|
2 | 2 | title: Create configuration baselines |
3 | 3 | titleSuffix: Configuration Manager |
4 | 4 | description: Create configuration baselines in Configuration Manager that you can deploy to a collection. |
5 | | -ms.date: 11/29/2019 |
| 5 | +ms.date: 01/10/2022 |
6 | 6 | ms.prod: configuration-manager |
7 | 7 | ms.technology: configmgr-compliance |
8 | 8 | ms.topic: conceptual |
@@ -76,17 +76,17 @@ To create a configuration baseline by using the **Create Configuration Baseline* |
76 | 76 |
|
77 | 77 | ## <a name="bkmk_CAbaselines"></a> Include custom configuration baselines as part of compliance policy assessment |
78 | 78 | <!--3608345--> |
79 | | -*(Introduced in version 1910)* |
80 | 79 |
|
81 | | -Starting in version 1910, you can add evaluation of custom configuration baselines as a compliance policy assessment rule. When you create or edit a configuration baseline, you have an option to **Evaluate this baseline as part of compliance policy assessment**. When adding or editing a compliance policy rule, you have a condition called **Include configured baselines in compliance policy assessment**. For co-managed devices, and when you configure Intune to take Configuration Manager compliance assessment results as part of the overall compliance status, this information is sent to Azure AD. You can then use it for conditional access to your Microsoft 365 Apps resources. For more information, see [Conditional access with co-management](../../comanage/quickstart-conditional-access.md). |
| 80 | +You can add evaluation of custom configuration baselines as a compliance policy assessment rule. When you create or edit a configuration baseline, you have an option to **Evaluate this baseline as part of compliance policy assessment**. When adding or editing a compliance policy rule, you have a condition called **Include configured baselines in compliance policy assessment**. For co-managed devices, and when you configure Intune to take Configuration Manager compliance assessment results as part of the overall compliance status, this information is sent to Azure AD. You can then use it for conditional access to your Microsoft 365 Apps resources. For more information, see [Conditional access with co-management](../../comanage/quickstart-conditional-access.md). |
82 | 81 |
|
83 | 82 | To include custom configuration baselines as part of compliance policy assessment, do the following: |
84 | 83 |
|
85 | 84 | - Create and deploy a compliance policy to a user collection with a rule to [**Include configured baselines in compliance policy assessment**](#bkmk_CA). |
86 | 85 | - Select [**Evaluate this baseline as part of compliance policy assessment**](#bkmk_eval-baseline) in a configuration baseline deployed to a device collection. |
87 | 86 |
|
88 | 87 | > [!IMPORTANT] |
89 | | -> When targeting devices that are co-managed, ensure you meet the [co-management prerequisites](../../comanage/overview.md#prerequisites). |
| 88 | +> - When targeting devices that are co-managed, ensure you meet the [co-management prerequisites](../../comanage/overview.md#prerequisites). Co-managed clients ignore service windows for remediation when their compliance policies workload is managed by Intune. <!--12439085, 12412748--> |
| 89 | +> - For devices managed by Configuration Manager, the client honors the service window for compliance policy remediation. To ignore the service window and remediate immediately, select **Check compliance** in the **Software Center**. <!--12439085, 12412748--> |
90 | 90 |
|
91 | 91 | ### Example evaluation scenario |
92 | 92 |
|
|
0 commit comments