The CIS Intune Benchmark.
Three assessment levels covering Intune device management configuration for Windows 11. Enrolment, compliance policies, app management, and security baselines.
3
Assessment levels: Baseline, L1, L2
Windows 11
Primary platform scope
Intune-native
No third-party tooling required
MDM-based
Modern device management scope
What the benchmark covers.
The CIS Microsoft Intune Benchmark provides guidance for securing Intune-managed Windows 11 devices. It covers the policies, compliance settings, and security baselines available within Intune without requiring third-party tooling.
The benchmark has three levels: Baseline, Level 1, and Level 2. Each level builds on the previous, adding progressively more restrictive configuration. The assessment evaluates your Intune policies against each control and produces a findings report with a specific remediation action for each gap.
Six areas of Intune configuration.
Controls are grouped across the major configuration areas of Microsoft Intune.
Device Enrolment
Enrolment restrictions, autopilot configuration, and enrolment profile settings.
Compliance Policies
Device compliance requirements, non-compliant device actions, and compliance monitoring.
Application Management
App deployment policies, app protection settings, and managed app configuration.
Device Configuration & Encryption
BitLocker encryption, Windows Hello, firewall policies, and device restriction profiles.
Security Baselines
Microsoft Security Baseline deployment and Defender for Endpoint integration policies.
Browser Security
Microsoft Edge configuration including SmartScreen, HTTPS-only mode, and extension policies.
Three levels of assessment.
Core configuration
Baseline controls cover the essential Intune configuration that every organisation should have. Enrolment, basic compliance, and core device restrictions.
Get a quoteStandard security
Level 1 adds security hardening appropriate for most organisations: encryption, security baselines, app management, and browser security.
Get a quoteAdvanced hardening
Level 2 adds advanced configuration controls for organisations managing sensitive data or operating in regulated sectors requiring higher device assurance.
Get a quoteRelationship to CIS M365
The CIS Intune Benchmark assesses device management configuration, while the CIS M365 Benchmark covers the Microsoft 365 platform controls. They are complementary: organisations managing Windows devices with Intune typically benefit from both assessments. The Intune assessment focuses on policy configuration within Intune itself; it does not duplicate the M365 controls.
Assess your Intune configuration.
Get in touch to discuss scope, level of assessment, and pricing for your environment.
