You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/protect/security-baseline-settings-defender-atp.md
+9-10Lines changed: 9 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,13 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Intune security baselines settings for Microsoft Defender for Endpoint
4
+
title: Settings list for the Microsoft Defender for Endpoint security baseline in Microsoft Intune
5
5
titleSuffix: Microsoft Intune
6
-
description: Security baseline settings supported by Intune for managing Microsoft Defender for Endpoint
6
+
description: View a list of the settings in the Microsoft Intune security baseline for Microsoft Defender for Endpoint. This list includes the default values for settings as found in the default configuration of the baseline.
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 09/10/2021
10
+
ms.date: 05/03/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -50,9 +50,9 @@ March 2020 v3
50
50
51
51
-->
52
52
53
-
# Microsoft Defender for Endpoint baseline settings for Intune
53
+
# Settings in the Microsoft Defender for Endpoint security baseline in Intune
54
54
55
-
View the Microsoft Defender for Endpoint baseline settings that are supported by Microsoft Intune. The Microsoft Defender for Endpoint baseline defaults represent the recommended configuration for Defender for Endpoint, and might not match baseline defaults for other security baselines.
55
+
View the settings that are part of the Microsoft Defender for Endpoint baseline that ou can deploy with Microsoft Intune. This article details the settings in the available versions of the baseline and the default values for each setting. The default baseline configuration represents the recommended configuration for applicable devices. Defaults for one baseline might not match defaults from other security baselines, or from other versions of this baseline.
56
56
57
57
::: zone pivot="atp-december-2020"
58
58
@@ -75,7 +75,7 @@ This version of the security baseline replaces previous versions. Profiles that
75
75
- Are now read-only. You can continue to use those profiles, but can't edit them to change their configuration.
76
76
- Can be updated to the latest version. After you update to the current baseline version, you can edit the profile to modify settings.
77
77
78
-
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action that's available when viewing the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
78
+
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action. This action is available when you view the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
79
79
80
80
To update a security baseline profile to the latest version of that baseline, see [Change the baseline version for a profile](../protect/security-baselines-configure.md#change-the-baseline-version-for-a-profile).
81
81
@@ -85,11 +85,10 @@ To update a security baseline profile to the latest version of that baseline, se
85
85
**Microsoft Defender for Endpoint baseline for March 2020 - version 3**
86
86
This version of the security baseline replaces previous versions. Profiles that were created prior to the availability of this baseline version:
87
87
88
-
89
88
- Are now read-only. You can continue to use those profiles, but can't edit them to change their configuration.
90
-
- Can be updated to the latest version. After update the current baseline version, you can edit the profile to modify settings.
89
+
- Can be updated to the latest version. After you update the current baseline version, you can edit the profile to modify settings.
91
90
92
-
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action that's available when viewing the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
91
+
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action. This action is available when you view the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
93
92
94
93
To update a security baseline profile to the latest version of that baseline, see [Change the baseline version for a profile](../protect/security-baselines-configure.md#change-the-baseline-version-for-a-profile).
95
94
@@ -218,7 +217,7 @@ To learn more, see [Attack surface reduction rules](/windows/security/threat-pro
218
217
219
218
For more information, see [WindowsDefenderApplicationGuard CSP](/windows/client-management/mdm/windowsdefenderapplicationguard-csp) in the Windows documentation.
220
219
221
-
While using Microsoft Edge, Microsoft Defender Application Guard protects your environment from sites that aren't trusted by your organization. When users visit sites that aren't listed in your isolated network boundary, the sites open in a Hyper-V virtual browsing session. Trusted sites are defined by a network boundary.
220
+
When you use Microsoft Edge, Microsoft Defender Application Guard protects your environment from sites that aren't trusted by your organization. When users visit sites that aren't listed in your isolated network boundary, the sites open in a Hyper-V virtual browsing session. Trusted sites are defined by a network boundary.
Copy file name to clipboardExpand all lines: memdocs/intune/protect/security-baseline-settings-edge.md
+7-8Lines changed: 7 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,13 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Intune security baselines settings for Microsoft Edge
4
+
title: Settings list for the Microsoft Edge security baseline in Intune
5
5
titleSuffix: Microsoft Intune
6
-
description: Security baseline settings supported by Intune for managing Microsoft Edge browser
6
+
description: View a list of the settings in the Microsoft Intune security baseline for Microsoft Edge browser. This list includes the default values for settings as found in the default configuration of the baseline.
View the Microsoft Edge web browser baseline settings that are supported by Microsoft Intune. The Microsoft Edge baseline defaults represent the recommended configuration for Microsoft Edge browsers, and might not match baseline defaults for other security baselines.
51
+
View the settings that are part of the Microsoft Edge web browser security baseline that you can deploy with Microsoft Intune. This article details the settings in the available versions of the baseline and the default values for each setting. The default baseline configuration represents the recommended configuration for applicable devices. Defaults for one baseline might not match defaults from other security baselines, or from other versions of this baseline.
52
52
53
53
::: zone pivot="edge-october-2019"
54
54
@@ -73,13 +73,12 @@ To update a security baseline profile to the latest version of that baseline, se
73
73
This version of the security baseline replaces previous versions. Profiles that were created prior to the availability of this baseline version:
74
74
75
75
- Are now read-only. You can continue to use those profiles, but can't edit them to change their configuration.
76
-
- Can be updated to the latest version. After update the current baseline version, you can edit the profile to modify settings.
76
+
- Can be updated to the latest version. After you update to the current baseline version, you can edit the profile to modify settings.
77
77
78
-
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action that's available when viewing the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
78
+
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action. This action is available when you view the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
79
79
80
80
To update a security baseline profile to the latest version of that baseline, see [Change the baseline version for a profile](../protect/security-baselines-configure.md#change-the-baseline-version-for-a-profile).
81
81
82
-
83
82
::: zone-end
84
83
::: zone pivot="edge-october-2019,edge-april-2020,edge-sept-2020"
85
84
@@ -317,7 +316,7 @@ To update a security baseline profile to the latest version of that baseline, se
317
316
318
317
List the specific extensions that users can't install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed are disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.
319
318
320
-
Use **\*** to block all extensions that aren't explicitly listed in the allow list. If this policy is set to *Not Configured*, users can install any extension in Microsoft Edge.
319
+
Use **\*** to block all extensions that aren't explicitly listed in the allowlist. If this policy is set to *Not Configured*, users can install any extension in Microsoft Edge.
Copy file name to clipboardExpand all lines: memdocs/intune/protect/security-baseline-settings-mdm-all.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,13 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Intune security baselines settings for Windows 10/11 MDM
4
+
title: Settings list for the Windows 10/11 MDM security baseline in Microsoft Intune
5
5
titleSuffix: Microsoft Intune
6
-
description: Review the defaults and available settings for the different versions of the Windows MDM security baseline that you can manage with Microsoft Intune.
6
+
description: View a list of the settings in the Microsoft Intune security baseline for Windows 10/11 MDM security. This list includes the default values for settings as found in the default configuration of the baseline.
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 04/06/2022
10
+
ms.date: 05/03/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -31,9 +31,9 @@ ms.collection:
31
31
---
32
32
33
33
34
-
# Security baseline settings Windows 10 and later with Intune
34
+
# Settings in the Windows 10/11 MDM security baseline in Intune
35
35
36
-
View the security baseline settings that Microsoft Intune supports for devices that run Windows 10 and Windows 11. The default values for settings in this baseline represent the recommended configuration for applicable devices. Defaults for one baseline might not match defaults from other security baselines, or from other versions of this baseline.
36
+
View the settings that are part of the Windows 10/11 MDM security baseline that you can deploy with Microsoft Intune. This article details the settings in the available versions of the baseline and the default values for each setting. The default baseline configuration represents the recommended configuration for applicable devices. Defaults for one baseline might not match defaults from other security baselines, or from other versions of this baseline.
37
37
38
38
- To learn about using security baselines with Intune and how to upgrade the baseline version in your security baseline profiles, see [Use security baselines](security-baselines.md).
39
39
- The most recent baseline version is **Security Baseline for Windows 10 and later for November 2021**
@@ -60,7 +60,7 @@ This version of the security baseline replaces previous versions. Profiles that
60
60
- Are now read-only. You can continue to use those profiles, but can't edit them to change their configuration.
61
61
- Can be updated to the latest version. After you update to the current baseline version, you can edit the profile to modify settings.
62
62
63
-
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action that's available when viewing the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
63
+
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action. THis action is available when you view the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
64
64
65
65
To update a security baseline profile to the latest version of that baseline, see [Change the baseline version for a profile](../protect/security-baselines-configure.md#change-the-baseline-version-for-a-profile).
66
66
@@ -1708,7 +1708,7 @@ This rule prevents attacks by blocking Adobe Reader from creating additional pro
When set to Yes, Defender will send information to Microsoft about any problems it finds. If set to Not configured, the client will return to default which enables the feature but allows the user to disable it.
1711
+
When set to Yes, Defender will send information to Microsoft about any problems it finds. If set to Not configured, the client will return to default, which enables the feature but allows the user to disable it.
Copy file name to clipboardExpand all lines: memdocs/intune/protect/security-baseline-settings-windows-365.md
+8-6Lines changed: 8 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,13 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Intune security baselines settings for Windows 365 Cloud PC
4
+
title: Settings list for the Windows 365 Cloud PC security baseline in Intune
5
5
titleSuffix: Microsoft Intune
6
-
description: Review settings for the Windows 365 Cloud PC security baseline for Microsoft Intune.
6
+
description: View a list of the settings in the Microsoft Intune security baseline for Windows 365 Cloud PC. This list includes the default values for settings as found in the default configuration of the baseline.
View the settings in the Windows 365 Cloud PC security baseline for deployment by Microsoft Intune. Use this baseline to configure [Windows 365 devices](/windows-365/overview) with a recommended security configuration.
36
+
View the settings that are part of the Windows 365 Cloud PC security baseline that you can deploy with Microsoft Intune. This article details the settings in the available versions of the baseline and the default values for each setting. The default baseline configuration represents the recommended configuration for applicable devices. Defaults for one baseline might not match defaults from other security baselines, or from other versions of this baseline.
37
+
38
+
Use this baseline to configure [Windows 365 devices](/windows-365/overview) with a recommended security configuration.
37
39
38
40
::: zone pivot="win365-2101"
39
41
@@ -52,14 +54,14 @@ This version of the security baseline replaces previous versions. Profiles that
52
54
- Are now read-only. You can continue to use those profiles, but can't edit them to change their configuration.
53
55
- Can be updated to the latest version. After you update to the current baseline version, you can edit the profile to modify settings.
54
56
55
-
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action that's available when viewing the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
57
+
To understand what's changed with this version of the baseline from previous versions, use the [Compare baselines](../protect/security-baselines.md#compare-baseline-versions) action. This action is available when you view the *Versions* pane for this baseline. Be sure to select the version of the baseline that you want to view.
56
58
57
59
To update a security baseline profile to the latest version of that baseline, see [Change the baseline version for a profile](../protect/security-baselines-configure.md#change-the-baseline-version-for-a-profile).
58
60
59
61
::: zone-end
60
62
::: zone pivot="win365-2110,win365-2101"
61
63
62
-
This article is a reference for the settings contained in this baseline. For each setting in this article, the default value identifies the Windows 365 Cloud PC team's recommended configuration for that setting as the setting is represented in the baseline. These defaults are not meant to identify the default configuration of the underlying CSP. To learn more about a setting, use the provided links to view that setting's *policy configuration service provider* (CSP) documentation or underlying rules like *attack surface reduction rule* documentation. The links in this document are the same as those you'll find when viewing information about the setting from within the Microsoft Endpoint Manager admin center.
64
+
This article is a reference for the settings contained in this baseline. For each setting in this article, the default value identifies the Windows 365 Cloud PC team's recommended configuration for that setting as the setting is represented in the baseline. These defaults aren't meant to identify the default configuration of the underlying CSP. Use the provided links to view content for the setting's *policy configuration service provider* (CSP) or underlying rules like *attack surface reduction rule*. The links in this document are the same as the links available from within the baseline configuration UI in the Microsoft Endpoint Manager admin center.
63
65
64
66
You can choose to deploy this baseline in its default configuration to apply that recommended security configuration to devices. You can also create custom instances of the baseline to meet your own security needs.
0 commit comments