You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/whats-new-archive.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1184,7 +1184,7 @@ Later, if recovery is needed, a user can always use any device to view their per
1184
1184
1185
1185
#### Improved view of security baseline details for devices<!-- 5536846 -->
1186
1186
1187
-
Now you can drill-in to the details for a device to view the settings details for security baselines that apply to the device. The settings appear in a simple, flat list, which includes the setting category, setting name, and status. For more information, see [View Endpoint security configurations per device](../protect/security-baselines-monitor.md#view-endpoint-security-configurations-per-device).
1187
+
Now you can drill-in to the details for a device to view the settings details for security baselines that apply to the device. The settings appear in a simple, flat list, which includes the setting category, setting name, and status. For more information, see [View Endpoint security configurations per device](../protect/security-baselines-monitor.md).
1188
1188
1189
1189
<!-- vvvvvvvvvvvvvvvvvvvvvv -->
1190
1190
### Monitor and troubleshoot
@@ -2189,7 +2189,7 @@ The following platforms support import of PFX certificates:
2189
2189
- Windows 10
2190
2190
2191
2191
#### View the endpoint security configuration for devices<!-- 6206460 -->
2192
-
We've updated the name of the option in the Microsoft Endpoint Manager admin center, for viewing [endpoint security configurations that apply to a specific device](../protect/security-baselines-monitor.md#view-endpoint-security-configurations-per-device). This option is renamed to **Endpoint security configuration** because it shows applicable security baselines and additional policies created outside of security baselines. Previously, this option was named *Security baselines*.
2192
+
We've updated the name of the option in the Microsoft Endpoint Manager admin center, for viewing [endpoint security configurations that apply to a specific device](../protect/security-baselines-monitor.md). This option is renamed to **Endpoint security configuration** because it shows applicable security baselines and additional policies created outside of security baselines. Previously, this option was named *Security baselines*.
Copy file name to clipboardExpand all lines: memdocs/intune/protect/endpoint-security-manage-devices.md
+7-8Lines changed: 7 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 04/16/2021
10
+
ms.date: 04/29/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -47,7 +47,7 @@ The initial *All devices* view displays your devices and includes key informatio
47
47
- When the device last checked in
48
48
- And more
49
49
50
-

50
+
:::image type="content" source="./media/endpoint-security-manage-devices/all-device-view.png" alt-text="The all device view in the admin center." lightbox="./media/endpoint-security-manage-devices/all-device-view.png":::
51
51
52
52
While viewing device details, you can select a device to drill-in for more information.
53
53
@@ -85,14 +85,13 @@ Consider the following fields:
85
85
86
86
## Review a devices policy
87
87
88
-
While viewing the list of devices, you can select a device to drill-in for more information about it by opening that device’s *Overview* page.
89
-
90
-
From the Overview page of a device, you can then select **Endpoint security configuration** to view the endpoint security policies that apply to that device. Policy details are available for devices managed by MDM and Intune.
88
+
To view information about the device configuration policies that apply to a device that's managed by MDM and Intune, you can view the [**Device configuration report**](../fundamentals/reports.md#device-configuration-report-operational). Both *endpoint security* and *security baseline* policies are device configuration policies.
91
89
90
+
To view the report, select a device and then select **Device configuration**, which is found below the *Monitor* category.
Devices that are managed by Configuration Manager don’t display policy details. To view additional information for these devices, use the Configuration Manager console.
95
-
94
+
Devices that are managed by Configuration Manager don’t display policy details in the report. To view additional information for these devices, use the Configuration Manager console.
96
95
## Remote actions for devices
97
96
98
97
Remote actions are actions you can start or apply to a device from the Microsoft Endpoint Manager admin center. When you view details for a device, you can access remote actions that apply to the device.
@@ -142,4 +141,4 @@ Options you manage for devices don’t take effect until the device checks in wi
142
141
143
142
## Next steps
144
143
145
-
[Manage endpoint security in Intune](../protect/endpoint-security.md)
144
+
[Manage endpoint security in Intune](../protect/endpoint-security.md)
Copy file name to clipboardExpand all lines: memdocs/intune/protect/security-baselines-monitor.md
+20-47Lines changed: 20 additions & 47 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 09/21/2020
10
+
ms.date: 04/29/2022
11
11
ms.topic: how-to
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -35,7 +35,7 @@ Intune provides several options to monitor security baselines. You can:
35
35
- Monitor the security baselines profile that applies to your users and devices.
36
36
- View how the settings from a selected profile are set on a selected device.
37
37
38
-
You can also view the *Endpoint security configurations* that apply to individual devices, which include security baselines.
38
+
You can also view the [Device configuration report](../fundamentals/reports.md#device-configuration-report-operational) to see which device configuration based policies apply to individual devices, which include security baselines.
39
39
40
40
For more information about the feature, see [Security baselines in Intune](security-baselines.md).
41
41
@@ -48,7 +48,7 @@ The *Overview* pane displays two status views for the selected baseline:
48
48
-**Security baseline posture** chart - This chart displays high-level details about device status for the baseline version. The available details:
49
49
-**Matches default baseline** – This status identifies when a devices configuration matches the default (unmodified) baseline configuration.
50
50
-**Matches custom settings** – This status identifies when a devices configuration matches the customized version of the baseline that you've deployed.
51
-
-**Misconfigured** – This status is a rollup that represents three status conditions from a device: *Error*, *Pending*, or *Conflict*. These separate states are available from other views, like the *Security baseline posture by category*, a list view that appears below this chart.
51
+
-**Misconfigured** – This status is a roll-up that represents three status conditions from a device: *Error*, *Pending*, or *Conflict*. These separate states are available from other views, like the *Security baseline posture by category*, a list view that appears below this chart.
52
52
-**Not applicable** - This status represents a device that can’t receive the policy. For example, the policy updates a setting specific to the latest version of Windows, but the device runs an older (earlier) version that doesn’t support that setting.
53
53
54
54
-**Security baseline posture by category** - A list view that displays device status by category. In this list view, the same details as the *Security baseline posture* chart are available. However, in place of *Misconfigured* you’ll see three columns for the status states that make up Misconfigured:
@@ -66,7 +66,7 @@ When you drill-in to the two preceding views, you can view the following details
66
66
-**Not applicable**: The device can't receive the policy. For example, the policy updates a setting specific to the latest version of Windows, but the device runs an older (earlier) version that doesn’t support that setting.
67
67
68
68
From the *Version* view, you can select **Device Status**. The Device Status view displays a list of the devices that receive this baseline and includes the following details:
69
-
-*USER PRINCIPAL NAME* - This displays the user profile associated with the baseline on the device.
69
+
-*USER PRINCIPAL NAME* - The user profile associated with the baseline on the device.
70
70
-*SECURITY BASELINE POSTURE* - This column displays the devices state:
71
71
-**Succeeded**: Policy is applied.
72
72
-**Error**: The policy failed to apply. The message typically displays with an error code that links to an explanation.
@@ -94,65 +94,38 @@ Monitoring the profile gives insight into the deployment state of your devices,
94
94
95
95
## Resolve conflicts for security baselines
96
96
97
-
To help resolve a conflict or error for settings in your security baseline profiles or Endpoint security policies, view the **Endpoint security configuration** of a device. This device-based view helps you identify where your profiles and policies contain settings that drive a status of Conflict or Error.
97
+
To help resolve a conflict or error for settings in your security baseline profiles or Endpoint security policies, view the [Device configuration report](../fundamentals/reports.md#device-configuration-report-operational) for a device. This report view helps you identify where your profiles and policies contain settings that drive a status of Conflict or Error.
98
98
99
-
You can reach information about settings in conflict or error through two paths from within Microsoft Endpoint Manager admin center:
99
+
You can also reach information about settings in conflict or error through two paths from within Microsoft Endpoint Manager admin center:
100
100
101
-
-**Endpoint security** > **Security baselines** > *select a baseline type* > **Profiles** > *select a baseline instance* > **Device Status** > **Endpoint security configuration** > *settings that show a Conflict or Errors*.
102
-
-**Devices** > *select a device* > **Endpoint security configuration** > *select a profile or baseline* > *select a setting from the list of settings that shows a Conflict or Errors*.
103
-
104
-
On the **Endpoint security configuration** view of a device, Intune displays each baseline profile and policy from endpoint security that’s assigned to that device. This view also identifies the associated User Principal Name for each entry, and the status of the baseline profile or policy. A profile or policy can appear multiple times on a device, once for each different User Principal Name associated with it.
105
-
106
-
<!-- pending
107
-
The **Baseline status** represents the worst available status from any applicable setting in that profile or policy. For example, if on the device a single setting from a profile is found to be in conflict while the rest of the baselines’ settings are successful, the *Baseline status* is set to *Conflict*.
108
-
109
-
The available status from best to worst:
110
-
111
-
- **Success** - The setting on the device matches the value as configured in the profile, and there are no conflicting configurations. This is either a default and recommended value, or a custom value specified by an administrator when the profile was configured.
112
-
- **Error** - The profile and settings failed to apply.
113
-
- **Conflict** - The setting conflicts with another instance of the setting from another policy, has an error, or is pending an update. This setting isn’t sent to the device until the conflict is resolved.
114
-
-->
101
+
-**Endpoint security** > **Security baselines** > *select a baseline type* > **Profiles** > *select a baseline instance* > **Device status**
102
+
-**Devices** > **All devices** > *select a device* > **Device configuration** > *select a Policy* > *select a setting from the list of settings that shows a Conflict or Error*.
115
103
116
104
### Drill in to identify and resolve conflicts
117
105
118
-
1. While viewing the Endpoint security configuration of a device, select a profile to drill-in to learn more about the issue that results in a conflict or error status.
106
+
1. While viewing the [Device configuration report](../fundamentals/reports.md#device-configuration-report-operational) for a device, select a policy to drill-in to learn more about the issue that results in a conflict or error status.
119
107
120
-
When you drill-in, Intune displays a list of settings for that profile that includes each setting that wasn’t set as *Not configured*, and the status of that setting. The display can be organized by Category, Setting name, or State. If you filter on the State you can quickly focus on only settings that have an error or conflict.
108
+
When you drill-in, Intune displays a list of settings for that policy that includes each setting that wasn’t set as *Not configured*, and the status of that setting.
121
109
122
110
2. To view details about a specific setting, select it to open the **Settings details** pane. In this pane you’ll see:
123
-
- Setting – The name of the setting.
124
-
- State – The status of the setting on the device.
125
-
- Source Profile – This is a list of each Endpoint security profile or security baseline that configures the same setting but with a different value.
126
111
127
-
> [!TIP]
128
-
> Unlike device configuration profiles, Endpoint security profiles won’t provide error codes or related details.
112
+
- Setting – The name of the setting.
113
+
- State – The status of the setting on the device.
114
+
- Source Profiles – A list of each conflicting profile that configures the same setting but with a different value.
129
115
130
-
3. To reconfigure conflicting profiles, select a record from the **Source Profile** list to open a view of that profiles configuration. From the profile’s configuration view, you can review and edit settings in that profile to remove the conflict.
116
+
3. To reconfigure conflicting profiles, select a record from the **Source Profile** list to open *Overview* for that profile. Select the profiles **Properties** and you can then review and edit settings in that profile to remove the conflict.
131
117
132
118
## View settings from profiles that apply to a device
133
119
134
-
You can select a profile for a Security Baseline, and drill-in to view a list of settings from that profile as they apply to an individual device. To view that list, drill into **Endpoint security** > **Security baselines** > *select the security baseline type* > *select the Profile you want to view* > **Device status**. You can also view the list by going to **Endpoint Security** > **All devices** > *select a device* > **Endpoint security configuration** > *select a baseline version*.
135
-
136
-
After selecting a device, Microsoft Endpoint Manager admin center displays a list of the settings from that profile that includes the category the setting is from and the configuration state on the device. Configuration states include the following values:
120
+
You can select a profile for a Security Baseline, and drill-in to view a list of settings from that profile as they apply to an individual device. To drill in:
137
121
138
-
-**Success** – The setting on the device matches the value as configured in the profile. This is either the baselines default and recommended value, or a custom value specified by an administrator when the profile was configured.
139
-
-**Conflict** – The setting is in conflict with another policy, has an error, or is pending an update.
140
-
-**Not applicable** – The setting is not applied by the profile.
141
-
142
-
> [!NOTE]
143
-
> The status values for settings will update in a future release to provide more granular details.
144
-
145
-
## View Endpoint security configurations per device
146
-
147
-
View details about the security configurations that apply to an individual device, which can help you isolate settings that are misconfigured.
122
+
-**Endpoint Security** > **All devices** > *select a device* > Device configuration > *select a baseline policy instance*
148
123
149
-
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
124
+
After you drill in, the admin center displays a list of the settings from that profile and the settings status. Status states include:
150
125
151
-
2. Go to **Devices** > **All devices** and select the device you want to view.
152
-
153
-
3. In the *Monitor* category, select **Endpoint security configuration** to view the list of security configurations that apply to that device.
154
-
155
-
4. You can select an Endpoint security configuration to drill in and view additional details about the evaluation of that security configuration on the device.
126
+
-**Succeeded** – The setting on the device matches the value as configured in the profile. This is either the baselines default and recommended value, or a custom value specified by an administrator when the profile was configured.
127
+
-**Conflict** – The setting is in conflict with another policy, has an error, or is pending an update.
0 commit comments