You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/protect/endpoint-security-account-protection-policy.md
+70-13Lines changed: 70 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,13 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Manage attack account protection settings with endpoint security policies in Microsoft Intune | Microsoft Docs
5
-
description: Configure and deploy policies for devices you manage with endpoint security account protection policy settings in Microsoft Endpoint Manager.
4
+
title: Manage account protection settings with endpoint security policies in Microsoft Intune | Microsoft Docs
5
+
description: Deploy policies for endpoint security account protection policies to devices you manage with in Microsoft Endpoint Manager.
6
6
keywords:
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 05/15/2020
10
+
ms.date: 01/26/2022
11
11
ms.topic: reference
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -30,28 +30,85 @@ ms.reviewer: mattcall
30
30
31
31
# Account protection policy for endpoint security in Intune
32
32
33
-
Use Intune endpoint security policies for account protection to protect the identity and accounts of your users. The account protection policy is focused on settings for Windows Hello and Credential Guard, which is part of Windows identity and access management.
34
-
35
-
-*Windows Hello for Business* replaces passwords with strong two-factor authentication on PCs and mobile devices.
36
-
-*Credential Guard* helps protect credentials and secrets that you use with your devices.
37
-
38
-
To learn more, see [Identity and access management](/windows/security/identity-protection/) in the Windows identity and access management documentation.
33
+
Use Intune endpoint security policies for account protection to protect the identity and accounts of your users and manage the built-in group memberships on devices.
39
34
40
35
Find the endpoint security policies for Account protection under *Manage* in the **Endpoint security** node of the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
41
36
42
37
View [settings for account protection profiles](../protect/endpoint-security-asr-profile-settings.md).
43
38
44
39
## Prerequisites for Account protection profiles
45
40
46
-
- Windows 10 or Windows 11
41
+
- To support the *Account protection (preview)* profile, devices must run Windows 10 or Windows 11.
42
+
- To support the *Local user group membership (preview)* profile, devices must run Windows 10 20H2 or later, or Windows 11.
47
43
48
44
## Account protection profiles
49
45
50
-
*Account protection profiles are in Preview*.
46
+
*Account protection profiles are in preview*.
47
+
48
+
**Windows 10/11 profiles**:
49
+
50
+
-**Account protection (preview)** – Settings for account protection policies help you protect user credentials.
51
+
52
+
The account protection policy is focused on settings for Windows Hello and Credential Guard, which is part of Windows identity and access management.
53
+
54
+
-*Windows Hello for Business* replaces passwords with strong two-factor authentication on PCs and mobile devices.
55
+
-*Credential Guard* helps protect credentials and secrets that you use with your devices.
56
+
57
+
To learn more, see [Identity and access management](/windows/security/identity-protection/) in the Windows identity and access management documentation.
58
+
59
+
-**Local user group membership (preview)** – Use this profile to add, remove, or replace members of the built-in local groups on Windows devices. For example, the Administrators local group has broad rights. You can use this policy to edit the Admin group's membership to lock it down to a set of exclusively defined members.
60
+
61
+
Use of this profile is detailed in the following section, [Manage local groups on Windows devices](#manage-local-groups-on-windows-devices).
62
+
63
+
## Manage local groups on Windows devices
64
+
65
+
Use the Local user group membership (preview) profile to manage the users that are members of the built-in local groups on Windows 10/11 devices that receive this policy.
66
+
67
+
### Configure the profile
68
+
69
+
This profile manages the local group membership on devices through [Policy CSP - LocalUsersAndGroups](/windows/client-management/mdm/policy-csp-localusersandgroups?WT.mc_id=Portal-fx). The CSP documentation includes additional details on how configurations apply, and an FAQ about the use of the CSP.
70
+
71
+
When configuring this profile, on the *Configuration settings* page you can create multiple rules to manage which built-in local groups you want to change, the group action to take, and the method to select the users.
72
+
73
+
:::image type="content" source="./media/endpoint-security-account-protection-policy/create-profile.png" alt-text="Screen shot of the Configuration settings page for configuring the profile.":::
74
+
75
+
The following are the configurations you can make:
76
+
77
+
-**Local group**: Select one or more groups from the drop-down. These groups will all apply the same Group and user action to the users you assign. You can create more than one grouping of local groups in a single profile and assign different actions and groups of users to each grouping of local groups.
78
+
79
+
-**Group and user action**: Configure the action to apply to the selected groups. This action will apply to the users you select for this same action and grouping of local accounts. Actions you can choose include:
80
+
-**Add (Update)**: Adds members to the selected groups. The group membership for users that aren’t specified by the policy are not changed.
81
+
-**Remove (Update)**: Remove members from the selected groups. The group membership for users that aren’t specified by the policy are not changed.
82
+
-**Add (Replace)**: Replace the members of the selected groups with the new members you specify for this action. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed.
83
+
84
+
> [!CAUTION]
85
+
> If the same group is configured with both a Replace and Update action, the Replace action wins. This is not considered a conflict. Such a configuration can occur when you deploy multiple policies to the same device, or when this CSP is also configured by use of Microsoft Graph.
86
+
87
+
-**User selection type**: Choose how to select users. Options include:
88
+
89
+
-**Users**: Select the users and user groups from your Azure Active Directory (Azure AD).
90
+
-**Manual**: Specify Azure AD users and groups manually, by username, domain/username, or the groups security identifier (SID).
91
+
92
+
-**Selected user(s)**: Depending on your selection for *User selection type*, you’ll use one of the following options:
93
+
94
+
-**Select user(s)**: Select the users and user groups from your Azure Active Directory (Azure AD).
95
+
-**Add users(s)**: This opens the **Add users** pane where you can then specify one or more user identifiers as they appear on a device. You can specify the user by *Username, Domain/username*, or by *security identifier (SID)*.
96
+
97
+
:::image type="content" source="./media/endpoint-security-account-protection-policy/add-user.png" alt-text="Screen shot of the Add users page.":::
98
+
99
+
### Conflicts
100
+
101
+
If policies create a conflict for a group membership, the conflicting settings from each policy are not sent to the device. Instead, the conflict is reported for those policies in the Microsoft Endpoint Manager admin center. To resolve the conflict, reconfigure one or more policies.
102
+
103
+
### Reporting
104
+
105
+
As devices check in and apply the policy, the admin center displays the status of the devices and users as successful or in error.
51
106
52
-
**Windows 10 profiles**:
107
+
Because the policy can contain multiple rules, consider the following:
53
108
54
-
-**Account protection***(Preview)* – Settings for account protection policies help you protect user credentials.
109
+
- When processing the policy for devices, the per-setting status view displays a status for the group of rules as if it’s a single setting.
110
+
- Each rule in the policy that results in an error is skipped, and not sent to devices.
111
+
- Each rule that is successful is sent to devices to be applied.
0 commit comments