You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/protect/security-baseline-settings-mdm-all.md
+40-2Lines changed: 40 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ description: Review the defaults and available settings for the different versio
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 11/19/2021
10
+
ms.date: 04/06/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -67,6 +67,16 @@ To update a security baseline profile to the latest version of that baseline, se
67
67
::: zone-end
68
68
::: zone pivot="mdm-sept-2020,mdm-december-2020,november-2021"
69
69
70
+
## Above Lock
71
+
72
+
-**Voice activate apps from locked screen**
73
+
Specifies whether or not the user can interact with a voice assistant using speech while the system is locked. If you enable or don’t configure this setting, the user can interact with voice assistant using speech while the system is locked. If you disable this setting, the system will need to be unlocked for the user to interact using speech.
Specify the level of cloud-delivered protection. Not Configured uses the default Microsoft Defender Antivirus blocking level and provides strong detection without increasing the risk of detecting legitimate files. High applies a strong level of detection. High + uses the High level and applies addition protection measures (may impact client performance). Zero tolerance blocks all unknown executables While unlikely, setting to High may cause some legitimate files to be detected.
When set to Yes, Microsoft Defender will scan network files. When set to Not configured, the client will return to default with is disabling scanning of network files.
When set to Yes, Defender will send information to Microsoft about any problems it finds. If set to Not configured, the client will return to default which enables the feature but allows the user to disable it.
@@ -1728,6 +1759,13 @@ This rule prevents attacks by blocking Adobe Reader from creating additional pro
1728
1759
1729
1760
**Default**: Block
1730
1761
1762
+
-**Block JavaScript or VBScript from launching downloaded executable content**:
1763
+
[Protect devices from exploits](/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction)
1764
+
1765
+
When set to Yes, Defender will block Javascript or VBScript files that have been downloaded from the Internet from being executed. When set to Audit only, Windows events will be raised instead of blocking. Setting to Not Configured will return the setting to Windows default, which is off. This attack surface reduction (ASR) rule is controlled via the following GUID: D3E037E1-3EB8-44C8-A917-57927947596D
1766
+
1767
+
**Default**: Block
1768
+
1731
1769
-**Block executable content download from email and webmail clients**:
1732
1770
[Block executable content download from email and webmail clients](/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction)
0 commit comments