INTUNE-017: Security baselines compliance
- Plataforma
- Entra ID / M365
- Categoría
- Intune / Endpoint Management
- Severidad
- High
- Pilar de Zero Trust
- Devices (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Microsoft security baselines in Intune provide pre-configured groups of Windows settings recommended by Microsoft security teams, covering areas such as credential protection, browser security, and attack surface reduction. Devices that deviate from the security baseline have weakened security postures and may be vulnerable to known attack vectors. Monitoring baseline compliance identifies configuration drift and helps maintain a consistent security posture.
Valor recomendado
90% or higher compliance with assigned security baselines; all conflict and error states resolved
Remediación
Deploy the latest Microsoft security baseline profile for Windows and Defender for Endpoint to all managed devices and monitor the per-setting compliance status. Investigate settings reporting conflict or error states, as these often indicate competing policies that need to be reconciled. Address non-compliant settings by evaluating whether the deviation is due to a legitimate business requirement that warrants a documented exception or a configuration issue that should be corrected.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- CM-6, SI-2