This document lists every policy JSON file in this repository and explains what each policy enforces on a device when deployed through Microsoft Intune.
Total policy files: 874
| Policy file | Device effect |
|---|---|
Android Benchmarks/Android Compliance/Baseline - Android Enterprise - Device Health.json |
On the device, this policy applies the "Baseline - Android Enterprise - Device Health" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Android Enterprise - Device Properties.json |
On the device, this policy applies the "Baseline - Android Enterprise - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Android Enterprise - Microsoft Defender for Endpoint.json |
On the device, this policy applies the "Baseline - Android Enterprise - Microsoft Defender for Endpoint" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Android Enterprise - System Security.json |
On the device, this policy applies the "Baseline - Android Enterprise - System Security" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Personally-owned work profile - Device Health.json |
On the device, this policy applies the "Baseline - Personally-owned work profile - Device Health" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Personally-owned work profile - Device Properties.json |
On the device, this policy applies the "Baseline - Personally-owned work profile - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Personally-owned work profile - Microsoft Defender for Endpoint.json |
On the device, this policy applies the "Baseline - Personally-owned work profile - Microsoft Defender for Endpoint" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Compliance/Baseline - Personally-owned work profile - System Security.json |
On the device, this policy applies the "Baseline - Personally-owned work profile - System Security" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Allow access to developer settings.json |
On the device, this policy applies the "Baseline - Android ENT - Allow access to developer settings" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block Bluetooth configuration.json |
On the device, this policy applies the "Baseline - Android ENT - Block Bluetooth configuration" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block access to camera.json |
On the device, this policy applies the "Baseline - Android ENT - Block access to camera" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block account changes.json |
On the device, this policy applies the "Baseline - Android ENT - Block account changes" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block beaming data from apps using NFC.json |
On the device, this policy applies the "Baseline - Android ENT - Block beaming data from apps using NFC" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block factory reset.json |
On the device, this policy applies the "Baseline - Android ENT - Block factory reset" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block roaming data services.json |
On the device, this policy applies the "Baseline - Android ENT - Block roaming data services" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block tethering and access to hotspots.json |
On the device, this policy applies the "Baseline - Android ENT - Block tethering and access to hotspots" setting from Intune and enforces the configured behavior for that feature. |
Android Benchmarks/Android Enterprise for Intune/Baseline - Android ENT - Block volume changes.json |
On the device, this policy applies the "Baseline - Android ENT - Block volume changes" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS Compliance/Baseline - macOS - Device Health.json |
On the device, this policy applies the "Baseline - macOS - Device Health" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS Compliance/Baseline - macOS - System Security.json |
On the device, this policy applies the "Baseline - macOS - System Security" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Allow History Clearing.json |
On the device, this policy applies the "Baseline - macOS - Allow History Clearing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Allow Platform SSO Auth Fallback.json |
On the device, this policy applies the "Baseline - macOS - Allow Platform SSO Auth Fallback" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Allow Private Browsing.json |
On the device, this policy applies the "Baseline - macOS - Allow Private Browsing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Allow Summary.json |
On the device, this policy applies the "Baseline - macOS - Allow Summary" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Safari Extension Identifier.json |
On the device, this policy applies the "Baseline - macOS - Safari Extension Identifier" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Safari History Clearing.json |
On the device, this policy applies the "Baseline - macOS - Safari History Clearing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Safari Homepage URL.json |
On the device, this policy applies the "Baseline - macOS - Safari Homepage URL" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Safari Page Type.json |
On the device, this policy applies the "Baseline - macOS - Safari Page Type" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple MacOS for Intune/Baseline - macOS - Safari Private Browsing.json |
On the device, this policy applies the "Baseline - macOS - Safari Private Browsing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - Disable Apple Intelligence .json |
On the device, this policy applies the "Baseline - Disable Apple Intelligence" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - Disable Web Distribution App Installation EU.json |
On the device, this policy applies the "Baseline - Disable Web Distribution App Installation EU" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Default Applications - Calling.json |
On the device, this policy applies the "Baseline - iOS - Default Applications - Calling" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Default Applications - Messaging.json |
On the device, this policy applies the "Baseline - iOS - Default Applications - Messaging" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari History Retention Enabled.json |
On the device, this policy applies the "Baseline - iOS - Safari History Retention Enabled" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Allow Safari History Clearing.json |
On the device, this policy applies the "Baseline - iOS - Allow Safari History Clearing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Allow Safari Private Browsing.json |
On the device, this policy applies the "Baseline - iOS - Allow Safari Private Browsing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Allowed Camera Restriction Bundle IDs.json |
On the device, this policy applies the "Baseline - iOS - Allowed Camera Restriction Bundle IDs" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Audio Accessory Settings.json |
On the device, this policy applies the "Baseline - iOS - Audio Accessory Settings" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Denied ICCIDs For RCS.json |
On the device, this policy applies the "Baseline - iOS - Denied ICCIDs For RCS" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Denied ICCIDs For iMessage And FaceTime.json |
On the device, this policy applies the "Baseline - iOS - Denied ICCIDs For iMessage And FaceTime" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Enforce Latest Software Update Version.json |
On the device, this policy applies the "Baseline - iOS - Enforce Latest Software Update Version" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Idle Reboot Allowed.json |
On the device, this policy applies the "Baseline - iOS - Idle Reboot Allowed" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Lock Screen Message.json |
On the device, this policy applies the "Baseline - iOS - Lock Screen Message" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Rapid Security Response.json |
On the device, this policy applies the "Baseline - iOS - Rapid Security Response" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Recommendation Cadence .json |
On the device, this policy applies the "Baseline - iOS - Recommendation Cadence" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Accept Cookies.json |
On the device, this policy applies the "Baseline - iOS - Safari Accept Cookies" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Allow Disabling Fraud Warning.json |
On the device, this policy applies the "Baseline - iOS - Safari Allow Disabling Fraud Warning" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Allow History Clearing.json |
On the device, this policy applies the "Baseline - iOS - Safari Allow History Clearing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Allow JavaScript.json |
On the device, this policy applies the "Baseline - iOS - Safari Allow JavaScript" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Allow Popups.json |
On the device, this policy applies the "Baseline - iOS - Safari Allow Popups" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Allow Summary.json |
On the device, this policy applies the "Baseline - iOS - Safari Allow Summary" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Extension Identifier.json |
On the device, this policy applies the "Baseline - iOS - Safari Extension Identifier" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Homepage URL.json |
On the device, this policy applies the "Baseline - iOS - Safari Homepage URL" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Page Type.json |
On the device, this policy applies the "Baseline - iOS - Safari Page Type" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Benchmarks/Baseline - iOS - Safari Private Browsing.json |
On the device, this policy applies the "Baseline - iOS - Safari Private Browsing" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Compliance/Baseline - iOSiPadOS - Device Health.json |
On the device, this policy applies the "Baseline - iOSiPadOS - Device Health" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Compliance/Baseline - iOSiPadOS - Device Properties.json |
On the device, this policy applies the "Baseline - iOSiPadOS - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Apple Benchmarks/Apple iOS Compliance/Baseline - iOSiPadOS - Microsoft Defender for Endpoint.json |
On the device, this policy applies the "Baseline - iOSiPadOS - Microsoft Defender for Endpoint" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Block external extensions from being installed.json |
On the device, this policy applies the "Baseline - Chrome - Block external extensions from being installed" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Configure extension installation allow list.json |
On the device, this policy applies the "Baseline - Chrome - Configure extension installation allow list" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Enable Bookmark Bar.json |
On the device, this policy applies the "Baseline - Chrome - Enable Bookmark Bar" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Enable Site Isolation for specified origins.json |
On the device, this policy applies the "Baseline - Chrome - Enable Site Isolation for specified origins" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Enable home button.json |
On the device, this policy applies the "Baseline - Chrome - Enable home button" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Legacy Browser Support.json |
On the device, this policy applies the "Baseline - Chrome - Legacy Browser Support" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Google Chrome/Baseline - Chrome - Show Home button on toolbar.json |
On the device, this policy applies the "Baseline - Chrome - Show Home button on toolbar" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Allow SpeculationRules prefetch for ServiceWorker-controlled URLs_2025-09-01T08_16_40.399Z.json |
On the device, this policy applies the "Baseline - Edge - Allow SpeculationRules prefetch for ServiceWorker-controlled URLs" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Allow pages to use the built-in AI APIs_2025-09-01T08_16_13.628Z.json |
On the device, this policy applies the "Baseline - Edge - Allow pages to use the built-in AI APIs" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Allow software WebGL fallback using SwiftShader_2025-09-01T08_16_19.767Z.json |
On the device, this policy applies the "Baseline - Edge - Allow software WebGL fallback using SwiftShader" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Configuration policy for Microsoft Edge for Business Reporting Connectors_2025-09-01T08_16_22.439Z.json |
On the device, this policy applies the "Baseline - Edge - Configuration policy for Microsoft Edge for Business Reporting Connectors" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Control access to AI-enhanced search in History_2025-09-01T08_16_52.308Z.json |
On the device, this policy applies the "Baseline - Edge - Control access to AI-enhanced search in History" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar_2025-09-01T08_16_24.895Z.json |
On the device, this policy applies the "Baseline - Edge - Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Control whether TLS 1.3 Early Data is enabled in Microsoft Edge_2025-09-01T08_16_43.911Z.json |
On the device, this policy applies the "Baseline - Edge - Control whether TLS 1.3 Early Data is enabled in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Prioritize app-specified profile to open external links_2025-09-01T08_16_32.548Z.json |
On the device, this policy applies the "Baseline - Edge - Prioritize app-specified profile to open external links" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Specify extensions users must allow in order to navigate using InPrivate mode_2025-09-01T08_16_28.644Z.json |
On the device, this policy applies the "Baseline - Edge - Specify extensions users must allow in order to navigate using InPrivate mode" setting from Intune and enforces the configured behavior for that feature. |
Browser Benchmarks/Microsoft Edge/Baseline - Edge - Use Primary Work Profile as default to open external links_2025-09-01T08_16_48.549Z.json |
On the device, this policy applies the "Baseline - Edge - Use Primary Work Profile as default to open external links" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - Choose how BitLocker-protected operating system drives can be recovered Require 48-digit recovery password.json |
On the device, this policy applies the "CISv4 - Choose how BitLocker-protected operating system drives can be recovered Require 48-digit recovery password" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Service Enabled.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Service Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'Configure RPC connection settings Use authentication for outgoing RPC connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'Configure RPC connection settings Use authentication for outgoing RPC connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'Configure RPC listener settings Protocols to allow for incoming RPC connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'Configure RPC listener settings Protocols to allow for incoming RPC connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'Enable Domain Network Firewall Default Inbound Action for Domain Profile.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'Enable Domain Network Firewall Default Inbound Action for Domain Profile" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'MSS (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing).json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'MSS (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'Microsoft network client Digitally sign communications (if server agrees).json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'Microsoft network client Digitally sign communications (if server agrees)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'Network Security Minimum Session Security For NTLMSSP Based Servers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'Network Security Minimum Session Security For NTLMSSP Based Servers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'PUA Protection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'PUA Protection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'Remote host allows delegation of non exportable credentials.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'Remote host allows delegation of non exportable credentials" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'User Account Control Behavior of the elevation prompt for standard users.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'User Account Control Behavior of the elevation prompt for standard users" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - 'User Account Control Only elevate UIAccess applications that are installed in secure locations.json |
On the device, this policy applies the "CISv4 - WIN - L1 - 'User Account Control Only elevate UIAccess applications that are installed in secure locations" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block Adobe Reader from creating child processes.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block Adobe Reader from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block JavaScript or VBScript from launching downloaded executable content.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block JavaScript or VBScript from launching downloaded executable content" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block Office applications from injecting code into other processes.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block Office applications from injecting code into other processes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block Office communication application from creating child processes.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block Office communication application from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block Win32 API calls from Office macros.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block Win32 API calls from Office macros" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block abuse of exploited vulnerable signed drivers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block abuse of exploited vulnerable signed drivers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block all Office applications from creating child processes.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block all Office applications from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block credential stealing from the Windows local security authority subsystem.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block credential stealing from the Windows local security authority subsystem" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block executable content from email client and webmail.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block executable content from email client and webmail" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block executable files from running unless they meet a prevalence, age, or trusted list criterion'.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block executable files from running unless they meet a prevalence, age, or trusted list criterion'" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block execution of potentially obfuscated scripts.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block execution of potentially obfuscated scripts" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block persistence through WMI event subscription.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block persistence through WMI event subscription" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block process creations originating from PSExec and WMI commands.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block process creations originating from PSExec and WMI commands" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Block untrusted and unsigned processes that run from USB.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Block untrusted and unsigned processes that run from USB" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - ASR Use advanced protection against ransomware.json |
On the device, this policy applies the "CISv4 - WIN - L1 - ASR Use advanced protection against ransomware" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Access Credential Manager As Trusted Caller.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Access Credential Manager As Trusted Caller" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Access From Network.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Access From Network" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Account Logon Audit Credential Validation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Account Logon Audit Credential Validation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Account Logon Logoff Audit Account Lockout.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Account Logon Logoff Audit Account Lockout" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Account Logon Logoff Audit Group Membership.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Account Logon Logoff Audit Group Membership" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Account Logon Logoff Audit Logoff.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Account Logon Logoff Audit Logoff" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Account Logon Logoff Audit Logon.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Account Logon Logoff Audit Logon" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Account Management Audit Application Group Management'.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Account Management Audit Application Group Management'" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Accounts Enable Guest account status.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Accounts Enable Guest account status" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Accounts Limit local account use of blank passwords to console logon only'.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Accounts Limit local account use of blank passwords to console logon only'" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Accounts Rename administrator account.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Accounts Rename administrator account" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Accounts Rename guest account.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Accounts Rename guest account" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Act As Part Of The Operating System.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Act As Part Of The Operating System" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Auto Connect To Wi Fi Sense Hotspots.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Auto Connect To Wi Fi Sense Hotspots" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Auto Update.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Auto Update" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Basic authentication WinRM Client.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Basic authentication WinRM Client" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Basic authentication WinRM Service.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Basic authentication WinRM Service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Behavior Monitoring.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Behavior Monitoring" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Clipboard Redirection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Clipboard Redirection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Cortana Above Lock.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Cortana Above Lock" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Cortana.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Cortana" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Email Scanning.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Email Scanning" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Full Scan Removable Drive Scanning.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Full Scan Removable Drive Scanning" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Game DVR.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Game DVR" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Indexing Encrypted Stores Or Items.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Indexing Encrypted Stores Or Items" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Input Personalization.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Input Personalization" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Local Log On.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Local Log On" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Microsoft accounts to be optional.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Microsoft accounts to be optional" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Networking.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Networking" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Print Spooler to accept client connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Print Spooler to accept client connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Realtime Monitoring.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Realtime Monitoring" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Script Scanning.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Script Scanning" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Search To Use Location.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Search To Use Location" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Spotlight Collection (User).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Spotlight Collection (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Telemetry.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Telemetry" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow Windows Ink Workspace.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow Windows Ink Workspace" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow apps from the Microsoft app store to auto update.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow apps from the Microsoft app store to auto update" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow scanning of all downloaded files and attachments.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow scanning of all downloaded files and attachments" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow unencrypted traffic WinRM Client.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow unencrypted traffic WinRM Client" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow unencrypted traffic WinRM Service.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow unencrypted traffic WinRM Service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Allow widgets.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Allow widgets" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Always prompt for password upon connection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Always prompt for password upon connection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Apply UAC restrictions to local accounts on network logons.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Apply UAC restrictions to local accounts on network logons" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Authentication Policy Change.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Authentication Policy Change" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Authorization Policy Change.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Authorization Policy Change" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Changes to Audit Policy.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Changes to Audit Policy" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit File Share Access.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit File Share Access" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Other Logon Logoff Events.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Other Logon Logoff Events" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Security Group Management.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Security Group Management" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Security System Extension.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Security System Extension" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit Special Logon.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit Special Logon" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Audit User Account Management.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Audit User Account Management" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Backup Directory.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Backup Directory" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Backup Files And Directories.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Backup Files And Directories" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Block Non Admin User Install.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Block Non Admin User Install" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Block Office applications from creating executable content.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Block Office applications from creating executable content" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Block all consumer Microsoft account user authentication.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Block all consumer Microsoft account user authentication" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Block launching Universal Windows apps with Windows Runtime API access from hosted content.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Block launching Universal Windows apps with Windows Runtime API access from hosted content" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Block user from showing account details on sign-in.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Block user from showing account details on sign-in" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Boot-Start Driver Initialization Policy.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Boot-Start Driver Initialization Policy" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Change System Time.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Change System Time" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Config refresh.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Config refresh" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure Lsa Protected Process is set to 'Enabled with UEFI Lock.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure Lsa Protected Process is set to 'Enabled with UEFI Lock" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure Offer Remote Assistance.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure Offer Remote Assistance" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure RPC connection settings Protocol to use for outgoing RPC connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure RPC connection settings Protocol to use for outgoing RPC connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure RPC listener settings Authentication protocol to use for incoming RPC connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure RPC listener settings Authentication protocol to use for incoming RPC connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure RPC over TCP port RPC over TCP port.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure RPC over TCP port RPC over TCP port" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure Redirection Guard Redirection Guard Options.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure Redirection Guard Redirection Guard Options" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure SMB v1 client driver.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure SMB v1 client driver" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure SMB v1 server.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure SMB v1 server" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure Solicited Remote Assistance.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure Solicited Remote Assistance" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure System Guard Launch.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure System Guard Launch" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure Windows Defender SmartScreen.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure Windows Defender SmartScreen" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Configure local setting override for reporting to Microsoft MAPS.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Configure local setting override for reporting to Microsoft MAPS" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Continue experiences on this device.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Continue experiences on this device" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size Security.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size Security" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size Setup.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size Setup" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size System.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size System" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Control Event Log behavior when the log file reaches its maximum size" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Create Global Objects.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Create Global Objects" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Create Page File.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Create Page File" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Create Permanent Shared Objects.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Create Permanent Shared Objects" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Create Symbolic Links.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Create Symbolic Links" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Create Token.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Create Token" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Credential Guard.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Credential Guard" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - DO Download Mode.json |
On the device, this policy applies the "CISv4 - WIN - L1 - DO Download Mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Days Until Aggressive Catchup Quick Scan.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Days Until Aggressive Catchup Quick Scan" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Debug Programs.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Debug Programs" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Defer Feature Updates Period in Days.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Defer Feature Updates Period in Days" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Defer Quality Updates Period (Days).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Defer Quality Updates Period (Days)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Deny Access From Network.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Deny Access From Network" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Deny Local Log On.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Deny Local Log On" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Deny Log On As Batch Job.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Deny Log On As Batch Job" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Deny Log On As Service Job.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Deny Log On As Service Job" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Deny Remote Desktop Services Log On.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Deny Remote Desktop Services Log On" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Detailed Tracking Audit PNP Activity.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Detailed Tracking Audit PNP Activity" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Detailed Tracking Audit Process Creation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Detailed Tracking Audit Process Creation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Alphanumeric Device Password Required.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Alphanumeric Device Password Required" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Device Password Expiration.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Device Password Expiration" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Device Password History.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Device Password History" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Max Device Password Failed Attempts.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Max Device Password Failed Attempts" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Max Inactivity Time Device Lock.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Max Inactivity Time Device Lock" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Min Device Password Complex Characters.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Min Device Password Complex Characters" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled Min Device Password Length.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled Min Device Password Length" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Device Password Enabled.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Device Password Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Disable Consumer Account State Content.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Disable Consumer Account State Content" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Disallow Autoplay for non-volume devices.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Disallow Autoplay for non-volume devices" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Disallow Digest authentication WinRM Client.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Disallow Digest authentication WinRM Client" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Disallow Exploit Protection Override.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Disallow Exploit Protection Override" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Disallow WinRM from storing RunAs credentials WinRM Service.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Disallow WinRM from storing RunAs credentials WinRM Service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not allow drive redirection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not allow drive redirection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not allow passwords to be saved.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not allow passwords to be saved" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not delete temp folders upon exit.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not delete temp folders upon exit" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not display network selection UI.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not display network selection UI" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not display the password reveal button.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not display the password reveal button" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not enumerate connected users on domain-joined computers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not enumerate connected users on domain-joined computers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Do not preserve zone information in file attachments (User).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Do not preserve zone information in file attachments (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable App Installer Experimental Features.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable App Installer Experimental Features" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable App Installer Hash Override.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable App Installer Hash Override" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable App Installer ms-appinstaller protocol.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable App Installer ms-appinstaller protocol" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Delegation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Delegation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Domain Network Firewall Disable Inbound Notifications.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Domain Network Firewall Disable Inbound Notifications" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Domain Network Firewall Enable Log Dropped Packets.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Domain Network Firewall Enable Log Dropped Packets" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Domain Network Firewall Enable Log Success Connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Domain Network Firewall Enable Log Success Connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Domain Network Firewall Log File Path' is set to '%SystemRoot%System32logfilesfirewalldomainfw.log.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Domain Network Firewall Log File Path' is set to '%SystemRoot%System32logfilesfirewalldomainfw.log" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Domain Network Firewall Log Max File Size.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Domain Network Firewall Log Max File Size" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Domain Network Firewall.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Domain Network Firewall" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable ESS with Supported Peripherals.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable ESS with Supported Peripherals" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable MPR notifications for the system.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable MPR notifications for the system" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Network Protection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Network Protection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable OneSettings Auditing.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable OneSettings Auditing" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall Default Inbound Action for Private Profile.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall Default Inbound Action for Private Profile" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall Disable Inbound Notifications.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall Disable Inbound Notifications" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall Enable Log Dropped Packets.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall Enable Log Dropped Packets" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall Enable Log Success Connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall Enable Log Success Connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall Log File Path' is set to '%SystemRoot%System32logfilesfirewallprivatefw.log.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall Log File Path' is set to '%SystemRoot%System32logfilesfirewallprivatefw.log" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall Log Max File Size.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall Log Max File Size" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Private Network Firewall.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Private Network Firewall" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Allow Local Ipsec Policy Merge.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Allow Local Ipsec Policy Merge" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Allow Local Policy Merge.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Allow Local Policy Merge" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Default Inbound Action for Public Profile.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Default Inbound Action for Public Profile" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Disable Inbound Notifications.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Disable Inbound Notifications" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Enable Log Dropped Packets.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Enable Log Dropped Packets" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Enable Log Success Connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Enable Log Success Connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Log File Path' is set to '%SystemRoot%System32logfilesfirewallpublicfw.log.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Log File Path' is set to '%SystemRoot%System32logfilesfirewallpublicfw.log" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall Log Max File Size.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall Log Max File Size" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Public Network Firewall.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Public Network Firewall" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable RPC Endpoint Mapper Client Authentication.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable RPC Endpoint Mapper Client Authentication" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Structured Exception Handling Overwrite Protection (SEHOP).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Structured Exception Handling Overwrite Protection (SEHOP)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Sudo.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Sudo" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Virtualization Based Security.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Virtualization Based Security" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Windows NTP Client.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Windows NTP Client" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable Windows NTP Server.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable Windows NTP Server" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enable insecure guest logons.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enable insecure guest logons" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Encryption Oracle Remediation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Encryption Oracle Remediation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enumerate administrator accounts on elevation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enumerate administrator accounts on elevation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Enumerate local users on domain-joined computers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Enumerate local users on domain-joined computers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Facial Features Use Enhanced Anti Spoofing.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Facial Features Use Enhanced Anti Spoofing" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Generate Security Audits.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Generate Security Audits" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Hardened UNC Paths.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Hardened UNC Paths" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Hide Exclusions From Local Users.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Hide Exclusions From Local Users" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Hypervisor Enforced Code Integrity.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Hypervisor Enforced Code Integrity" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Impersonate Client.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Impersonate Client" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Include command line in process creation events.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Include command line in process creation events" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Increase Scheduling Priority.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Increase Scheduling Priority" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Interactive logon Do not display last signed-in.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Interactive logon Do not display last signed-in" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Interactive logon Do not require CTRL+ALT+DEL.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Interactive logon Do not require CTRL+ALT+DEL" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Interactive logon Machine inactivity limit.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Interactive logon Machine inactivity limit" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Interactive logon Message text for users attempting to log on.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Interactive logon Message text for users attempting to log on" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Interactive logon Message title for users attempting to log on.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Interactive logon Message title for users attempting to log on" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Interactive logon Smart card removal behavior.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Interactive logon Smart card removal behavior" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Let Apps Activate With Voice Above Lock.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Let Apps Activate With Voice Above Lock" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Limit Diagnostic Log Collection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Limit Diagnostic Log Collection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Limit Dump Collection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Limit Dump Collection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Limits print driver installation to Administrators.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Limits print driver installation to Administrators" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Load Unload Device Drivers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Load Unload Device Drivers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Lock Memory.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Lock Memory" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSI Allow user control over installs.json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSI Allow user control over installs" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSI Always install with elevated privileges (User).json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSI Always install with elevated privileges (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSI Always install with elevated privileges.json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSI Always install with elevated privileges" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (AutoAdminLogon) Enable Automatic Logon (not recommended).json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (AutoAdminLogon) Enable Automatic Logon (not recommended)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing).json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes.json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (SafeDllSearchMode) Enable Safe DLL search mode (recommended).json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (SafeDllSearchMode) Enable Safe DLL search mode (recommended)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended).json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - MSS (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning.json |
On the device, this policy applies the "CISv4 - WIN - L1 - MSS (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Manage Volume.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Manage Volume" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Manage auditing and security log.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Manage auditing and security log" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Manage preview builds.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Manage preview builds" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Manage processing of Queue-specific files Manage processing of Queue-Specific files.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Manage processing of Queue-specific files Manage processing of Queue-Specific files" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Microsoft network client Digitally sign communications (always).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Microsoft network client Digitally sign communications (always)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Microsoft network client Send unencrypted password to third-party SMB servers.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Microsoft network client Send unencrypted password to third-party SMB servers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Microsoft network server Digitally sign communications (always).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Microsoft network server Digitally sign communications (always)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Microsoft network server Digitally sign communications (if client agrees).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Microsoft network server Digitally sign communications (if client agrees)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Minimize the number of simultaneous connections to the Internet or a Windows Domain.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Minimize the number of simultaneous connections to the Internet or a Windows Domain" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Minimum PIN Length.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Minimum PIN Length" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Minimum Password Age.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Minimum Password Age" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Modify Firmware Environment.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Modify Firmware Environment" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Modify Object Label.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Modify Object Label" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network Security Allow PKU2U authentication requests.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network Security Allow PKU2U authentication requests" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network Security Minimum Session Security For NTLMSSP Based Clients.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network Security Minimum Session Security For NTLMSSP Based Clients" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network access Do not allow anonymous enumeration of SAM accounts and shares.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network access Do not allow anonymous enumeration of SAM accounts and shares" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network access Do not allow anonymous enumeration of SAM accounts.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network access Do not allow anonymous enumeration of SAM accounts" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network access Restrict anonymous access to Named Pipes and Shares.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network access Restrict anonymous access to Named Pipes and Shares" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network access Restrict clients allowed to make remote calls to SAM.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network access Restrict clients allowed to make remote calls to SAM" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network security Allow Local System to use computer identity for NTLM.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network security Allow Local System to use computer identity for NTLM" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network security Do not store LAN Manager hash value on next password change.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network security Do not store LAN Manager hash value on next password change" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network security LAN Manager authentication level.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network security LAN Manager authentication level" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Network security Restrict NTLM Audit Incoming NTLM Traffic.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Network security Restrict NTLM Audit Incoming NTLM Traffic" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Notify Malicious.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Notify Malicious" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Notify Password Reuse.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Notify Password Reuse" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Notify Unsafe App.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Notify Unsafe App" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Notify antivirus programs when opening attachments (User).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Notify antivirus programs when opening attachments (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Object Access Audit Detailed File Share.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Object Access Audit Detailed File Share" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Object Access Audit Other Object Access Events.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Object Access Audit Other Object Access Events" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Object Access Audit Removable Storage.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Object Access Audit Removable Storage" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Oobe Enable Rtp And Sig Update.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Oobe Enable Rtp And Sig Update" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Password Age Days.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Password Age Days" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Password Complexity.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Password Complexity" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Password Length.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Password Length" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Pause Updates.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Pause Updates" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Point and Print Restrictions When installing drivers for a new connection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Point and Print Restrictions When installing drivers for a new connection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Point and Print Restrictions When updating drivers for an existing connection.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Point and Print Restrictions When updating drivers for an existing connection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Policy Change Audit MPSSVC Rule Level Policy Change.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Policy Change Audit MPSSVC Rule Level Policy Change" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Policy Change Audit Other Policy Change Events.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Policy Change Audit Other Policy Change Events" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Post Authentication Reset Delay.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Post Authentication Reset Delay" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Post-authentication actions.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Post-authentication actions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prevent device metadata retrieval from the Internet.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prevent device metadata retrieval from the Internet" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prevent downloading of enclosures.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prevent downloading of enclosures" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prevent enabling lock screen camera.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prevent enabling lock screen camera" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prevent enabling lock screen slide show.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prevent enabling lock screen slide show" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prevent the use of security questions for local accounts.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prevent the use of security questions for local accounts" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prevent users from sharing files within their profile. (User).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prevent users from sharing files within their profile. (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Privilege Use Audit Sensitive Privilege Use.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Privilege Use Audit Sensitive Privilege Use" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Profile Single Process.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Profile Single Process" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Profile System Performance.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Profile System Performance" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prohibit connection to non-domain networks when connected to domain authenticated network.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prohibit connection to non-domain networks when connected to domain authenticated network" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prohibit installation and configuration of Network Bridge on your DNS domain network.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prohibit installation and configuration of Network Bridge on your DNS domain network" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Prohibit use of Internet Connection Sharing on your DNS domain network.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Prohibit use of Internet Connection Sharing on your DNS domain network" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Quick Scan Include Exclusions.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Quick Scan Include Exclusions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Refresh cadence.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Refresh cadence" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Remote Encryption Protection Configured State.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Remote Encryption Protection Configured State" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Remote Shutdown.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Remote Shutdown" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Replace Process Level Token.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Replace Process Level Token" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require PIN For Pairing.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require PIN For Pairing" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require Platform Security Features.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require Platform Security Features" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require Security Device.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require Security Device" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require UEFI Memory Attributes Table.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require UEFI Memory Attributes Table" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require a password when a computer wakes (on battery).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require a password when a computer wakes (on battery)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require a password when a computer wakes (plugged in).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require a password when a computer wakes (plugged in)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require domain users to elevate when setting a network's location.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require domain users to elevate when setting a network's location" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require secure RPC communication.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require secure RPC communication" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require use of specific security layer for remote (RDP) connections.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require use of specific security layer for remote (RDP) connections" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Require user authentication for remote connections by using Network Level Authentication.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Require user authentication for remote connections by using Network Level Authentication" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Restore Files And Directories.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Restore Files And Directories" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Restrict Unauthenticated RPC clients.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Restrict Unauthenticated RPC clients" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Scheduled Install Day.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Scheduled Install Day" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Set client connection encryption level.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Set client connection encryption level" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Set the default behavior for AutoRun.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Set the default behavior for AutoRun" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Shut Down The System.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Shut Down The System" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Sign-in and lock last interactive user automatically after a restart.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Sign-in and lock last interactive user automatically after a restart" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Specify the maximum log file size (KB) Application.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Specify the maximum log file size (KB) Application" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Specify the maximum log file size (KB) Security.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Specify the maximum log file size (KB) Security" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Specify the maximum log file size (KB) Setup.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Specify the maximum log file size (KB) Setup" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Specify the maximum log file size (KB) System.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Specify the maximum log file size (KB) System" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - System Audit I Psec Driver.json |
On the device, this policy applies the "CISv4 - WIN - L1 - System Audit I Psec Driver" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - System Audit Other System Events.json |
On the device, this policy applies the "CISv4 - WIN - L1 - System Audit Other System Events" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - System Audit Security State Change.json |
On the device, this policy applies the "CISv4 - WIN - L1 - System Audit Security State Change" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - System Audit System Integrity.json |
On the device, this policy applies the "CISv4 - WIN - L1 - System Audit System Integrity" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Take Ownership.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Take Ownership" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off Autoplay.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off Autoplay" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off Data Execution Prevention for Explorer.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off Data Execution Prevention for Explorer" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off Internet download for Web publishing and online ordering wizards.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off Internet download for Web publishing and online ordering wizards" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off app notifications on the lock screen.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off app notifications on the lock screen" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off background refresh of Group Policy.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off background refresh of Group Policy" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off downloading of print drivers over HTTP.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off downloading of print drivers over HTTP" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off heap termination on corruption.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off heap termination on corruption" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off multicast name resolution.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off multicast name resolution" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off picture password sign-in.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off picture password sign-in" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off shell protocol protected mode.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off shell protocol protected mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off the offer to update to the latest version of Windows.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off the offer to update to the latest version of Windows" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn off toast notifications on the lock screen (User).json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn off toast notifications on the lock screen (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - Turn on convenience PIN sign-in.json |
On the device, this policy applies the "CISv4 - WIN - L1 - Turn on convenience PIN sign-in" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - User Account Control Behavior of the elevation prompt for administrators.json |
On the device, this policy applies the "CISv4 - WIN - L1 - User Account Control Behavior of the elevation prompt for administrators" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - User Account Control Detect application installations and prompt for elevation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - User Account Control Detect application installations and prompt for elevation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - User Account Control Run all administrators in Admin Approval Mode.json |
On the device, this policy applies the "CISv4 - WIN - L1 - User Account Control Run all administrators in Admin Approval Mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - User Account Control Switch to the secure desktop when prompting for elevation.json |
On the device, this policy applies the "CISv4 - WIN - L1 - User Account Control Switch to the secure desktop when prompting for elevation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - User Account Control Use Admin Approval Mode.json |
On the device, this policy applies the "CISv4 - WIN - L1 - User Account Control Use Admin Approval Mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L1 - WDigest Authentication.json |
On the device, this policy applies the "CISv4 - WIN - L1 - WDigest Authentication" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Camera.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Camera" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Cloud Search.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Cloud Search" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Cross Device Clipboard.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Cross Device Clipboard" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Font Providers.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Font Providers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Location.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Location" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Message Sync.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Message Sync" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Online Tips.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Online Tips" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Remote Shell Access.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Remote Shell Access" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Shared User App Data.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Shared User App Data" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow Windows Spotlight (User).json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow Windows Spotlight (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow remote server management through WinRM Service.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow remote server management through WinRM Service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow search highlights.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow search highlights" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow suggested apps in Windows Ink Workspace.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow suggested apps in Windows Ink Workspace" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Allow users to connect remotely by using Remote Desktop Services.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Allow users to connect remotely by using Remote Desktop Services" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Configuration of wireless settings using Windows Connect Now.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Configuration of wireless settings using Windows Connect Now" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Configure Watson events.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Configure Watson events" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Devices Prevent users from installing printer drivers when connecting to shared printers.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Devices Prevent users from installing printer drivers when connecting to shared printers" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disable Advertising ID.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disable Advertising ID" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disable Enterprise Auth Proxy.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disable Enterprise Auth Proxy" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disable One Drive File Sync.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disable One Drive File Sync" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disable Store Originated Apps.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disable Store Originated Apps" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disallow Cloud Notification.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disallow Cloud Notification" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disallow KMS Client Online AVS Validation.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disallow KMS Client Online AVS Validation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Disallow copying of user input methods to the system account for sign-in.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Disallow copying of user input methods to the system account for sign-in" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Do not allow COM port redirection.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Do not allow COM port redirection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Do not allow LPT port redirection.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Do not allow LPT port redirection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Do not allow supported Plug and Play device redirection.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Do not allow supported Plug and Play device redirection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Enable Convert Warn To Block.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Enable Convert Warn To Block" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Enable File Hash Computation.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Enable File Hash Computation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Join Microsoft MAPS.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Join Microsoft MAPS" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Log On As Batch Job.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Log On As Batch Job" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - MSS (DisableSavePassword) Prevent the dial up password from being saved (recommended).json |
On the device, this policy applies the "CISv4 - WIN - L2 - MSS (DisableSavePassword) Prevent the dial up password from being saved (recommended)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - MSS (KeepAliveTime) How often keep-alive packets are sent in milliseconds.json |
On the device, this policy applies the "CISv4 - WIN - L2 - MSS (KeepAliveTime) How often keep-alive packets are sent in milliseconds" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - MSS (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS).json |
On the device, this policy applies the "CISv4 - WIN - L2 - MSS (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - MSS (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted.json |
On the device, this policy applies the "CISv4 - WIN - L2 - MSS (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - MSS (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted.json |
On the device, this policy applies the "CISv4 - WIN - L2 - MSS (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Microsoft Support Diagnostic Tool Turn on MSDT interactive communication with support provider.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Microsoft Support Diagnostic Tool Turn on MSDT interactive communication with support provider" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Prevent Codec Download (User).json |
On the device, this policy applies the "CISv4 - WIN - L2 - Prevent Codec Download (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Prevent Internet Explorer security prompt for Windows Installer scripts.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Prevent Internet Explorer security prompt for Windows Installer scripts" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Prohibit access of the Windows Connect Now wizards.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Prohibit access of the Windows Connect Now wizards" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Remote Encryption Protection Aggressiveness.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Remote Encryption Protection Aggressiveness" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Restrict clipboard transfer from server to client.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Restrict clipboard transfer from server to client" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Set time limit for active but idle Remote Desktop Services sessions.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Set time limit for active but idle Remote Desktop Services sessions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Set time limit for disconnected sessions.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Set time limit for disconnected sessions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Support device authentication using certificate.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Support device authentication using certificate" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Help Experience Improvement Program (User).json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Help Experience Improvement Program (User)" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Push To Install service.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Push To Install service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Registration if URL connection is referring to Microsoft.com'.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Registration if URL connection is referring to Microsoft.com'" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Search Companion content file updates.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Search Companion content file updates" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Windows Customer Experience Improvement Program.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Windows Customer Experience Improvement Program" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off Windows Error Reporting.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off Windows Error Reporting" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off access to the Store.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off access to the Store" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off printing over HTTP.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off printing over HTTP" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off the Order Prints picture task.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off the Order Prints picture task" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off the Publish to Web.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off the Publish to Web" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off the Store application.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off the Store application" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn off the Windows Messenger Customer Experience Improvement Program.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn off the Windows Messenger Customer Experience Improvement Program" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn on Mapper IO (LLTDIO) driver.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn on Mapper IO (LLTDIO) driver" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn on PowerShell Script Block Logging.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn on PowerShell Script Block Logging" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn on PowerShell Transcription.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn on PowerShell Transcription" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Turn on Responder (RSPNDR) driver.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Turn on Responder (RSPNDR) driver" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Intune for Windows 11 Benchmarks/CISv4 - WIN - L2 - Upload User Activities.json |
On the device, this policy applies the "CISv4 - WIN - L2 - Upload User Activities" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Ads setting for sites with intrusive ads.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Ads setting for sites with intrusive ads" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow Basic authentication for HTTP.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow Basic authentication for HTTP" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow Google Cast to connect to Cast devices on all IP addresses.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow Google Cast to connect to Cast devices on all IP addresses" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow cross-origin HTTP Authentication prompts.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow cross-origin HTTP Authentication prompts" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow download restrictions.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow download restrictions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow import of data from other browsers on each Microsoft Edge launch.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow import of data from other browsers on each Microsoft Edge launch" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow importing of autofill form data.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow importing of autofill form data" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow importing of browser settings.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow importing of browser settings" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow importing of home page settings.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow importing of home page settings" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow importing of payment info.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow importing of payment info" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow importing of saved passwords.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow importing of saved passwords" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow importing of search engine settings.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow importing of search engine settings" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow managed extensions to use the Enterprise Hardware Platform API.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow managed extensions to use the Enterprise Hardware Platform API" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow queries to a Browser Network Time service.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow queries to a Browser Network Time service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow remote debugging.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow remote debugging" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow the audio sandbox to run.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow the audio sandbox to run" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow user feedback.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow user feedback" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Allow websites to query for available payment methods.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Allow websites to query for available payment methods" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Blocks external extensions from being installed.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Blocks external extensions from being installed" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Clear browsing data when Microsoft Edge closes.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Clear browsing data when Microsoft Edge closes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Clear cached images and files when Microsoft Edge closes.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Clear cached images and files when Microsoft Edge closes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Clear history for IE and IE mode every time you exit.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Clear history for IE and IE mode every time you exit" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Compose is enabled for writing on the web.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Compose is enabled for writing on the web" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure Edge Website Typo Protection.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure Edge Website Typo Protection" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure InPrivate mode availability.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure InPrivate mode availability" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure Microsoft Defender SmartScreen.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure Microsoft Defender SmartScreen" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure Related Matches in Find on Page.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure Related Matches in Find on Page" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure the Share experience.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure the Share experience" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure the list of names that will bypass the HSTS policy check.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure the list of names that will bypass the HSTS policy check" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure the list of types that are excluded from synchronization.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure the list of types that are excluded from synchronization" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Configure users ability to override feature flags.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Configure users ability to override feature flags" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Continue running background apps after Microsoft Edge closes.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Continue running background apps after Microsoft Edge closes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Control communication with the Experimentation and Configuration Service.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Control communication with the Experimentation and Configuration Service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Control use of insecure content exceptions.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Control use of insecure content exceptions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - DNS interception checks enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - DNS interception checks enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Delete old browser data on migration.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Delete old browser data on migration" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Disable saving browser history.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Disable saving browser history" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Disable synchronization of data using Microsoft sync services.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Disable synchronization of data using Microsoft sync services" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Edge 3P SERP Telemetry Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Edge 3P SERP Telemetry Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Edge Wallet E-Tree Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Edge Wallet E-Tree Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable AutoFill for addresses.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable AutoFill for addresses" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable AutoFill for payment instructions.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable AutoFill for payment instructions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable CryptoWallet feature.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable CryptoWallet feature" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable Discover access to page contents for AAD profiles.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable Discover access to page contents for AAD profiles" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable Follow service in Microsoft Edge.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable Follow service in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable Google Cast.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable Google Cast" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable Microsoft Defender SmartScreen DNS requests.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable Microsoft Defender SmartScreen DNS requests" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable browser legacy extension point blocking.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable browser legacy extension point blocking" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable component updates in Microsoft Edge.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable component updates in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable deleting browser and download history.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable deleting browser and download history" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable globally scoped HTTP auth cache.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable globally scoped HTTP auth cache" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable profile creation from the Identity flyout menu or the Settings page.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable profile creation from the Identity flyout menu or the Settings page" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable resolution of navigation errors using a web service.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable resolution of navigation errors using a web service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable saving passwords to the password manager.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable saving passwords to the password manager" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable security warnings for command-line flags.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable security warnings for command-line flags" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable site isolation for every site.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable site isolation for every site" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable startup boost.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable startup boost" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable tab organization suggestions.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable tab organization suggestions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable the Search bar.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable the Search bar" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable the linked account feature.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable the linked account feature" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable upload files from mobile in Microsoft Edge desktop.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable upload files from mobile in Microsoft Edge desktop" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable use of ephemeral profiles.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable use of ephemeral profiles" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enable warnings for insecure forms.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enable warnings for insecure forms" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Enables DALL-E themes generation.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Enables DALL-E themes generation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Guided Switch Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Guided Switch Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Hide the First-run experience and splash screen.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Hide the First-run experience and splash screen" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - In-app support Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - In-app support Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Manage exposure of local IP addresses by WebRTC.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Manage exposure of local IP addresses by WebRTC" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Prevent bypassing Microsoft Defender SmartScreen prompts for sites.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Prevent bypassing Microsoft Defender SmartScreen prompts for sites" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Set disk cache size, in bytes.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Set disk cache size, in bytes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Set the time period for update notifications.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Set the time period for update notifications" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Shopping in Microsoft Edge Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Shopping in Microsoft Edge Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Show Microsoft Rewards experiences.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Show Microsoft Rewards experiences" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Show the Reload in Internet Explorer mode button in the toolbar.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Show the Reload in Internet Explorer mode button in the toolbar" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Standalone Sidebar Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Standalone Sidebar Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Suggest similar pages when a webpage can’t be found.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Suggest similar pages when a webpage can’t be found" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Suppress the unsupported OS warning.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Suppress the unsupported OS warning" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Update policy override default.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Update policy override default" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 1 Benchmark/CISv3 - EDGE - L1 - Wallet Donation Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L1 - Wallet Donation Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow features to download assets from the Asset Delivery Service.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow features to download assets from the Asset Delivery Service" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow file selection dialogs.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow file selection dialogs" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow or block audio capture.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow or block audio capture" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow or deny screen capture.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow or deny screen capture" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow read access via the File System API on these sites.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow read access via the File System API on these sites" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow unconfigured sites to be reloaded in Internet Explorer mode.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow unconfigured sites to be reloaded in Internet Explorer mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow users to open files using the ClickOnce protocol.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow users to open files using the ClickOnce protocol" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow users to open files using the DirectInvoke protocol.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow users to open files using the DirectInvoke protocol" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Allow users to proceed from the HTTPS warning page.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Allow users to proceed from the HTTPS warning page" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - AutoLaunch Protocols Component Enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - AutoLaunch Protocols Component Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Block third party cookies.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Block third party cookies" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Browser sign-in settings.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Browser sign-in settings" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Configure Online Text To Speech.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Configure Online Text To Speech" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Configure Speech Recognition.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Configure Speech Recognition" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Configure extension management settings.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Configure extension management settings" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Configure the list of types that are excluded from synchronization.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Configure the list of types that are excluded from synchronization" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control use of JavaScript JIT.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control use of JavaScript JIT" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control use of the File System API for reading.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control use of the File System API for reading" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control use of the Headless Mode.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control use of the Headless Mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control use of the Serial API.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control use of the Serial API" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control use of the Web Bluetooth API.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control use of the Web Bluetooth API" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control use of the WebHID API.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control use of the WebHID API" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Control where security restrictions on insecure origins apply.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Control where security restrictions on insecure origins apply" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Default sensors setting.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Default sensors setting" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Default setting for third-party storage partitioning.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Default setting for third-party storage partitioning" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enable Drop feature in Microsoft Edge.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enable Drop feature in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enable QR Code Generator.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enable QR Code Generator" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enable Translate.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enable Translate" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enable guest mode.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enable guest mode" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enable search suggestions.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enable search suggestions" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enforce Bing SafeSearch.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enforce Bing SafeSearch" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enforce Google SafeSearch.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enforce Google SafeSearch" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Enhanced Security Mode configuration for Intranet zone sites.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Enhanced Security Mode configuration for Intranet zone sites" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Let users snip a Math problem and get the solution with a step-by-step explanation.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Let users snip a Math problem and get the solution with a step-by-step explanation" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Live captions allowed.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Live captions allowed" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Show an Always open checkbox in external protocol dialog.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Show an Always open checkbox in external protocol dialog" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Specify if online OCSPCRL checks are required for local trust anchors.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Specify if online OCSPCRL checks are required for local trust anchors" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Spell checking provided by Microsoft Editor.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Spell checking provided by Microsoft Editor" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Supported authentication schemes.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Supported authentication schemes" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Tab Services enabled.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Tab Services enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Microsoft Edge Level 1 and Level 2 Benchmarks/CISv3 Microsoft Edge Level 2 Benchmark/CISv3 - EDGE - L2 - Text prediction enabled by default.json |
On the device, this policy applies the "CISv3 - EDGE - L2 - Text prediction enabled by default" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Visual Studio Code/CISv1 - VS Code - L1 - Ensure ChatToolsAutoApprove' is set to Disabled.json |
On the device, this policy applies the "CISv1 - VS Code - L1 - Ensure ChatToolsAutoApprove' is set to Disabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Visual Studio Code/CISv1 - VS Code - L1 - Ensure TelemetryLevel is set to Enabled.json |
On the device, this policy applies the "CISv1 - VS Code - L1 - Ensure TelemetryLevel is set to Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Visual Studio Code/CISv1 - VS Code - L1 - Ensure UpdateMode is set to Enabled.json |
On the device, this policy applies the "CISv1 - VS Code - L1 - Ensure UpdateMode is set to Enabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Visual Studio Code/CISv1 - VS Code - L2 - Ensure AllowedExtensions is configured.json |
On the device, this policy applies the "CISv1 - VS Code - L2 - Ensure AllowedExtensions is configured" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Visual Studio Code/CISv1 - VS Code - L2 - Ensure ChatMCP is set to Disabled.json |
On the device, this policy applies the "CISv1 - VS Code - L2 - Ensure ChatMCP is set to Disabled" setting from Intune and enforces the configured behavior for that feature. |
CIS Benchmarks/CIS - Visual Studio Code/CISv1 - VS Code - L2 - Ensure EnableFeedback is set to Disabled.json |
On the device, this policy applies the "CISv1 - VS Code - L2 - Ensure EnableFeedback is set to Disabled" setting from Intune and enforces the configured behavior for that feature. |
ISO-IEC 27001-2022/Microsoft Edge/Microsoft Edge - ISO_IEC 27001_2022_2026-07-27T18_56_14.527Z.json |
On the device, this policy applies the "Microsoft Edge - ISO IEC 27001 2022" setting from Intune and enforces the configured behavior for that feature. |
Linux Benchmarks/Linux Compliance/Baseline - Linux - Device Encryption.json |
On the device, this policy applies the "Baseline - Linux - Device Encryption" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - Defender for Endpoint Linux .json |
On the device, this policy applies the "Baseline - Defender for Endpoint Linux" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - MDE Device Tag.json |
On the device, this policy applies the "Baseline - MDE Device Tag" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - MDE Enable file hash computation feature.json |
On the device, this policy applies the "Baseline - MDE Enable file hash computation feature" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - Microsoft Defender Antivirus.json |
On the device, this policy applies the "Baseline - Microsoft Defender Antivirus" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - Microsoft Defender Update controls.json |
On the device, this policy applies the "Baseline - Microsoft Defender Update controls" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - Smartscreen Enhanced Phishing Protection Audit Mode.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection Audit Mode" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - Smartscreen Enhanced Phishing Protection Block Mode.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection Block Mode" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Defender for Endpoint/Baseline - Windows Defender Security Experience.json |
On the device, this policy applies the "Baseline - Windows Defender Security Experience" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block Adobe Reader from creating child processes.json |
On the device, this policy applies the "ASR - AUDIT - Block Adobe Reader from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block JavaScript or VBScript from launching downloaded executable content.json |
On the device, this policy applies the "ASR - AUDIT - Block JavaScript or VBScript from launching downloaded executable content" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block Office applications from creating executable content.json |
On the device, this policy applies the "ASR - AUDIT - Block Office applications from creating executable content" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block Office communication application from creating child processes.json |
On the device, this policy applies the "ASR - AUDIT - Block Office communication application from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block Win32 API calls from Office macros.json |
On the device, this policy applies the "ASR - AUDIT - Block Win32 API calls from Office macros" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block abuse of exploited vulnerable signed drivers (Device).json |
On the device, this policy applies the "ASR - AUDIT - Block abuse of exploited vulnerable signed drivers (Device)" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block all Office applications from creating child processes.json |
On the device, this policy applies the "ASR - AUDIT - Block all Office applications from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block credential stealing from the Windows local security authority subsystem.json |
On the device, this policy applies the "ASR - AUDIT - Block credential stealing from the Windows local security authority subsystem" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block executable content from email client and webmail.json |
On the device, this policy applies the "ASR - AUDIT - Block executable content from email client and webmail" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block executable files from running unless they meet a prevalence.json |
On the device, this policy applies the "ASR - AUDIT - Block executable files from running unless they meet a prevalence" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block execution of potentially obfuscated scripts.json |
On the device, this policy applies the "ASR - AUDIT - Block execution of potentially obfuscated scripts" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block persistence through WMI event subscription.json |
On the device, this policy applies the "ASR - AUDIT - Block persistence through WMI event subscription" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block rebooting machine in Safe Mode.json |
On the device, this policy applies the "ASR - AUDIT - Block rebooting machine in Safe Mode" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Block untrusted and unsigned processes that run from USB.json |
On the device, this policy applies the "ASR - AUDIT - Block untrusted and unsigned processes that run from USB" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Enable Controlled Folder Access.json |
On the device, this policy applies the "ASR - AUDIT - Enable Controlled Folder Access" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Audit Policies/ASR - AUDIT - Use advanced protection against ransomware.json |
On the device, this policy applies the "ASR - AUDIT - Use advanced protection against ransomware" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block Adobe Reader from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block Adobe Reader from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block JavaScript or VBScript from launching downloaded executable content.json |
On the device, this policy applies the "ASR - BLOCK - Block JavaScript or VBScript from launching downloaded executable content" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block Office applications from creating executable content.json |
On the device, this policy applies the "ASR - BLOCK - Block Office applications from creating executable content" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block Office communication application from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block Office communication application from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block Win32 API calls from Office macros.json |
On the device, this policy applies the "ASR - BLOCK - Block Win32 API calls from Office macros" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block abuse of exploited vulnerable signed drivers (Device).json |
On the device, this policy applies the "ASR - BLOCK - Block abuse of exploited vulnerable signed drivers (Device)" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block all Office applications from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block all Office applications from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block credential stealing from the Windows local security authority subsystem.json |
On the device, this policy applies the "ASR - BLOCK - Block credential stealing from the Windows local security authority subsystem" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block executable content from email client and webmail.json |
On the device, this policy applies the "ASR - BLOCK - Block executable content from email client and webmail" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block executable files from running unless they meet a prevalence.json |
On the device, this policy applies the "ASR - BLOCK - Block executable files from running unless they meet a prevalence" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block execution of potentially obfuscated scripts.json |
On the device, this policy applies the "ASR - BLOCK - Block execution of potentially obfuscated scripts" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block persistence through WMI event subscription.json |
On the device, this policy applies the "ASR - BLOCK - Block persistence through WMI event subscription" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block rebooting machine in Safe Mode.json |
On the device, this policy applies the "ASR - BLOCK - Block rebooting machine in Safe Mode" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Block untrusted and unsigned processes that run from USB.json |
On the device, this policy applies the "ASR - BLOCK - Block untrusted and unsigned processes that run from USB" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Enable Controlled Folder Access.json |
On the device, this policy applies the "ASR - BLOCK - Enable Controlled Folder Access" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Attack Surface Reduction/Block Policies/ASR - BLOCK - Use advanced protection against ransomware.json |
On the device, this policy applies the "ASR - BLOCK - Use advanced protection against ransomware" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Bitlocker en Personal Data Encryption/Baseline - Bitlocker Policy.json |
On the device, this policy applies the "Baseline - Bitlocker Policy" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Bitlocker en Personal Data Encryption/Baseline - Personal Data Encryption.json |
On the device, this policy applies the "Baseline - Personal Data Encryption" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Browser Protection/Baseline - Chrome Microsoft Defender Browser Protection.json |
On the device, this policy applies the "Baseline - Chrome Microsoft Defender Browser Protection" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Browser Protection/Baseline - Scareware Blocker in Microsoft Edge.json |
On the device, this policy applies the "Baseline - Scareware Blocker in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Browser Protection/Baseline - Smartscreen Enhanced Phishing Protection.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Endpoint Protection/Baseline - Account Protection.json |
On the device, this policy applies the "Baseline - Account Protection" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Endpoint Protection/Baseline - App and Browser Isolation.json |
On the device, this policy applies the "Baseline - App and Browser Isolation" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Endpoint Protection/Baseline - Device Control.json |
On the device, this policy applies the "Baseline - Device Control" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/FIDO/Baseline - Enables FIDO Security Keys to be used during Windows Sign In -1.json |
On the device, this policy applies the "Baseline - Enables FIDO Security Keys to be used during Windows Sign In -1" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Firewall/Baseline - MacOS - Firewall.json |
On the device, this policy applies the "Baseline - MacOS - Firewall" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Firewall/Baseline - Windows - Firewall.json |
On the device, this policy applies the "Baseline - Windows - Firewall" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Intune Default Security Baselines/Baseline - Intune Security Baseline - Microsoft Edge.json |
On the device, this policy applies the "Baseline - Intune Security Baseline - Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Intune Default Security Baselines/Baseline - Intune Security Baseline - Windows 365.json |
On the device, this policy applies the "Baseline - Intune Security Baseline - Windows 365" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Intune Default Security Baselines/Baseline - Intune Security Baseline - Windows Defender Security Experience.json |
On the device, this policy applies the "Baseline - Intune Security Baseline - Windows Defender Security Experience" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Intune Default Security Baselines/Baseline - Intune Security Baseline -Windows 11.json |
On the device, this policy applies the "Baseline - Intune Security Baseline -Windows 11" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Windows Hello for Business/Baseline - WHFB Exclude Security Devices TPM 1.2 .json |
On the device, this policy applies the "Baseline - WHFB Exclude Security Devices TPM 1.2" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Windows Hello for Business/Baseline - WHFB Disable Post Logon Provisioning.json |
On the device, this policy applies the "Baseline - WHFB Disable Post Logon Provisioning" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Windows Hello for Business/Baseline - WHFB Muti-Factor unlock Template config.json |
On the device, this policy applies the "Baseline - WHFB Muti-Factor unlock Template config" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Windows Hello for Business/Baseline - WHFB Require Security Device.json |
On the device, this policy applies the "Baseline - WHFB Require Security Device" setting from Intune and enforces the configured behavior for that feature. |
Microsoft Endpoint Security Benchmarks/Microsoft Endpoint Security Benchmarks/Windows Hyper-v/Baseline - Windows with Hyper-v - Firewall.json |
On the device, this policy applies the "Baseline - Windows with Hyper-v - Firewall" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block Adobe Reader from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block Adobe Reader from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block JavaScript or VBScript from launching downloaded executable content.json |
On the device, this policy applies the "ASR - BLOCK - Block JavaScript or VBScript from launching downloaded executable content" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block Office applications from creating executable content.json |
On the device, this policy applies the "ASR - BLOCK - Block Office applications from creating executable content" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block Office communication application from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block Office communication application from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block Win32 API calls from Office macros.json |
On the device, this policy applies the "ASR - BLOCK - Block Win32 API calls from Office macros" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block abuse of exploited vulnerable signed drivers (Device).json |
On the device, this policy applies the "ASR - BLOCK - Block abuse of exploited vulnerable signed drivers (Device)" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block all Office applications from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block all Office applications from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block credential stealing from the Windows local security authority subsystem.json |
On the device, this policy applies the "ASR - BLOCK - Block credential stealing from the Windows local security authority subsystem" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block executable content from email client and webmail.json |
On the device, this policy applies the "ASR - BLOCK - Block executable content from email client and webmail" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block executable files from running unless they meet a prevalence.json |
On the device, this policy applies the "ASR - BLOCK - Block executable files from running unless they meet a prevalence" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block execution of potentially obfuscated scripts.json |
On the device, this policy applies the "ASR - BLOCK - Block execution of potentially obfuscated scripts" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block persistence through WMI event subscription.json |
On the device, this policy applies the "ASR - BLOCK - Block persistence through WMI event subscription" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block rebooting machine in Safe Mode.json |
On the device, this policy applies the "ASR - BLOCK - Block rebooting machine in Safe Mode" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Block untrusted and unsigned processes that run from USB.json |
On the device, this policy applies the "ASR - BLOCK - Block untrusted and unsigned processes that run from USB" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Enable Controlled Folder Access.json |
On the device, this policy applies the "ASR - BLOCK - Enable Controlled Folder Access" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/ASR - BLOCK - Use advanced protection against ransomware.json |
On the device, this policy applies the "ASR - BLOCK - Use advanced protection against ransomware" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - WHFB Exclude Security Devices TPM 1.2 .json |
On the device, this policy applies the "Baseline - WHFB Exclude Security Devices TPM 1.2" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Account Protection.json |
On the device, this policy applies the "Baseline - Account Protection" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Bitlocker Policy.json |
On the device, this policy applies the "Baseline - Bitlocker Policy" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Block add MSA accounts and non-MSA accounts.json |
On the device, this policy applies the "Baseline - Block add MSA accounts and non-MSA accounts" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Cloud Remediation quick machine recovery.json |
On the device, this policy applies the "Baseline - Cloud Remediation quick machine recovery" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Configure Outlook profile .json |
On the device, this policy applies the "Baseline - Configure Outlook profile" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Configure Searchbar on taskbar.json |
On the device, this policy applies the "Baseline - Configure Searchbar on taskbar" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Delivery Optimization.json |
On the device, this policy applies the "Baseline - Delivery Optimization" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Disable Xbox services.json |
On the device, this policy applies the "Baseline - Disable Xbox services" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Edge - Control whether TLS 1.3 Early Data is enabled in Microsoft Edge_2025-09-01T08_16_43.911Z.json |
On the device, this policy applies the "Baseline - Edge - Control whether TLS 1.3 Early Data is enabled in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Edge - Use Primary Work Profile as default to open external links_2025-09-01T08_16_48.549Z.json |
On the device, this policy applies the "Baseline - Edge - Use Primary Work Profile as default to open external links" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Enable Local Administrator Account.json |
On the device, this policy applies the "Baseline - Enable Local Administrator Account" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Enable Windows Backup_2025-09-01T08_19_23.564Z.json |
On the device, this policy applies the "Baseline - Enable Windows Backup" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Enables FIDO Security Keys to be used during Windows Sign In -1.json |
On the device, this policy applies the "Baseline - Enables FIDO Security Keys to be used during Windows Sign In -1" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - One Drive management settings.json |
On the device, this policy applies the "Baseline - One Drive management settings" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Scareware Blocker in Microsoft Edge.json |
On the device, this policy applies the "Baseline - Scareware Blocker in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Smartscreen Enhanced Phishing Protection.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Storage Sense.json |
On the device, this policy applies the "Baseline - Storage Sense" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Teams - File links open preference default selection as Desktop App.json |
On the device, this policy applies the "Baseline - Teams - File links open preference default selection as Desktop App" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Teams - Prevent Microsoft Teams from starting automatically after installation.json |
On the device, this policy applies the "Baseline - Teams - Prevent Microsoft Teams from starting automatically after installation" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Universal Print Provisioning.json |
On the device, this policy applies the "Baseline - Universal Print Provisioning" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows - Compliancs Device Health.json |
On the device, this policy applies the "Baseline - Windows - Compliancs Device Health" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows - Device Properties.json |
On the device, this policy applies the "Baseline - Windows - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows - Firewall.json |
On the device, this policy applies the "Baseline - Windows - Firewall" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows - System Security with Defender.json |
On the device, this policy applies the "Baseline - Windows - System Security with Defender" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows 11 Taskbar .json |
On the device, this policy applies the "Baseline - Windows 11 Taskbar" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows AI - Default App for Copilot key on keyboard.json |
On the device, this policy applies the "Baseline - Windows AI - Default App for Copilot key on keyboard" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows OneDrive automatically.json |
On the device, this policy applies the "Baseline - Windows OneDrive automatically" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows Power Settings.json |
On the device, this policy applies the "Baseline - Windows Power Settings" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Associate Baseline/Baseline - Windows health monitoring.json |
On the device, this policy applies the "Baseline - Windows health monitoring" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block Adobe Reader from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block Adobe Reader from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block JavaScript or VBScript from launching downloaded executable content.json |
On the device, this policy applies the "ASR - BLOCK - Block JavaScript or VBScript from launching downloaded executable content" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block Office applications from creating executable content.json |
On the device, this policy applies the "ASR - BLOCK - Block Office applications from creating executable content" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block Office communication application from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block Office communication application from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block Win32 API calls from Office macros.json |
On the device, this policy applies the "ASR - BLOCK - Block Win32 API calls from Office macros" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block abuse of exploited vulnerable signed drivers (Device).json |
On the device, this policy applies the "ASR - BLOCK - Block abuse of exploited vulnerable signed drivers (Device)" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block all Office applications from creating child processes.json |
On the device, this policy applies the "ASR - BLOCK - Block all Office applications from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block credential stealing from the Windows local security authority subsystem.json |
On the device, this policy applies the "ASR - BLOCK - Block credential stealing from the Windows local security authority subsystem" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block executable content from email client and webmail.json |
On the device, this policy applies the "ASR - BLOCK - Block executable content from email client and webmail" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block executable files from running unless they meet a prevalence.json |
On the device, this policy applies the "ASR - BLOCK - Block executable files from running unless they meet a prevalence" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block execution of potentially obfuscated scripts.json |
On the device, this policy applies the "ASR - BLOCK - Block execution of potentially obfuscated scripts" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block persistence through WMI event subscription.json |
On the device, this policy applies the "ASR - BLOCK - Block persistence through WMI event subscription" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block rebooting machine in Safe Mode.json |
On the device, this policy applies the "ASR - BLOCK - Block rebooting machine in Safe Mode" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Block untrusted and unsigned processes that run from USB.json |
On the device, this policy applies the "ASR - BLOCK - Block untrusted and unsigned processes that run from USB" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Enable Controlled Folder Access.json |
On the device, this policy applies the "ASR - BLOCK - Enable Controlled Folder Access" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/ASR - BLOCK - Use advanced protection against ransomware.json |
On the device, this policy applies the "ASR - BLOCK - Use advanced protection against ransomware" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - WHFB Exclude Security Devices TPM 1.2 .json |
On the device, this policy applies the "Baseline - WHFB Exclude Security Devices TPM 1.2" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Account Protection.json |
On the device, this policy applies the "Baseline - Account Protection" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - App and Browser Isolation.json |
On the device, this policy applies the "Baseline - App and Browser Isolation" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Bitlocker Policy.json |
On the device, this policy applies the "Baseline - Bitlocker Policy" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Block add MSA accounts and non-MSA accounts.json |
On the device, this policy applies the "Baseline - Block add MSA accounts and non-MSA accounts" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Cloud Remediation quick machine recovery.json |
On the device, this policy applies the "Baseline - Cloud Remediation quick machine recovery" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Configure Outlook profile .json |
On the device, this policy applies the "Baseline - Configure Outlook profile" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Configure Searchbar on taskbar.json |
On the device, this policy applies the "Baseline - Configure Searchbar on taskbar" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Delivery Optimization.json |
On the device, this policy applies the "Baseline - Delivery Optimization" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Device Control.json |
On the device, this policy applies the "Baseline - Device Control" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Disable Xbox services.json |
On the device, this policy applies the "Baseline - Disable Xbox services" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Edge - Control whether TLS 1.3 Early Data is enabled in Microsoft Edge_2025-09-01T08_16_43.911Z.json |
On the device, this policy applies the "Baseline - Edge - Control whether TLS 1.3 Early Data is enabled in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Edge - Specify extensions users must allow in order to navigate using InPrivate mode_2025-09-01T08_16_28.644Z.json |
On the device, this policy applies the "Baseline - Edge - Specify extensions users must allow in order to navigate using InPrivate mode" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Edge - Use Primary Work Profile as default to open external links_2025-09-01T08_16_48.549Z.json |
On the device, this policy applies the "Baseline - Edge - Use Primary Work Profile as default to open external links" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Enable Local Administrator Account.json |
On the device, this policy applies the "Baseline - Enable Local Administrator Account" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Enable Windows Backup_2025-09-01T08_19_23.564Z.json |
On the device, this policy applies the "Baseline - Enable Windows Backup" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Enables FIDO Security Keys to be used during Windows Sign In -1.json |
On the device, this policy applies the "Baseline - Enables FIDO Security Keys to be used during Windows Sign In -1" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - One Drive management settings.json |
On the device, this policy applies the "Baseline - One Drive management settings" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Personal Data Encryption.json |
On the device, this policy applies the "Baseline - Personal Data Encryption" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Prevent Microsoft Teams from starting automatically after installation.json |
On the device, this policy applies the "Baseline - Prevent Microsoft Teams from starting automatically after installation" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Require Network In OOBE.json |
On the device, this policy applies the "Baseline - Require Network In OOBE" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - SSL Cipher Suite Order.json |
On the device, this policy applies the "Baseline - SSL Cipher Suite Order" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Scareware Blocker in Microsoft Edge.json |
On the device, this policy applies the "Baseline - Scareware Blocker in Microsoft Edge" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - SkipUserStatusPage ESP.json |
On the device, this policy applies the "Baseline - SkipUserStatusPage ESP" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Smartscreen Enhanced Phishing Protection.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Storage Sense.json |
On the device, this policy applies the "Baseline - Storage Sense" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Teams - File links open preference default selection as Desktop App.json |
On the device, this policy applies the "Baseline - Teams - File links open preference default selection as Desktop App" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Teams - Prevent Microsoft Teams from starting automatically after installation.json |
On the device, this policy applies the "Baseline - Teams - Prevent Microsoft Teams from starting automatically after installation" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Universal Print Provisioning.json |
On the device, this policy applies the "Baseline - Universal Print Provisioning" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - WHFB Disable Post Logon Provisioning.json |
On the device, this policy applies the "Baseline - WHFB Disable Post Logon Provisioning" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - WHFB Muti-Factor unlock Template config.json |
On the device, this policy applies the "Baseline - WHFB Muti-Factor unlock Template config" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - WHFB Require Security Device.json |
On the device, this policy applies the "Baseline - WHFB Require Security Device" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows - Compliancs Device Health.json |
On the device, this policy applies the "Baseline - Windows - Compliancs Device Health" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows - Device Properties.json |
On the device, this policy applies the "Baseline - Windows - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows - Firewall.json |
On the device, this policy applies the "Baseline - Windows - Firewall" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows - Microsoft Defender for Endpoint Risk score.json |
On the device, this policy applies the "Baseline - Windows - Microsoft Defender for Endpoint Risk score" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows - System Security with Defender.json |
On the device, this policy applies the "Baseline - Windows - System Security with Defender" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows 11 Taskbar .json |
On the device, this policy applies the "Baseline - Windows 11 Taskbar" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows AI - Default App for Copilot key on keyboard.json |
On the device, this policy applies the "Baseline - Windows AI - Default App for Copilot key on keyboard" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows OneDrive automatically.json |
On the device, this policy applies the "Baseline - Windows OneDrive automatically" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows Power Settings.json |
On the device, this policy applies the "Baseline - Windows Power Settings" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Expert Baseline/Baseline - Windows health monitoring.json |
On the device, this policy applies the "Baseline - Windows health monitoring" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block Adobe Reader from creating child processes.json |
On the device, this policy applies the "ASR - AUDIT - Block Adobe Reader from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block JavaScript or VBScript from launching downloaded executable content.json |
On the device, this policy applies the "ASR - AUDIT - Block JavaScript or VBScript from launching downloaded executable content" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block Office applications from creating executable content.json |
On the device, this policy applies the "ASR - AUDIT - Block Office applications from creating executable content" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block Office communication application from creating child processes.json |
On the device, this policy applies the "ASR - AUDIT - Block Office communication application from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block Win32 API calls from Office macros.json |
On the device, this policy applies the "ASR - AUDIT - Block Win32 API calls from Office macros" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block abuse of exploited vulnerable signed drivers (Device).json |
On the device, this policy applies the "ASR - AUDIT - Block abuse of exploited vulnerable signed drivers (Device)" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block all Office applications from creating child processes.json |
On the device, this policy applies the "ASR - AUDIT - Block all Office applications from creating child processes" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block credential stealing from the Windows local security authority subsystem.json |
On the device, this policy applies the "ASR - AUDIT - Block credential stealing from the Windows local security authority subsystem" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block executable content from email client and webmail.json |
On the device, this policy applies the "ASR - AUDIT - Block executable content from email client and webmail" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block executable files from running unless they meet a prevalence.json |
On the device, this policy applies the "ASR - AUDIT - Block executable files from running unless they meet a prevalence" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block execution of potentially obfuscated scripts.json |
On the device, this policy applies the "ASR - AUDIT - Block execution of potentially obfuscated scripts" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block persistence through WMI event subscription.json |
On the device, this policy applies the "ASR - AUDIT - Block persistence through WMI event subscription" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block rebooting machine in Safe Mode.json |
On the device, this policy applies the "ASR - AUDIT - Block rebooting machine in Safe Mode" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Block untrusted and unsigned processes that run from USB.json |
On the device, this policy applies the "ASR - AUDIT - Block untrusted and unsigned processes that run from USB" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Enable Controlled Folder Access.json |
On the device, this policy applies the "ASR - AUDIT - Enable Controlled Folder Access" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/ASR - AUDIT - Use advanced protection against ransomware.json |
On the device, this policy applies the "ASR - AUDIT - Use advanced protection against ransomware" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Bitlocker Policy.json |
On the device, this policy applies the "Baseline - Bitlocker Policy" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Block add MSA accounts and non-MSA accounts.json |
On the device, this policy applies the "Baseline - Block add MSA accounts and non-MSA accounts" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Configure Outlook profile .json |
On the device, this policy applies the "Baseline - Configure Outlook profile" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Disable Xbox services.json |
On the device, this policy applies the "Baseline - Disable Xbox services" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Edge - Use Primary Work Profile as default to open external links_2025-09-01T08_16_48.549Z.json |
On the device, this policy applies the "Baseline - Edge - Use Primary Work Profile as default to open external links" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Enable Local Administrator Account.json |
On the device, this policy applies the "Baseline - Enable Local Administrator Account" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Enable Windows Backup_2025-09-01T08_19_23.564Z.json |
On the device, this policy applies the "Baseline - Enable Windows Backup" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - One Drive management settings.json |
On the device, this policy applies the "Baseline - One Drive management settings" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Smartscreen Enhanced Phishing Protection.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows - Compliancs Device Health.json |
On the device, this policy applies the "Baseline - Windows - Compliancs Device Health" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows - Device Properties.json |
On the device, this policy applies the "Baseline - Windows - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows - Firewall.json |
On the device, this policy applies the "Baseline - Windows - Firewall" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows 11 Taskbar .json |
On the device, this policy applies the "Baseline - Windows 11 Taskbar" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows AI - Default App for Copilot key on keyboard.json |
On the device, this policy applies the "Baseline - Windows AI - Default App for Copilot key on keyboard" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows OneDrive automatically.json |
On the device, this policy applies the "Baseline - Windows OneDrive automatically" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows Power Settings.json |
On the device, this policy applies the "Baseline - Windows Power Settings" setting from Intune and enforces the configured behavior for that feature. |
Modern Workplace Fundamentals Baseline/Baseline - Windows health monitoring.json |
On the device, this policy applies the "Baseline - Windows health monitoring" setting from Intune and enforces the configured behavior for that feature. |
NIS2 20222-555 (Europe)/Microsoft Edge/Microsoft Edge - NIS2 - 2022_2555_2026-07-27T19_12_15.278Z.json |
On the device, this policy applies the "Microsoft Edge - NIS2 - 2022 2555" setting from Intune and enforces the configured behavior for that feature. |
NIS2 20222-555 (Europe)/Windows 11/Microsoft Windows 11 - NIS2 - 2022_2555_2026-07-27T19_05_31.178Z.json |
On the device, this policy applies the "Microsoft Windows 11 - NIS2 - 2022 2555" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Allow only company domain accounts.json |
On the device, this policy applies the "Baseline - Visual Studio - Allow only company domain accounts" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Disable Agent Mode.json |
On the device, this policy applies the "Baseline - Visual Studio - Disable Agent Mode" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Disable Copilot.json |
On the device, this policy applies the "Baseline - Visual Studio - Disable Copilot" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Disable IntelliCode custom model training.json |
On the device, this policy applies the "Baseline - Visual Studio - Disable IntelliCode custom model training" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Disable dev tunnels in Visual Studio.json |
On the device, this policy applies the "Baseline - Visual Studio - Disable dev tunnels in Visual Studio" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Disable the send-a-smile feature.json |
On the device, this policy applies the "Baseline - Visual Studio - Disable the send-a-smile feature" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Disable update notifications in Visual Studio.json |
On the device, this policy applies the "Baseline - Visual Studio - Disable update notifications in Visual Studio" setting from Intune and enforces the configured behavior for that feature. |
Visual Studio Benchmarks/Baseline - Visual Studio - Remove out-of-support components during updates.json |
On the device, this policy applies the "Baseline - Visual Studio - Remove out-of-support components during updates" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Block add MSA accounts and non-MSA accounts.json |
On the device, this policy applies the "Baseline - Block add MSA accounts and non-MSA accounts" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Chrome Password manager and protection configuration.json |
On the device, this policy applies the "Baseline - Chrome Password manager and protection configuration" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Cloud Remediation quick machine recovery.json |
On the device, this policy applies the "Baseline - Cloud Remediation quick machine recovery" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Configure Outlook profile .json |
On the device, this policy applies the "Baseline - Configure Outlook profile" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Configure Searchbar on taskbar.json |
On the device, this policy applies the "Baseline - Configure Searchbar on taskbar" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Configure Teams Chat icon.json |
On the device, this policy applies the "Baseline - Configure Teams Chat icon" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Configure Windows protected print.json |
On the device, this policy applies the "Baseline - Configure Windows protected print" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Delivery Optimization.json |
On the device, this policy applies the "Baseline - Delivery Optimization" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Disable Web Distribution App Installation EU.json |
On the device, this policy applies the "Baseline - Disable Web Distribution App Installation EU" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Disable Xbox services.json |
On the device, this policy applies the "Baseline - Disable Xbox services" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Edge Password manager and protection configuration.json |
On the device, this policy applies the "Baseline - Edge Password manager and protection configuration" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Enable Guest account for secure assessment .json |
On the device, this policy applies the "Baseline - Enable Guest account for secure assessment" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Enable Local Administrator Account.json |
On the device, this policy applies the "Baseline - Enable Local Administrator Account" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Enable Shared PC mode with OneDrive sync.json |
On the device, this policy applies the "Baseline - Enable Shared PC mode with OneDrive sync" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Enable Windows Backup_2025-09-01T08_19_23.564Z.json |
On the device, this policy applies the "Baseline - Enable Windows Backup" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Enable Xbox Game Save Task.json |
On the device, this policy applies the "Baseline - Enable Xbox Game Save Task" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Google Chrome Management.json |
On the device, this policy applies the "Baseline - Google Chrome Management" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - One Drive management settings.json |
On the device, this policy applies the "Baseline - One Drive management settings" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Prevent Microsoft Teams from starting automatically after installation.json |
On the device, this policy applies the "Baseline - Prevent Microsoft Teams from starting automatically after installation" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Require Network In OOBE.json |
On the device, this policy applies the "Baseline - Require Network In OOBE" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - SSL Cipher Suite Order.json |
On the device, this policy applies the "Baseline - SSL Cipher Suite Order" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Shared Multi-user device.json |
On the device, this policy applies the "Baseline - Shared Multi-user device" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - SkipUserStatusPage ESP.json |
On the device, this policy applies the "Baseline - SkipUserStatusPage ESP" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Smartscreen Enhanced Phishing Protection.json |
On the device, this policy applies the "Baseline - Smartscreen Enhanced Phishing Protection" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Storage Sense.json |
On the device, this policy applies the "Baseline - Storage Sense" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Turn Off Copilot in Windows (User).json |
On the device, this policy applies the "Baseline - Turn Off Copilot in Windows (User)" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Universal Print Provisioning.json |
On the device, this policy applies the "Baseline - Universal Print Provisioning" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Windows 11 Taskbar .json |
On the device, this policy applies the "Baseline - Windows 11 Taskbar" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Windows OneDrive automatically.json |
On the device, this policy applies the "Baseline - Windows OneDrive automatically" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Windows Power Settings.json |
On the device, this policy applies the "Baseline - Windows Power Settings" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Windows Sandbox.json |
On the device, this policy applies the "Baseline - Windows Sandbox" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Windows Subsystem For Linux.json |
On the device, this policy applies the "Baseline - Windows Subsystem For Linux" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Intune Modern Workplace Windows 11/Baseline - Windows health monitoring.json |
On the device, this policy applies the "Baseline - Windows health monitoring" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Microsoft Teams/Baseline - AVD - FSLogic Include Teams data.json |
On the device, this policy applies the "Baseline - AVD - FSLogic Include Teams data" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Microsoft Teams/Baseline - Teams - Don’t install Microsoft Teams with new installations or updates of Office.json |
On the device, this policy applies the "Baseline - Teams - Don’t install Microsoft Teams with new installations or updates of Office" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Microsoft Teams/Baseline - Teams - File links open preference default selection as Desktop App.json |
On the device, this policy applies the "Baseline - Teams - File links open preference default selection as Desktop App" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Microsoft Teams/Baseline - Teams - Prevent Microsoft Teams from starting automatically after installation.json |
On the device, this policy applies the "Baseline - Teams - Prevent Microsoft Teams from starting automatically after installation" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Microsoft Teams/Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants.json |
On the device, this policy applies the "Baseline - Teams - Restrict sign in to Teams to accounts in specific tenants" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows 11 Compliance/Baseline - Windows - Compliancs Device Health.json |
On the device, this policy applies the "Baseline - Windows - Compliancs Device Health" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows 11 Compliance/Baseline - Windows - Device Properties.json |
On the device, this policy applies the "Baseline - Windows - Device Properties" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows 11 Compliance/Baseline - Windows - Microsoft Defender for Endpoint Risk score.json |
On the device, this policy applies the "Baseline - Windows - Microsoft Defender for Endpoint Risk score" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows 11 Compliance/Baseline - Windows - System Security with Defender.json |
On the device, this policy applies the "Baseline - Windows - System Security with Defender" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows 11 Compliance/Baseline - Windows - System Security without Defender.json |
On the device, this policy applies the "Baseline - Windows - System Security without Defender" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Paint Generative Fill.json |
On the device, this policy applies the "Baseline - Windows AI - Paint Generative Fill" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Block Microsoft Recall.json |
On the device, this policy applies the "Baseline - Windows AI - Block Microsoft Recall" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Manage Microsoft Recall.json |
On the device, this policy applies the "Baseline - Windows AI - Manage Microsoft Recall" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Turn Off Copilot in Windows (User).json |
On the device, this policy applies the "Baseline - Windows AI - Turn Off Copilot in Windows (User)" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Block Microsoft Recall.json |
On the device, this policy applies the "Baseline - Windows AI - Block Microsoft Recall" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Copilot access to Microsoft Edge page content for Entra account.json |
On the device, this policy applies the "Baseline - Windows AI - Copilot access to Microsoft Edge page content for Entra account" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Default App for Copilot key on keyboard.json |
On the device, this policy applies the "Baseline - Windows AI - Default App for Copilot key on keyboard" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Disable Click To Do.json |
On the device, this policy applies the "Baseline - Windows AI - Disable Click To Do" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Disable GitHub Copilot for Individual.json |
On the device, this policy applies the "Baseline - Windows AI - Disable GitHub Copilot for Individual" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Disable GitHub Copilot.json |
On the device, this policy applies the "Baseline - Windows AI - Disable GitHub Copilot" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Enable Edge GenAI local foundational model .json |
On the device, this policy applies the "Baseline - Windows AI - Enable Edge GenAI local foundational model" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Enable Paint Cocreator.json |
On the device, this policy applies the "Baseline - Windows AI - Enable Paint Cocreator" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Paint Image Creator.json |
On the device, this policy applies the "Baseline - Windows AI - Paint Image Creator" setting from Intune and enforces the configured behavior for that feature. |
Windows 11 Benchmarks/Windows AI/Baseline - Windows AI - Settings Agent.json |
On the device, this policy applies the "Baseline - Windows AI - Settings Agent" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Configure H.265HEVC hardware encoding for RDP.json |
On the device, this policy applies the "Baseline - AVD - Configure H.265HEVC hardware encoding for RDP" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Enable RDP Shortpath for managed network using NAT traversal.json |
On the device, this policy applies the "Baseline - AVD - Enable RDP Shortpath for managed network using NAT traversal" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Enable RDP Shortpath for managed networks.json |
On the device, this policy applies the "Baseline - AVD - Enable RDP Shortpath for managed networks" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Enable RDP Shortpath for public network using NAT traversal.json |
On the device, this policy applies the "Baseline - AVD - Enable RDP Shortpath for public network using NAT traversal" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Enable RDP Shortpath for public network using Relay (TURN).json |
On the device, this policy applies the "Baseline - AVD - Enable RDP Shortpath for public network using Relay (TURN)" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Enable screen capture protection.json |
On the device, this policy applies the "Baseline - AVD - Enable screen capture protection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Enable watermarking.json |
On the device, this policy applies the "Baseline - AVD - Enable watermarking" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - FSLogic Include Teams data.json |
On the device, this policy applies the "Baseline - AVD - FSLogic Include Teams data" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Azure Virtual Desktop/Baseline - AVD - Use port range for RDP Shortpath for unmanaged networks.json |
On the device, this policy applies the "Baseline - AVD - Use port range for RDP Shortpath for unmanaged networks" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Allow audio and video playback redirection.json |
On the device, this policy applies the "Baseline - Win365 - Allow audio and video playback redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Allow audio recording redirection.json |
On the device, this policy applies the "Baseline - Win365 - Allow audio recording redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow COM port redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow COM port redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow Clipboard redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow Clipboard redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow client printer redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow client printer redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow drive redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow drive redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow smart card device redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow smart card device redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow supported Plug and Play device redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow supported Plug and Play device redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Do not allow video capture redirection.json |
On the device, this policy applies the "Baseline - Win365 - Do not allow video capture redirection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Enable screen capture protection.json |
On the device, this policy applies the "Baseline - Win365 - Enable screen capture protection" setting from Intune and enforces the configured behavior for that feature. |
Windows Cloud PC and AVD/Windows 365 Cloud PC/Baseline - Win365 - Enable watermarking.json |
On the device, this policy applies the "Baseline - Win365 - Enable watermarking" setting from Intune and enforces the configured behavior for that feature. |