Support Tip: Updates to Microsoft Defender ATP baseline
Published Mar 30 2020 09:48 AM 4,129 Views

For customers who are taking advantage of Microsoft Endpoint Manager’s Security Baselines for Microsoft Defender ATP, you might notice a banner in the UI of the Device Management admin console indicating a new baseline version has been released with this iteration.

 

MDATP baselines.jpg


Existing profiles will continue to work as expected – no action is needed.

To make any changes/customizations to settings within a profile that has an updated baseline available, Microsoft requires you update that profile to a supported version of a baseline and make your changes.

 

You can select the two versions of the baseline and then choose ‘Compare baselines’ to download a CSV file that details those differences. There are changes in these areas:

  • BitLocker,
  • Windows Hello for Business,
  • Exploit Protection,
  • Folder protection,
  • Credential guard,
  • SmartScreen,
  • and Application Guard


When you are ready, the update process can be started by selecting ‘Profiles’ under the Microsoft Defender ATP baseline, select ‘Change Version’. To learn more, see “Change the baseline version for a profile“.

 

2 Comments
Brass Contributor

@Intune_Support_Team 
how come tamper protection isn’t include in the new baseline? As it is part of the Intune endpoint protection policy. 

Brass Contributor

I think at the moment the whole endpoint security is a bit of a mess

there are the same settings in device configuration, you have ATP profiles, security baseline profiles, now i see another split out of items

 

Can we have some consistent approach to defining device configurations please

 

I even tried the new bitlocker policy and it spat errors (admit is still preview)

Version history
Last update:
‎Dec 19 2023 01:30 PM
Updated by: