What's better than Windows Security Baselines in Microsoft Intune? Let's see!

Поділитися
Вставка
  • Опубліковано 22 жов 2024

КОМЕНТАРІ • 17

  • @jigsaw4770
    @jigsaw4770 10 місяців тому +1

    Preach! catalog > Baseline!! Thanks for sharing Dean, this will definitely be useful for everyone - and thanks to David for compiling this!!

  • @artforartforart
    @artforartforart 10 місяців тому +6

    The way I do this:
    1. Login to CIS Workbench and download CIS Build Pack for given benchmark eg Windows 11...
    2. Unzip the build pack
    3. Import whatever you need to Intune GPO Analyser
    4. You can even merge GPOs in Intune eg Comp L1 and Comp L2
    5. Review and select policies
    6. Export as Intune configuration profile
    Done
    This way you have original stuff from CIS. You can edit this - add, remove etc.

    • @aydinpr
      @aydinpr 5 місяців тому

      Is there a way to get these Build Packs/Kits without buying a CIS SecureSuite Membership?

  • @gdr1174
    @gdr1174 4 місяці тому

    Well this is promising. It's slightly overwhelming when trying to consider the different frameworks and different ways to implement settings. Thanks for sharing!

  • @DruDubay
    @DruDubay 2 місяці тому +1

    FYI, the Device policy will disable OneDrive, you can find the setting under "System\Disable One Drive File Sync" which is set to "Sync disabled"

  • @Timmy-Hi5
    @Timmy-Hi5 10 місяців тому

    This is great!, have you tested in the scenario where you have your baselines already configured or additional configuration profiles configured.
    It looks good and easy but going to be very difficult to convince security team to disable baselines and use this 🎅🎁🎄

  • @Carnavallllll
    @Carnavallllll 8 місяців тому

    Hi Dean, Why would you choose for Accounts Block Microsoft Accounts: Users can't add or log on with Microsoft accounts?

  • @intergalact288
    @intergalact288 10 місяців тому

    very nice... thanks Dean to share

  • @5624DK
    @5624DK Місяць тому

    Remote Desktop is being disabled by the policy. I've tried everything, but it’s still not enabling.

  • @cjax235
    @cjax235 7 місяців тому

    Thanks!

  • @ulrikboesen
    @ulrikboesen 10 місяців тому +1

    Would it be possible to only use Business Premium for this?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP  8 місяців тому

      I believe it is possible with M365 BP, yes.

  • @Fernando-y7s8h
    @Fernando-y7s8h 8 місяців тому

    I used this configuration, and they had device lock settings in place, which requires 14 characters, so when using autopilot reset to test out a fresh computer, when prompted with windows hello for business it asked me to setup a PIN that was 14 characters long LOL... what's up with that? This intune stuff is quite confusing...

  • @byron_glover
    @byron_glover 10 місяців тому +1

    Why not just use AD GPO Windows Baselines instead? Or am I missing something here?

  • @patrick__007
    @patrick__007 10 місяців тому

    Thanks Dean!