We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Security baselines
Intune security baselines

Deploying the Microsoft baseline does not make you CIS compliant, and Microsoft states that outright.

Asked directly whether these baselines amount to CIS or NIST compliance, the published answer is that strictly speaking they do not, because no one-to-one mapping exists between them. They are an excellent place to start, assembled by the same team that writes the group policy baselines, and they are not a certification. Where a customer questionnaire or an auditor has asked specifically for CIS, that distinction is the entire conversation.

Book a baseline reviewSee the available baselines
Intune security baselines for US organizations
  • Not CISMicrosoft's own answer, stated plainly
  • Most restrictiveBaseline defaults, by design
  • Not for VDIThe Defender baseline, per Microsoft
  • Read-onlyOlder profile versions, once superseded
The compliance conversation this page exists to correct

A baseline is a starting point, not a certification.

This comes up constantly, usually when somebody has told a client, a SOC 2 auditor or a cyber insurance carrier that the estate is CIS hardened because a baseline was deployed.

  • The question gets answered directly in the documentation. Are these baselines CIS or NIST compliant? Strictly speaking, no. The explanation given is that bodies such as CIS are consulted while compiling the recommendations, and that no one-to-one mapping exists between being CIS compliant and holding these baselines.
  • The relationship is described honestly too. The recommendations come out of engagement with enterprise customers and with external agencies including the Department of Defense and NIST, those bodies publish their own recommendations which closely mirror these, and a great many customers take the baselines as a starting point and then tailor them from there.
  • The sentence you can write with confidence is that the estate is configured against the recommended Microsoft security baseline. That is substantial, defensible and true. The sentence you cannot write is that it is CIS compliant, and that claim will not survive a competent auditor or a serious security review from a customer.
  • Where a specific standard is genuinely required of you, the baseline is where the work starts and what you actually need is a measured assessment against that standard. Vulnerability Management, for instance, supports baseline profiles measured specifically against the Center for Internet Security benchmarks and the Security Technical Implementation Guides.
Ask what your estate can honestly be described as meeting
What they are

Eight things about these baselines that determine how you ought to use them.

Each one is a bundle of preconfigured Windows settings that apply and enforce detailed security recommendations from the relevant teams, and every one can be tailored so it enforces only the settings and values you actually want. They cover Windows 11 and Windows 10 from build 1809 onward.

These are not CIS or NIST compliance, and that is stated outright

Put the question plainly and the published answer is that strictly speaking they are not. The security team consults bodies such as CIS while compiling its recommendations, and there is no one-to-one mapping between being CIS compliant and holding these baselines. When a client or an auditor asks specifically for CIS, deploying the baseline is a genuinely good start and it is not the answer to their question.

The defaults are the most restrictive, deliberately

In almost every scenario the default values in these baselines are the most restrictive available, and you are told to confirm they do not conflict with other policy settings or features already in your environment. That is exactly the right way to design a baseline, and it is also precisely why assigning one broadly without validating it first is how a security improvement turns into an outage.

The Defender baseline is not for virtual desktops

The Defender for Endpoint baseline is optimized for physical machines and is currently not recommended for virtual machines or virtual desktops, because several of its settings interfere with remote interactive sessions in a virtualized environment. For any company running virtual desktops alongside physical hardware, that is a scoping decision to take at the start rather than a footnote to read later.

Baselines can disagree with each other

Different baseline types can contain the same setting carrying different default values, with the Windows and Defender baselines given as the worked example, and Intune has no way of determining which value is right for you. Deploying two of them without reading the overlap first produces conflicts somebody then has to investigate, and those conflicts are not always obvious from the outside.

Old versions become read-only once superseded

Once a newer version appears, the settings in any profile built on an older one become read-only. Those profiles keep working, and you can still change the name, the description and who they are assigned to, but you cannot alter a setting or create anything new on the old version. There is a built-in route for moving a profile onto a newer version rather than rebuilding it from scratch, and that is the one to take.

Multiple baseline families, including some people do not know exist

There is one for Windows 10 and later, one for Defender for Endpoint, one for the Microsoft 365 applications, one for the browser, two variants covering the mixed reality headset, one for the cloud PC service, and a local AI agent baseline currently in preview. The cloud PC and application baselines in particular get overlooked constantly by companies that deployed the Windows one and considered the job finished.

The same team behind them, and very nearly the same settings as group policy

The same security team selected and organized the settings in each baseline, Intune carries every relevant one, and the only things left out are settings applying specifically to a domain controller on your own hardware. Everything else is identical. For a company migrating away from group policy, that continuity is a genuine argument rather than a marketing line.

A local AI agent baseline exists, in preview

A local AI agent baseline exists in preview, which tells you something about where endpoint hardening is heading over the next few years. It is also stated plainly that preview versions are not recommended in production, because the settings can change during the preview period. Worth knowing exists. Not worth deploying to anything real.

How we approach it

Four things that turn a baseline into a maintained control rather than a single afternoon of work.

These are among the highest value configurations available anywhere in Intune, and among the easiest to deploy once, forget entirely, and then describe inaccurately to an auditor.

We state what your estate actually meets

Saying your estate is configured against the Microsoft recommended security baseline is accurate, defensible and substantial. Saying it is CIS compliant is none of those things, and the documentation states as much. Getting that wording right protects you when a client questionnaire, a SOC 2 auditor or an insurer asks the question, and it costs nothing beyond a little precision.

Everything gets validated before assignment, because the defaults are the strictest values available

The defaults are the most restrictive values in almost every scenario, and you are told to confirm they do not conflict with existing policy or features, with a firewall and delivery optimization conflict given as the worked example. So we pilot first, go looking for conflicts with the configuration profiles already deployed, and document every single deviation from a default alongside the reason it was made.

We scope the Defender baseline away from virtual desktops

It is optimized for physical machines and not currently recommended for virtual machines or virtual desktops, because several settings interfere with remote interactive sessions. A company running virtual desktops alongside physical hardware needs that separation designed into the assignment rather than discovered through six weeks of unexplained session problems.

We put version management on a cycle

New versions publish, older profiles quietly become read-only, and estates end up years behind a baseline nobody noticed had moved at all. The admin center shows how many versions exist and when the most recent one published, and there is a built-in route for moving a profile onto a newer version. Checking that on a schedule is the only thing preventing a baseline turning into a historical curiosity.

Where this matters most

Six US situations where baselines need attention.

Almost every company here has already deployed a baseline. The problem is what it covers, what it quietly conflicts with, and what has been said about it to other people.

A firm that has already told a client it is CIS hardened

Extremely common, and almost always said in complete good faith after deploying the Windows baseline, usually on a security questionnaire from a large customer. The published answer is that these are not strictly CIS or NIST compliant and that no one-to-one mapping exists. Correcting the claim yourself is a considerably better outcome than having an auditor correct it for you, and the underlying position is strong enough to state accurately without embarrassment.

An organization that deployed one baseline and stopped

The Windows baseline has been applied while the ones covering the Microsoft 365 applications, the browser and, where cloud PCs exist, the cloud PC service, have not. That leaves the applications people spend their entire day inside, the browser through which almost every attack arrives, and the virtual desktops completely unhardened, while everybody believes the hardening is finished.

An estate mixing physical devices and virtual desktops

This happens where the Defender for Endpoint baseline was assigned to everything. It is optimized for physical machines, is not currently recommended for virtual machines or virtual desktops, and several of its settings interfere with remote interactive sessions. The symptom is intermittent session problems that nobody ever connects back to a baseline assignment made months earlier.

A business where the baseline broke something

Because the defaults are the most restrictive values by design, and somebody assigned them without validating anything first. The shape of the problem is even given as an example: firewall defaults that may not merge connection security rules and local policy rules with the managed ones, which is worth checking wherever delivery optimization is running. The fix is a documented deviation from default, not walking away from the baseline entirely.

An organization migrating from group policy

The question here is always whether the cloud version is genuinely as good as what came before. The same security team chose and organized the settings, Intune carries every relevant one, and the only omissions are those applying specifically to a domain controller on your own hardware. That is a substantially stronger reassurance than any general claim of parity.

An estate whose baseline profiles are years old

New versions publish on a regular cadence, older profiles quietly turn read-only, and nobody notices any of it because the profiles carry on working perfectly well. The admin center shows how many versions exist and when the last one published, and a profile can be moved forward without rebuilding it. Most estates we assess sit at least one major version behind.

Three positions

How Windows hardening is actually done in US organizations.

The middle column, one baseline deployed on its defaults and never opened again, is the most common position anywhere. It is genuinely better than nothing, and considerably less than the people running it believe it to be.
Windows hardened against a recommended set
Baselines managedYes
One baseline, deployed onceYes
Nothing configuredNo
Office applications hardened
Baselines managedYes
One baseline, deployed onceNo
Nothing configuredNo
Browser hardened
Baselines managedYes
One baseline, deployed onceNo
Nothing configuredNo
Cloud PCs on the right baseline
Baselines managedYes
One baseline, deployed onceNo
Nothing configuredNot applicable
Virtual desktops excluded from the Defender baseline
Baselines managedYes
One baseline, deployed onceUnlikely
Nothing configuredNot applicable
Conflicts between baselines identified
Baselines managedYes
One baseline, deployed onceNo
Nothing configuredNot applicable
Profiles moved to current baseline versions
Baselines managedYes
One baseline, deployed onceNo
Nothing configuredNot applicable
Deviations from default documented
Baselines managedYes
One baseline, deployed onceNo
Nothing configuredNot applicable
Compliance claim accurately stated
Baselines managedYes
One baseline, deployed onceOften overstated
Nothing configuredNot applicable
Survives a vendor security review
Baselines managedYes
One baseline, deployed onceSometimes
Nothing configuredNo
Feature
Baselines managed
One baseline, deployed once
Nothing configured
Windows hardened against a recommended set
YesYesNo
Office applications hardened
YesNoNo
Browser hardened
YesNoNo
Cloud PCs on the right baseline
YesNoNot applicable
Virtual desktops excluded from the Defender baseline
YesUnlikelyNot applicable
Conflicts between baselines identified
YesNoNot applicable
Profiles moved to current baseline versions
YesNoNot applicable
Deviations from default documented
YesNoNot applicable
Compliance claim accurately stated
YesOften overstatedNot applicable
Survives a vendor security review
YesSometimesNo
The baselines available

The baseline families, and which ones most organizations have missed.

Taken from the published list of what is available. Most companies deploy the first one and stop there, which leaves the applications, the browser and the cloud PCs entirely unhardened.

Baseline

Security Baseline for Windows 10 and later

What it covers, and whether it is commonly deployed
The core Windows baseline. Usually the only one deployed.

Baseline

Microsoft Defender for Endpoint baseline

What it covers, and whether it is commonly deployed
The Defender configuration. Not recommended anywhere near a virtual machine or a virtual desktop.

Baseline

Microsoft 365 Apps for Enterprise

What it covers, and whether it is commonly deployed
The Office application baseline. Frequently overlooked entirely.

Baseline

Microsoft Edge

What it covers, and whether it is commonly deployed
Browser hardening. Also frequently overlooked.

Baseline

Windows 365 Security Baseline

What it covers, and whether it is commonly deployed
Built for cloud PCs specifically, rather than reusing the one meant for physical hardware.

Baseline

HoloLens 2, standard and advanced

What it covers, and whether it is commonly deployed
Two variants, for organizations with mixed reality devices.

Baseline

Local AI agent baseline

What it covers, and whether it is commonly deployed
In preview. Microsoft advises against preview baselines in production.

Baseline

STIG audit baseline

What it covers, and whether it is commonly deployed
Audit only, assessing devices against DISA STIG recommendations. Available to GCC High tenants only and requires Advanced Analytics licensing, so commercial tenants cannot use it.
BaselineWhat it covers, and whether it is commonly deployed
Security Baseline for Windows 10 and laterThe core Windows baseline. Usually the only one deployed.
Microsoft Defender for Endpoint baselineThe Defender configuration. Not recommended anywhere near a virtual machine or a virtual desktop.
Microsoft 365 Apps for EnterpriseThe Office application baseline. Frequently overlooked entirely.
Microsoft EdgeBrowser hardening. Also frequently overlooked.
Windows 365 Security BaselineBuilt for cloud PCs specifically, rather than reusing the one meant for physical hardware.
HoloLens 2, standard and advancedTwo variants, for organizations with mixed reality devices.
Local AI agent baselineIn preview. Microsoft advises against preview baselines in production.
STIG audit baselineAudit only, assessing devices against DISA STIG recommendations. Available to GCC High tenants only and requires Advanced Analytics licensing, so commercial tenants cannot use it.
How a review runs

Five steps, and the language question comes first.

Two to four weeks including a pilot, delivered remotely. The technical work involved is modest. Establishing what can honestly be claimed afterward, and validating everything against the configuration you already run, is where the value actually sits.
  1. 1

    Establish what is deployed and what has been claimed

    Which baselines exist at all, which version each profile sits on, which devices they reach, and what has already been said internally, on questionnaires, and to clients about compliance. That last item is very often where the most important correction lies, given the published answer on CIS and NIST.

  2. 2

    Identify the gaps in coverage

    Nearly always the application baseline and the browser one, plus the cloud PC baseline wherever those exist. Between them they cover the applications people spend their day inside and the browser through which almost every attack arrives, which makes the gap considerably larger than their obscurity would suggest.

  3. 3

    Find the conflicts before assigning anything new

    Between the baselines themselves, since different types can set the same value differently and nothing will resolve that on your behalf, and between the baselines and the device configuration profiles you already run, which very often manage the same settings. The monitoring view gives you a status per setting to work through methodically.

  4. 4

    Pilot, then document every deviation

    Because in almost every scenario the defaults are the most restrictive values available. Wherever a setting has to be loosened, that deviation and the reason behind it belong written down, because that record is exactly what an auditor asks for and it is what stops somebody re-tightening it eighteen months later without any idea why it was changed.

  5. 5

    Set a version review cycle

    New versions publish, older profiles turn read-only, and absolutely nothing announces any of it. A scheduled look at the last published date and at which versions your profiles sit on, using the built-in route to move them forward rather than rebuilding from scratch, is what keeps this current instead of historical.

Straight answers

What organizations ask about Intune security baselines.

No, and the question gets answered directly in the documentation itself. Are these baselines CIS or NIST compliant? Strictly speaking, no. The explanation given is that the security team consults bodies such as CIS while compiling its recommendations, and that no one-to-one mapping exists between being CIS compliant and holding these baselines.

That the estate is configured against the recommended Microsoft security baseline, which is a substantial and entirely defensible position to hold. The recommendations themselves come from engagement with enterprise customers and with external agencies including the Department of Defense and NIST, and those bodies publish their own recommendations which closely mirror these. Similar is not the same word as certified.

Deliberately, and it is stated plainly. In almost every scenario the defaults in these baselines are the most restrictive available, and you are told to confirm they do not conflict with other policy or features already running. That is exactly the right behavior for a baseline, and it is also precisely why assigning one broadly without validating it first turns a security improvement into a support incident.

One for Windows 10 and later, one for Defender for Endpoint, one for the Microsoft 365 applications, one for the browser, two variants covering the mixed reality headset, one for the cloud PC service, a local AI agent baseline still in preview, and an audit baseline against the Security Technical Implementation Guides available only in the higher government cloud.

It is a good start, and it leaves real gaps. The application baseline covers the tools people work inside all day. The browser baseline covers the route through which almost every attack arrives. And where cloud PCs exist there is a baseline built specifically for them. In our experience a company deploys the Windows one and has no idea the others are even available.

The advice is against it. That baseline is optimized for physical machines and is not currently recommended for virtual machines or virtual desktops, because several of its settings interfere with remote interactive sessions in a virtualized environment. Across a mixed estate, that means the assignment has to exclude those devices deliberately rather than by accident.

Then you have a conflict to resolve yourself, and the documentation is upfront that nothing can resolve it on your behalf. Different baseline types, with the Windows and Defender ones given as the example, can carry the same setting at different default values, because each is preconfigured around recommendations specific to its own product. Reading the overlap before deploying both is the only way to avoid the problem entirely.

They can, and that is documented: these baselines routinely manage the same settings you might already be setting through a device configuration profile or another policy type. The monitoring view gives a status per setting, which is the practical way to find the collisions, and it is worth working through before a broad assignment rather than after somebody reports that a setting refuses to apply.

Because a newer version has since published. Once that happens, the settings inside any profile built on an older version become read-only. Those profiles keep working, and the name, description and assignments remain editable, but the settings themselves do not, and nothing new can be created on the old version. A built-in route exists for moving an existing profile onto a newer one.

The baselines list in the admin center shows each template, how many of your profiles use it, how many versions of that type exist in total, and the date the most recent one published. Open a baseline and look at versions and you can see which one each of your profiles is actually sitting on. Two minutes of work, and most estates have never done it once.

Not in production. Microsoft states plainly that it does not recommend using preview versions of security baselines in a production environment, because the settings in a preview baseline might change over the course of the preview. The local AI agent baseline is currently in preview, which makes it worth knowing about and not worth deploying to devices people depend on.

Almost. Microsoft states the same security team chose and organized the settings for each baseline, that Intune includes all the relevant settings, and that some settings in the group policy baseline specific to an on-premises domain controller are excluded from the Intune recommendations, with all other settings the same. For anyone migrating from group policy that is a meaningful reassurance.

Microsoft describes it as assessing Windows devices against Security Technical Implementation Guide recommendations published by DISA, and unlike other baselines it is audit-only: it does not configure or enforce settings. It is available only to GCC High tenants and requires Advanced Analytics licensing. If you are a defense industrial base organization already on GCC High it is worth knowing about; a commercial tenant cannot use it, and a measured STIG or CIS assessment through Defender Vulnerability Management is the route instead.

Then you need something that measures against those standards rather than a baseline that resembles them. Defender Vulnerability Management provides customizable baseline profiles measuring compliance against established benchmarks including the Center for Internet Security benchmarks and the Security Technical Implementation Guides, which is a different capability from the Intune security baselines and the right one for that requirement.

Scoped per engagement, typically two to four weeks including a pilot and the conflict review. What we will do free in the first conversation is tell you which baselines you have deployed, which versions your profiles are on, and whether anything your organization has said about compliance needs correcting, since that last one is usually the most valuable finding.
Before deploying

Fifteen questions worth answering first.

The first block asks what you are genuinely trying to achieve here. The second covers the validation that stops this becoming an outage. The third covers ongoing management, which is exactly where baselines quietly go stale.

What you are achieving

  • Has anybody claimed CIS or NIST compliance?
    Microsoft answers that question with a no.
  • Is a specific standard actually required?
    If so, a measured assessment is what you need.
  • Which baselines are already deployed?
    Usually the Windows one, and nothing else.
  • Are your Office applications and browser hardened?
    Separate baselines exist for both.
  • Do you have Cloud PCs?
    There is a Windows 365 baseline for them.

Validation

  • Do you run virtual machines or virtual desktops?
    The Defender baseline is not recommended for those.
  • Do two baselines set the same setting differently?
    This is documented as happening, and nothing can resolve it on your behalf.
  • Do baselines conflict with your configuration profiles?
    They frequently manage the same settings.
  • Are you using delivery optimization?
    Microsoft names it in a firewall configuration example.
  • Has this been piloted before broad assignment?
    Defaults are the most restrictive by design.

Ongoing management

  • Which baseline version are your profiles on?
    Older versions become read-only once superseded.
  • Do you know when a new version publishes?
    The admin center shows a last published date.
  • Who reviews and moves profiles to new versions?
    There is a built-in option to change version.
  • Are any profiles on a preview baseline?
    Microsoft advises against that in production.
  • Are per-setting conflicts being monitored?
    Baseline monitoring shows per-setting status.
Related reading

The pages around this one.

Defender Vulnerability Management

Where CIS and STIG benchmark compliance is actually measured, as opposed to approximated by a baseline.

Learn more

Microsoft Intune

The platform these are configured in, alongside configuration profiles, compliance and application deployment.

Learn more

Disk encryption with Intune

Where a security baseline can silently block silent BitLocker encryption, and the specific setting to check.

Learn more
Next step

Check which baseline versions your profiles are actually on.

The admin center shows how many versions exist and when the latest published. Most estates we assess are at least one major version behind, on a profile that has quietly become read-only, while believing hardening is current.

Book a baseline reviewSee Microsoft Intune services

Related Services

Explore more solutions that work great with this service

Intune Endpoint Security Antivirus Policy

Intune antivirus policy consolidation for US organizations: every

Learn more

Intune Endpoint Security Firewall Policy

Host firewall policy managed from Intune, per ring

Learn more

Attack Surface Reduction Rules Deployment

Attack surface reduction rules deployment for US organizations:

Learn more

Microsoft Defender Vulnerability Management Services

Defender Vulnerability Management deployment for US organizations:

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

BitLocker Disk Encryption Management with Intune

BitLocker encryption management for US businesses: pre-deployment

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA