Template family: Intune — device compliance
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Compliance → Templates → Augmentt Default

What this template is for

Augmentt policy for device security best practices. Requires Bitlocker, Secure Boot, and Code Integrity to be compliant. Requires Encryption on data storage, Firewall, TPM, and Antivirus. Password required to unlock device, simple passwords blocked, password required when returning from idle state. Defender not enforced in this policy. CIS v8: 4.3, 4.5, 7.3, 10.1.

What it actually does

Creates a windows10CompliancePolicy in Microsoft Intune configured as follows.

SettingValue
rtpEnabledtrue
tpmRequiredtrue
defenderEnabledfalse
bitLockerEnabledtrue
passwordRequiredtrue
wslDistributions(none)
antivirusRequiredtrue
secureBootEnabledtrue
signatureOutOfDatetrue
antiSpywareRequiredfalse
passwordBlockSimpletrue
codeIntegrityEnabledtrue
passwordRequiredTypedeviceDefault
passwordMinimumLength14
activeFirewallRequiredtrue
memoryIntegrityEnabledfalse
storageRequireEncryptiontrue
firmwareProtectionEnabledfalse
kernelDmaProtectionEnabledfalse
requireHealthyDeviceReportfalse
deviceThreatProtectionEnabledfalse
validOperatingSystemBuildRanges(none)
passwordRequiredToUnlockFromIdletrue
passwordPreviousPasswordBlockCount24
virtualizationBasedSecurityEnabledfalse
earlyLaunchAntiMalwareDriverEnabledfalse
passwordMinutesOfInactivityBeforeLock15
configurationManagerComplianceRequiredfalse
deviceThreatProtectionRequiredSecurityLevelunavailable

Anything not listed keeps the Microsoft default.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.