Template family: Intune — device configuration
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Configuration → Templates → Augmentt Default

What this template is for

Block abuse of exploited vulnerable signed drivers (Device). Block Adobe Reader from creating child processes. Block all Office applications from creating child processes. Block credential stealing from the Windows local security authority subsystem. Block executable content from email. Block executable files from running unless they meet a trusted list criterion. Audit execution of potentially obfuscated scripts. Block JavaScript or VBScript from launching downloaded executable content. Block Office applications from creating executable content. Block Office applications from injecting code into other processes. Audit Office communication application from creating child processes. Block persistence through WMI event subscription. Audit process creations originating from PSExec and WMI commands. Block untrusted and unsigned processes that run from USB. Block Win32 API calls from Office macros. Use advanced protection against ransomware (Audit). CIS v8: 10.5.

What it actually does

SettingValue
platformswindows10
technologiesmdm
templateReference.templateId(empty)
templateReference.templateFamilynone

Anything not listed keeps the Microsoft default.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.