INTUNE-005: Configuration profile assignment analysis

Platform
Entra ID / M365
Category
Intune / Endpoint Management
Severity
Medium
Zero Trust pillar
Devices (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Configuration profiles are only effective when properly assigned to the correct device or user groups. Profiles assigned to overly broad groups may cause conflicts or apply settings to inappropriate devices, while narrowly assigned profiles may leave devices unconfigured. Analyzing assignment coverage ensures that security configurations reach all intended endpoints without conflicts.

Recommended value

All security-critical profiles assigned to appropriate groups with no unassigned critical profiles and no conflicting assignments

Remediation

Review the assignment status and target groups for each configuration profile, paying attention to profiles with errors or conflicts. Resolve any profile conflicts by adjusting assignments, merging similar profiles, or using filters to target specific device characteristics. Ensure security-critical profiles such as BitLocker, firewall, and antivirus settings are assigned to all applicable devices through comprehensive group membership.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for INTUNE-005
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
CM-6