Skip to content
CIS Microsoft Intune Benchmarks

Your devices are only as secure as the policies managing them.

Intune is where device security is actually enforced. We assess your Intune configuration against the CIS Benchmarks covering Windows 11, Microsoft Edge, Defender Antivirus and Office, and show you where policy and reality have drifted apart.

Windows 11, Edge, Defender, Office
L1, L2 and BitLocker
Intune-native, no extra tooling
Independent assessment
What it is

A family of benchmarks, not one document.

CIS publishes a family of benchmarks specifically for Microsoft Intune, rather than one single document. Our assessment covers four of them: the CIS Microsoft Intune for Windows 11 Benchmark (v5.0.0), which is the core device hardening standard; the CIS Microsoft Intune for Microsoft Edge Benchmark (v1.0.0); the CIS Microsoft Intune for Microsoft Defender Antivirus Benchmark (v1.0.0); and the CIS Microsoft Intune for Office Benchmark (v1.1.0).

This matters because device security is not one surface. A hardened Windows build with an unmanaged browser, or strong device policy with weak Office macro settings, leaves the same gaps open.

Published by
Center for Internet Security (CIS)
Benchmarks assessed
Intune for Windows 11 (v5.0.0), Microsoft Edge (v1.0.0), Defender Antivirus (v1.0.0), Office (v1.1.0)
Profiles
Level 1, Level 2 and BitLocker
Applies to
Devices managed through Microsoft Intune
Why it matters

Device management is where policy stops being theoretical.

A Conditional Access rule that requires a compliant device only means something if your compliance policy actually checks something worthwhile.

Drift is the normal state

Intune policy accumulates. Policies get created for a project, superseded, and never removed. Assignments overlap. Conflicting settings resolve in ways nobody intended, and the admin console does not make this obvious.

Defaults are not a baseline

Intune ships permissive. A tenant that has enrolled devices without deliberate hardening is managing devices, not securing them.

Remote and hybrid working moved the perimeter

The laptop in someone’s kitchen is the boundary now, and its configuration is the control.

It is increasingly asked about

Cyber insurance questionnaires and enterprise supplier assessments both ask about device encryption, patch enforcement and administrative rights. These are Intune questions.

What it covers

Policy, and whether it is actually enforcing anything.

  • Device enrolment

    Enrolment restrictions, Autopilot configuration, enrolment profiles and platform controls.

  • Device compliance

    Compliance policy rules, health attestation, actions for non-compliance and how compliance feeds Conditional Access. The Windows 11 benchmark expanded this area significantly in v5.0.0.

  • Device configuration

    Settings Catalog and endpoint security policy, device restrictions, credential protection.

  • Encryption

    BitLocker policy, recovery key escrow and the dedicated BitLocker profile.

  • Network and protocol security

    Firewall policy, SMB hardening and legacy protocol handling.

  • Defender Antivirus

    Real-time protection, cloud-delivered protection, attack surface reduction rules and tamper protection.

  • Microsoft Edge

    SmartScreen, HTTPS enforcement, extension control and password manager policy.

  • Office

    Macro handling, protected view, external content and legacy file format policy.

Profile levels

Level 1, Level 2 and BitLocker.

The Windows 11 benchmark organises its recommendations into three profiles.

Level 1

The core baseline

Suitable for most organisations.

Level 2

Additional hardening

Adds hardening that may affect functionality and needs deliberate assessment before rollout.

BitLocker

Encryption

A separate profile covering encryption settings specifically.

How it works

Scoped, assessed, reported, handed over.

Scoping

A short call covering your device estate, which benchmarks are relevant and what is driving the work. Scope and fee are confirmed before we start.

Assessment

We review your Intune policies against each applicable control, including how policies interact. Conflicting and superseded assignments are called out, because a correct setting that loses a conflict is not a correct setting.

Reporting

A findings report in plain English, prioritised by risk, with a specific remediation action per gap. Level 2 and BitLocker findings are flagged separately where they carry user impact.

Handover

We walk you through the findings. Act on it yourself, pass it to your IT provider, or ask us to remediate.

What you receive

  • A findings report in plain English, prioritised by risk
  • A specific remediation action against every gap
  • Level 2 and BitLocker findings flagged separately where they carry user impact
  • Conflicting and superseded policy assignments called out
  • A walkthrough of the findings, and the report to keep
Scope and fee

Quoted per engagement, agreed before we start.

Quoted

Scope and fee confirmed at the discovery call, before any work begins.

The assessment is the deliverable. There is no tooling to buy and no third-party product being sold alongside it.

What the scope depends on

  • The size and make-up of your device estate
  • Which of the four benchmarks are relevant to you
  • Whether Windows 10 devices need including as well
  • Whether you want us to carry out the remediation as well
Official sources

Read it from the source.

The benchmarks are published by CIS, not by us. Read them there.

Framework information checked on 18 September 2026.

FAQ

Common questions

We only use Intune for enrolment. Is this still worth doing?

Usually yes, and often more so. Enrolment without hardening is the most common pattern we see, and it is the one that gives the most false confidence.

Do you need admin access to our tenant?

We need read access sufficient to review policy configuration. We agree the exact permissions at scoping and they are removed afterwards.

Will Level 2 break things?

Some Level 2 controls can affect how people work, which is exactly why they are a separate profile. We flag user impact against each one so you can decide rather than discover.

Can you assess Windows 10 devices too?

Yes. CIS publishes a separate Windows 10 benchmark and we can include it where your estate is mixed. Worth raising at scoping.

Find out what your device policies are actually enforcing.

A short discovery call is enough to scope the work and give you a fixed fee.