Microsoft Intune. Recommendations cover device enrollment, compliance policies, configuration profiles, app protection, conditional access, and monitoring and reporting.

~95Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1EnrollmentRestrictions, Autopilot, DEP
2ComplianceWindows, iOS, Android
3Config ProfilesRestrictions, Defender
4App ProtectionData transfer, managed apps
5Conditional AccessMFA, device compliance
6MonitoringReports, notifications

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Microsoft Intune deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — Device Enrollment

▶

1.1 Enrollment Configuration

▶
1.1.1 Ensure Device Enrollment Restrictions Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Device Enrollment Restrictions Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Device Enrollment Restrictions Are Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Device Enrollment Restrictions Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.1.2 Ensure Platform Restrictions Block Personal Devices Where Required (Automated)
L1 Auto
Description

This recommendation ensures that Platform Restrictions Block Personal Devices Where Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Platform Restrictions Block Personal Devices Where Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Platform Restrictions Block Personal Devices Where Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.1.3 Ensure Device Limit Restrictions Are Set (Automated)
L1 Auto
Description

This recommendation verifies that Device Limit Restrictions Are Set on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Device Limit Restrictions Are Set. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Device Limit Restrictions Are Set. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.1.4 Ensure Terms of Use Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Terms of Use Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Terms of Use Are Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Terms of Use Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.2 Enrollment Profiles

▶
1.2.1 Ensure Windows Autopilot Is Configured for Corporate Devices (Automated)
L1 Auto
Description

This recommendation verifies that Windows Autopilot Is Configured for Corporate Devices on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Windows Autopilot Is Configured for Corporate Devices. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Windows Autopilot Is Configured for Corporate Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.2.2 Ensure Apple DEP/ADE Is Configured for iOS/macOS Devices (Automated)
L1 Auto
Description

This recommendation verifies that Apple DEP/ADE Is Configured for iOS/macOS Devices on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Apple DEP/ADE Is Configured for iOS/macOS Devices. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Apple DEP/ADE Is Configured for iOS/macOS Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.2.3 Ensure Android Enterprise Enrollment Is Preferred Over Device Admin (Automated)
L1 Auto
Description

This recommendation verifies that Android Enterprise Enrollment Is Preferred Over Device Admin on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Android Enterprise Enrollment Is Preferred Over Device Admin. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Android Enterprise Enrollment Is Preferred Over Device Admin. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

1.2.4 Ensure Multi-Factor Authentication Is Required for Enrollment (Automated)
L1 Auto
Description

This recommendation ensures that Multi-Factor Authentication Is Required for Enrollment on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Multi-Factor Authentication Is Required for Enrollment. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Multi-Factor Authentication Is Required for Enrollment. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2 — Compliance Policies

▶

2.1 Windows Compliance

▶
2.1.1 Ensure BitLocker Is Required (Automated)
L1 Auto
Description

This recommendation ensures that BitLocker Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that BitLocker Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure BitLocker Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.1.2 Ensure Minimum OS Version Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Minimum OS Version Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Minimum OS Version Is Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Minimum OS Version Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.1.3 Ensure Password Complexity Is Required (Automated)
L1 Auto
Description

This recommendation ensures that Password Complexity Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Password Complexity Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Password Complexity Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.1.4 Ensure Firewall Is Required (Automated)
L1 Auto
Description

This recommendation ensures that Firewall Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Firewall Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Firewall Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.1.5 Ensure TPM Is Required (Automated)
L2 Auto
Description

This recommendation ensures that TPM Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that TPM Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure TPM Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.2 iOS & Android Compliance

▶
2.2.1 Ensure Jailbroken/Rooted Devices Are Blocked (Automated)
L1 Auto
Description

This setting ensures that Jailbroken/Rooted Devices Are Blocked on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Jailbroken/Rooted Devices Are Blocked. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Jailbroken/Rooted Devices Are Blocked. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.2.2 Ensure Minimum OS Version Is Set for Mobile Platforms (Automated)
L1 Auto
Description

This recommendation verifies that Minimum OS Version Is Set for Mobile Platforms on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Minimum OS Version Is Set for Mobile Platforms. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Minimum OS Version Is Set for Mobile Platforms. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.2.3 Ensure Device Passcode Is Required (Automated)
L1 Auto
Description

This recommendation ensures that Device Passcode Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Device Passcode Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Device Passcode Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

2.2.4 Ensure Device Encryption Is Required (Automated)
L1 Auto
Description

This recommendation ensures that Device Encryption Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Device Encryption Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Device Encryption Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3 — Configuration Profiles

▶

3.1 Device Restrictions

▶
3.1.1 Ensure Camera Is Restricted Where Required (Automated)
L2 Auto
Description

This setting ensures that Camera Is Restricted Where Required on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Camera Is Restricted Where Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Camera Is Restricted Where Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.1.2 Ensure Screen Capture Is Restricted for Managed Apps (Automated)
L2 Auto
Description

This setting ensures that Screen Capture Is Restricted for Managed Apps on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Screen Capture Is Restricted for Managed Apps. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Screen Capture Is Restricted for Managed Apps. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.1.3 Ensure USB File Transfer Is Restricted on Managed Devices (Automated)
L2 Auto
Description

This setting ensures that USB File Transfer Is Restricted on Managed Devices on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that USB File Transfer Is Restricted on Managed Devices. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure USB File Transfer Is Restricted on Managed Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.1.4 Ensure Cloud Backup Is Restricted for Corporate Data (Automated)
L1 Auto
Description

This setting ensures that Cloud Backup Is Restricted for Corporate Data on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Cloud Backup Is Restricted for Corporate Data. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Cloud Backup Is Restricted for Corporate Data. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.2 Endpoint Security

▶
3.2.1 Ensure Microsoft Defender for Endpoint Integration Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Microsoft Defender for Endpoint Integration Is Enabled on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Microsoft Defender for Endpoint Integration Is Enabled. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Microsoft Defender for Endpoint Integration Is Enabled. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.2.2 Ensure Attack Surface Reduction Rules Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Attack Surface Reduction Rules Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Attack Surface Reduction Rules Are Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Attack Surface Reduction Rules Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.2.3 Ensure Endpoint Detection and Response Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Endpoint Detection and Response Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Endpoint Detection and Response Is Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Endpoint Detection and Response Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

3.2.4 Ensure Disk Encryption Profile Is Deployed (Automated)
L1 Auto
Description

This recommendation verifies that Disk Encryption Profile Is Deployed on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Disk Encryption Profile Is Deployed. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Disk Encryption Profile Is Deployed. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4 — App Protection

▶

4.1 App Protection Policies

▶
4.1.1 Ensure Data Transfer Between Managed and Unmanaged Apps Is Restricted (Automated)
L1 Auto
Description

This setting ensures that Data Transfer Between Managed and Unmanaged Apps Is Restricted on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Data Transfer Between Managed and Unmanaged Apps Is Restricted. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Data Transfer Between Managed and Unmanaged Apps Is Restricted. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4.1.2 Ensure Copy/Paste Between Managed and Unmanaged Apps Is Restricted (Automated)
L1 Auto
Description

This setting ensures that Copy/Paste Between Managed and Unmanaged Apps Is Restricted on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Copy/Paste Between Managed and Unmanaged Apps Is Restricted. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Copy/Paste Between Managed and Unmanaged Apps Is Restricted. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4.1.3 Ensure PIN or Biometric Is Required for App Access (Automated)
L1 Auto
Description

This recommendation ensures that PIN or Biometric Is Required for App Access on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that PIN or Biometric Is Required for App Access. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure PIN or Biometric Is Required for App Access. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4.1.4 Ensure Offline Access Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Offline Access Timeout Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Offline Access Timeout Is Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Offline Access Timeout Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4.2 Managed Apps

▶
4.2.1 Ensure Required Apps Are Deployed via Company Portal (Automated)
L1 Auto
Description

This recommendation ensures that Required Apps Are Deployed via Company Portal on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Required Apps Are Deployed via Company Portal. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Required Apps Are Deployed via Company Portal. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4.2.2 Ensure Blocked Apps List Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Blocked Apps List Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Blocked Apps List Is Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Blocked Apps List Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

4.2.3 Ensure App Configuration Policies Are Applied (Automated)
L1 Auto
Description

This recommendation verifies that App Configuration Policies Are Applied on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that App Configuration Policies Are Applied. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure App Configuration Policies Are Applied. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5 — Conditional Access

▶

5.1 Access Policies

▶
5.1.1 Ensure Compliant Device Is Required for Access (Automated)
L1 Auto
Description

This recommendation ensures that Compliant Device Is Required for Access on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Compliant Device Is Required for Access. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Compliant Device Is Required for Access. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5.1.2 Ensure MFA Is Required for All Users (Automated)
L1 Auto
Description

This recommendation ensures that MFA Is Required for All Users on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that MFA Is Required for All Users. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure MFA Is Required for All Users. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5.1.3 Ensure Legacy Authentication Is Blocked (Automated)
L1 Auto
Description

This setting ensures that Legacy Authentication Is Blocked on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.

Audit

In the Microsoft Intune admin center, verify that Legacy Authentication Is Blocked. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Legacy Authentication Is Blocked. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5.1.4 Ensure Sign-In Risk Policy Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that Sign-In Risk Policy Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Sign-In Risk Policy Is Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Sign-In Risk Policy Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5.2 Device-Based Policies

▶
5.2.1 Ensure Approved Client App Is Required (Automated)
L1 Auto
Description

This recommendation ensures that Approved Client App Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that Approved Client App Is Required. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Approved Client App Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5.2.2 Ensure App Protection Policy Is Required for Unmanaged Devices (Automated)
L1 Auto
Description

This recommendation ensures that App Protection Policy Is Required for Unmanaged Devices on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In the Microsoft Intune admin center, verify that App Protection Policy Is Required for Unmanaged Devices. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure App Protection Policy Is Required for Unmanaged Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

5.2.3 Ensure Named Locations Are Configured for Trusted Networks (Automated)
L1 Auto
Description

This recommendation verifies that Named Locations Are Configured for Trusted Networks on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Named Locations Are Configured for Trusted Networks. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Named Locations Are Configured for Trusted Networks. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6 — Monitoring & Reporting

▶

6.1 Monitoring

▶
6.1.1 Ensure Non-Compliant Device Reports Are Reviewed (Manual)
L1 Manual
Description

This recommendation verifies that Non-Compliant Device Reports Are Reviewed on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Non-Compliant Device Reports Are Reviewed. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Non-Compliant Device Reports Are Reviewed. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6.1.2 Ensure Device Compliance Trends Are Monitored (Automated)
L1 Auto
Description

This recommendation verifies that Device Compliance Trends Are Monitored on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Device Compliance Trends Are Monitored. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Device Compliance Trends Are Monitored. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6.1.3 Ensure Policy Assignment Failures Are Monitored (Automated)
L1 Auto
Description

This recommendation verifies that Policy Assignment Failures Are Monitored on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Policy Assignment Failures Are Monitored. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Policy Assignment Failures Are Monitored. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6.2 Notifications

▶
6.2.1 Ensure Non-Compliance Email Notifications Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Non-Compliance Email Notifications Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Non-Compliance Email Notifications Are Configured. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Non-Compliance Email Notifications Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6.2.2 Ensure Device Wipe Actions Are Logged (Automated)
L1 Auto
Description

This recommendation verifies that Device Wipe Actions Are Logged on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Device Wipe Actions Are Logged. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Device Wipe Actions Are Logged. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6.2.3 Ensure Audit Logs Are Exported to SIEM (Automated)
L2 Auto
Description

This recommendation verifies that Audit Logs Are Exported to SIEM on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Audit Logs Are Exported to SIEM. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Audit Logs Are Exported to SIEM. Create or edit the policy, apply the setting, and assign it to the appropriate groups.

6.2.4 Ensure Diagnostic Settings Forward to Log Analytics (Automated)
L1 Auto
Description

This recommendation verifies that Diagnostic Settings Forward to Log Analytics on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In the Microsoft Intune admin center, verify that Diagnostic Settings Forward to Log Analytics. Navigate to the appropriate blade and review the policy configuration.

Remediation

In the Microsoft Intune admin center, configure Diagnostic Settings Forward to Log Analytics. Create or edit the policy, apply the setting, and assign it to the appropriate groups.