Edge security baseline and all other security baselines

%3CLINGO-SUB%20id%3D%22lingo-sub-1251807%22%20slang%3D%22en-US%22%3EEdge%20security%20baseline%20and%20all%20other%20security%20baselines%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1251807%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20say%20sorry%20in%20advance%20for%20this%20stupid%20question%20and%20by%20having%20asked%20it%20in%20a%20new%20conversation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20want%20to%20know%20why%20on%20Intune%20we%20have%20the%20possibility%20to%20configure%20devices%20with%20those%20security%20baselines%20AND%2FOR%20with%20the%20(almost%3F)%20same%20settings%20on%20Device%20configuration%20profiles.%3C%2FP%3E%3CP%3EI%20mean%2C%20why%3F%20Two%20places%3F%20Would%20it%20be%20better%20to%20just%20have%20Security%20baselines%20settings%20or%20just%20Device%20configuration%20settings%3F%20This%20is%20confusing%20and%20in%20my%20company%20we%20realize%20that%20both%20are%20doing%20the%20job...%20or%20one%20settings%20is%20set%20to%20enabled%20on%20one%20side%2C%20then%20disabled%20on%20the%20other%20side.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20consider%20closing%20this%20thread%20only%20when%20a%20proper%20answer%20is%20given.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGianluca%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1259287%22%20slang%3D%22en-US%22%3ERe%3A%20Edge%20security%20baseline%20and%20all%20other%20security%20baselines%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1259287%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F434826%22%20target%3D%22_blank%22%3E%40GianlucaSB%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22xmsonormal%22%3ESecurity%20baselines%20are%20designed%20with%20MSFT%20best%20practice%20configuration%20by%20default.%20Our%26nbsp%3Bdevice%20configuration%20profiles%20are%20all%20not%20configured%20by%20default.%3C%2FP%3E%0A%3CP%20class%3D%22xmsonormal%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22xmsonormal%22%3Eyou%20can%20use%20the%20baselines%20as%20a%20starting%20point%2C%20and%20supplement%20them%20with%20your%20own%20individual%20settings%20based%20on%20your%20business%20needs.%3C%2FP%3E%0A%3CP%20class%3D%22xmsonormal%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22xmsonormal%22%3EAll%20of%20the%20settings%20in%20our%20security%20baselines%20are%20also%20available%20in%20the%20device%20configuration%20profiles%20%E2%80%93%20we%E2%80%99ve%20just%20pulled%20together%20the%20most%20important%20and%20preconfigured%20them.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1259451%22%20slang%3D%22en-US%22%3ERe%3A%20Edge%20security%20baseline%20and%20all%20other%20security%20baselines%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1259451%22%20slang%3D%22en-US%22%3EOk%2C%20but%20still%20having%20Windows%20Hello%20for%20Business%20in%203%20different%20places%20(Baseline%2C%20configuration%20profiles%20and%20Enrollment)%20it%20just%20creates%20confusion.%20Same%20for%20other%20settings%2C%20and%20it%20is%20not%20clear%20who%20overpowers%20who%20in%20case%20of%20some%20settings%20that%20are%20applied%20in%20two%20or%20more%20different%20places%20at%20the%20same%20time.%3CBR%20%2F%3E%3CBR%20%2F%3ECheers%2C%3CBR%20%2F%3EGianluca%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1259465%22%20slang%3D%22en-US%22%3ERe%3A%20Edge%20security%20baseline%20and%20all%20other%20security%20baselines%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1259465%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F434826%22%20target%3D%22_blank%22%3E%40GianlucaSB%3C%2FA%3E%26nbsp%3Bfeedback%20noted.%26nbsp%3B%20We%20will%20see%20what%20we%20can%20do%20in%20future%20updates.%26nbsp%3B%20I%20would%20also%20suggest%20getting%20this%20posted%20over%20on%20the%20Intune%20side%20as%20they%20dont%20monitor%20this%20channel%20and%20actually%20have%20their%20own%20baseline.%26nbsp%3B%20They%20just%20consume%20the%20settings%20from%20us.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1267800%22%20slang%3D%22en-US%22%3ERe%3A%20Edge%20security%20baseline%20and%20all%20other%20security%20baselines%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1267800%22%20slang%3D%22en-US%22%3EHello%2C%3CBR%20%2F%3E%3CBR%20%2F%3Eplease%20do%20so!%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%2C%3CBR%20%2F%3EGianlucaSB%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello all,

 

I say sorry in advance for this stupid question and by having asked it in a new conversation.

 

I want to know why on Intune we have the possibility to configure devices with those security baselines AND/OR with the (almost?) same settings on Device configuration profiles.

I mean, why? Two places? Would it be better to just have Security baselines settings or just Device configuration settings? This is confusing and in my company we realize that both are doing the job... or one settings is set to enabled on one side, then disabled on the other side.

 

Please consider closing this thread only when a proper answer is given.

 

Thank you!

 

Gianluca

4 Replies

@GianlucaSB 

Security baselines are designed with MSFT best practice configuration by default. Our device configuration profiles are all not configured by default.

 

you can use the baselines as a starting point, and supplement them with your own individual settings based on your business needs.

 

All of the settings in our security baselines are also available in the device configuration profiles – we’ve just pulled together the most important and preconfigured them.

Ok, but still having Windows Hello for Business in 3 different places (Baseline, configuration profiles and Enrollment) it just creates confusion. Same for other settings, and it is not clear who overpowers who in case of some settings that are applied in two or more different places at the same time.

Cheers,
Gianluca

@GianlucaSB feedback noted.  We will see what we can do in future updates.  I would also suggest getting this posted over on the Intune side as they dont monitor this channel and actually have their own baseline.  They just consume the settings from us.

Hello,

please do so!

Thanks,
GianlucaSB