CIS Microsoft Intune Benchmark
Secure configuration guidelines for Microsoft Intune Mobile Device Management
v2.0.0 March 2025Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Microsoft Intune. Recommendations cover device enrollment, compliance policies, configuration profiles, app protection, conditional access, and monitoring and reporting.
| Section | Area | Focus |
|---|---|---|
| 1 | Enrollment | Restrictions, Autopilot, DEP |
| 2 | Compliance | Windows, iOS, Android |
| 3 | Config Profiles | Restrictions, Defender |
| 4 | App Protection | Data transfer, managed apps |
| 5 | Conditional Access | MFA, device compliance |
| 6 | Monitoring | Reports, notifications |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Microsoft Intune deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — Device Enrollment
▶1.1 Enrollment Configuration
▶This recommendation verifies that Device Enrollment Restrictions Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Device Enrollment Restrictions Are Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Device Enrollment Restrictions Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that Platform Restrictions Block Personal Devices Where Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Platform Restrictions Block Personal Devices Where Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Platform Restrictions Block Personal Devices Where Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Device Limit Restrictions Are Set on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Device Limit Restrictions Are Set. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Device Limit Restrictions Are Set. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Terms of Use Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Terms of Use Are Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Terms of Use Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
1.2 Enrollment Profiles
▶This recommendation verifies that Windows Autopilot Is Configured for Corporate Devices on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Windows Autopilot Is Configured for Corporate Devices. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Windows Autopilot Is Configured for Corporate Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Apple DEP/ADE Is Configured for iOS/macOS Devices on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Apple DEP/ADE Is Configured for iOS/macOS Devices. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Apple DEP/ADE Is Configured for iOS/macOS Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Android Enterprise Enrollment Is Preferred Over Device Admin on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Android Enterprise Enrollment Is Preferred Over Device Admin. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Android Enterprise Enrollment Is Preferred Over Device Admin. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that Multi-Factor Authentication Is Required for Enrollment on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Multi-Factor Authentication Is Required for Enrollment. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Multi-Factor Authentication Is Required for Enrollment. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
2 — Compliance Policies
▶2.1 Windows Compliance
▶This recommendation ensures that BitLocker Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that BitLocker Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure BitLocker Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Minimum OS Version Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Minimum OS Version Is Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Minimum OS Version Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that Password Complexity Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Password Complexity Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Password Complexity Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that Firewall Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Firewall Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Firewall Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that TPM Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that TPM Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure TPM Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
2.2 iOS & Android Compliance
▶This setting ensures that Jailbroken/Rooted Devices Are Blocked on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Jailbroken/Rooted Devices Are Blocked. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Jailbroken/Rooted Devices Are Blocked. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Minimum OS Version Is Set for Mobile Platforms on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Minimum OS Version Is Set for Mobile Platforms. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Minimum OS Version Is Set for Mobile Platforms. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that Device Passcode Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Device Passcode Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Device Passcode Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that Device Encryption Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Device Encryption Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Device Encryption Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
3 — Configuration Profiles
▶3.1 Device Restrictions
▶This setting ensures that Camera Is Restricted Where Required on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Camera Is Restricted Where Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Camera Is Restricted Where Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This setting ensures that Screen Capture Is Restricted for Managed Apps on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Screen Capture Is Restricted for Managed Apps. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Screen Capture Is Restricted for Managed Apps. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This setting ensures that USB File Transfer Is Restricted on Managed Devices on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that USB File Transfer Is Restricted on Managed Devices. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure USB File Transfer Is Restricted on Managed Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This setting ensures that Cloud Backup Is Restricted for Corporate Data on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Cloud Backup Is Restricted for Corporate Data. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Cloud Backup Is Restricted for Corporate Data. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
3.2 Endpoint Security
▶This recommendation verifies that Microsoft Defender for Endpoint Integration Is Enabled on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Microsoft Defender for Endpoint Integration Is Enabled. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Microsoft Defender for Endpoint Integration Is Enabled. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Attack Surface Reduction Rules Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Attack Surface Reduction Rules Are Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Attack Surface Reduction Rules Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Endpoint Detection and Response Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Endpoint Detection and Response Is Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Endpoint Detection and Response Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Disk Encryption Profile Is Deployed on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Disk Encryption Profile Is Deployed. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Disk Encryption Profile Is Deployed. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
4 — App Protection
▶4.1 App Protection Policies
▶This setting ensures that Data Transfer Between Managed and Unmanaged Apps Is Restricted on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Data Transfer Between Managed and Unmanaged Apps Is Restricted. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Data Transfer Between Managed and Unmanaged Apps Is Restricted. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This setting ensures that Copy/Paste Between Managed and Unmanaged Apps Is Restricted on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Copy/Paste Between Managed and Unmanaged Apps Is Restricted. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Copy/Paste Between Managed and Unmanaged Apps Is Restricted. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that PIN or Biometric Is Required for App Access on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that PIN or Biometric Is Required for App Access. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure PIN or Biometric Is Required for App Access. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Offline Access Timeout Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Offline Access Timeout Is Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Offline Access Timeout Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
4.2 Managed Apps
▶This recommendation ensures that Required Apps Are Deployed via Company Portal on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Required Apps Are Deployed via Company Portal. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Required Apps Are Deployed via Company Portal. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Blocked Apps List Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Blocked Apps List Is Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Blocked Apps List Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that App Configuration Policies Are Applied on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that App Configuration Policies Are Applied. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure App Configuration Policies Are Applied. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
5 — Conditional Access
▶5.1 Access Policies
▶This recommendation ensures that Compliant Device Is Required for Access on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Compliant Device Is Required for Access. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Compliant Device Is Required for Access. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that MFA Is Required for All Users on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that MFA Is Required for All Users. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure MFA Is Required for All Users. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This setting ensures that Legacy Authentication Is Blocked on the Microsoft Intune MDM platform. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Intune MDM platform is essential for defense in depth.
In the Microsoft Intune admin center, verify that Legacy Authentication Is Blocked. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Legacy Authentication Is Blocked. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Sign-In Risk Policy Is Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Sign-In Risk Policy Is Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Sign-In Risk Policy Is Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
5.2 Device-Based Policies
▶This recommendation ensures that Approved Client App Is Required on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that Approved Client App Is Required. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Approved Client App Is Required. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation ensures that App Protection Policy Is Required for Unmanaged Devices on the Microsoft Intune MDM platform. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Microsoft Intune MDM platform may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In the Microsoft Intune admin center, verify that App Protection Policy Is Required for Unmanaged Devices. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure App Protection Policy Is Required for Unmanaged Devices. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Named Locations Are Configured for Trusted Networks on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Named Locations Are Configured for Trusted Networks. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Named Locations Are Configured for Trusted Networks. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
6 — Monitoring & Reporting
▶6.1 Monitoring
▶This recommendation verifies that Non-Compliant Device Reports Are Reviewed on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Non-Compliant Device Reports Are Reviewed. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Non-Compliant Device Reports Are Reviewed. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Device Compliance Trends Are Monitored on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Device Compliance Trends Are Monitored. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Device Compliance Trends Are Monitored. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Policy Assignment Failures Are Monitored on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Policy Assignment Failures Are Monitored. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Policy Assignment Failures Are Monitored. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
6.2 Notifications
▶This recommendation verifies that Non-Compliance Email Notifications Are Configured on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Non-Compliance Email Notifications Are Configured. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Non-Compliance Email Notifications Are Configured. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Device Wipe Actions Are Logged on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Device Wipe Actions Are Logged. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Device Wipe Actions Are Logged. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Audit Logs Are Exported to SIEM on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Audit Logs Are Exported to SIEM. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Audit Logs Are Exported to SIEM. Create or edit the policy, apply the setting, and assign it to the appropriate groups.
This recommendation verifies that Diagnostic Settings Forward to Log Analytics on the Microsoft Intune MDM platform. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Microsoft Intune MDM platform vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In the Microsoft Intune admin center, verify that Diagnostic Settings Forward to Log Analytics. Navigate to the appropriate blade and review the policy configuration.
In the Microsoft Intune admin center, configure Diagnostic Settings Forward to Log Analytics. Create or edit the policy, apply the setting, and assign it to the appropriate groups.