0%

Template family: Intune — device configuration
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Configuration → Templates → Augmentt Default

What this template is for

Security Guideline Benchmarks per NIST Checklist 1161 Version 4.0.0 https://ncp.nist.gov/checklist/1161

Notes: 49.3 (L1) Configure 'Accounts: Rename administrator account' (Automated) AMAdministrator 49.4 (L1) Configure 'Accounts: Rename guest account' (Automated) AMGuest 49.9 (L1) Configure 'Interactive logon: Message text for users attempting to log on' (Automated) (NOT SET) 49.10 (L1) Configure 'Interactive logon: Message title for users attempting to log on' (Automated) (NOT SET) 4.11.7.2.14 (BL) Ensure 'Enforce drive encryption type on operating system drives: Select the encryption type: (device)' is set to 'Enabled: Full encryption' 22.9 (L1) Ensure 'ASR: Block all Office applications from creating child processes' is set to 'Audit'

Exceptions: 4.6.11.1 (L1) Ensure 'Hardened UNC Paths' is set to 'Enabled, with "Require Mutual Authentication", "Require Integrity", and “Require Privacy” set for all NETLOGON and SYSVOL shares'

What it actually does

SettingValue
platformswindows10
technologiesmdm
templateReference.templateId(empty)
templateReference.templateFamilynone

Anything not listed keeps the Microsoft default.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.