Microsoft Intune
Device security

Ref Windows Mdm Settings

In brief

The documentation now includes the Windows 11 version 26H2 security baseline and its default settings across areas including SMB, network security, DNS, and Windows Connection Manager.

What Intune admins need to know

Administrators can use the updated reference to review and compare 26H2 baseline defaults when planning or validating managed-device configurations. No action is required.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • sub-secure-endpoints ms.reviewer: aanavath ms.subservice: protect description: ViewReview the default setting configuration of the varioussettings in each Microsoft Intune Windows security baselinesbaseline version and compare recommended configurations for Windows.managed devices. ms.date: 2026-06-23T00:09-30T00:00:00.0000000Z ms.topic: reference ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1030 zone_pivot_groups: windows-mdm-versions locale: en-us document_id: f1e7e40a-164f-9d9a-9eb8-4a9d20296136
  • Change the baseline version for a profile
  • Manage security baselines

::: zone pivot="mdm-26h2"

Security Baseline for Windows, version 26H2

The settings in this baseline are taken from the Windows 11 version 26H2 security baseline as found in the Security Compliance Toolkit and Baselines from the Microsoft Download Center, and include only the settings that apply to Windows devices managed through Intune. When available, the setting name links to the source Configuration Service Provider (CSP), and then displays that settings default configuration in the baseline.

Administrative Templates

Control Panel > Personalization

  • Prevent enabling lock screen camera Baseline default: EnabledLearn more
  • Prevent enabling lock screen slide show Baseline default: EnabledLearn more

MS Security Guide

  • Apply UAC restrictions to local accounts on network logons Baseline default: EnabledLearn more

  • Configure SMB v1 client driver Baseline default: EnabledLearn more

    • Configure MrxSmb10 driver Baseline default: Disable driver (recommended)
  • Configure SMB v1 server Baseline default: DisabledLearn more

  • Enable Structured Exception Handling Overwrite Protection (SEHOP) Baseline default: EnabledLearn more

MSS (Legacy)

  • MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing) Baseline default: EnabledLearn more

    • DisableIPSourceRouting IPv6 (Device) Baseline default: Highest protection, source routing is completely disabled
  • MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing) Baseline default: EnabledLearn more

    • DisableIPSourceRouting (Device) Baseline default: Highest protection, source routing is completely disabled
  • MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes Baseline default: DisabledLearn more

  • MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers Baseline default: EnabledLearn more

Network > DNS Client

  • Turn off multicast name resolution Baseline default: EnabledLearn more

Network > Network Connections

  • Prohibit use of Internet Connection Sharing on your DNS domain network Baseline default: EnabledLearn more

Network > Network Provider

  • Hardened UNC Paths Baseline default: EnabledLearn more
    • Hardened UNC Paths: (Device) Baseline defaults:

      NameValue
      \\*\SYSVOLRequireMutualAuthentication=1,RequireIntegrity=1
      \\*\NETLOGONRequireMutualAuthentication=1,RequireIntegrity=1

Network > Windows Connection Manager

  • Prohibit connection to non-domain networks when connected to domain authenticated network Baseline default: EnabledLearn more

Printers

  • Configure Windows Ready Print driver ranking Baseline default: EnabledLearn more

  • Configure Redirection Guard Baseline default: EnabledLearn more

    • Redirection Guard Options (Device) Baseline default: Redirection Guard Enabled
  • Configure RPC connection settings Baseline default: EnabledLearn more

    • Use authentication for outgoing RPC connections: (Device) Baseline default: Default
    • Protocol to use for outgoing RPC connections: (Device) Baseline default: RPC over TCP
  • Configure RPC listener settings Baseline default: EnabledLearn more

    • Protocols to allow for incoming RPC connections: (Device) Baseline default: RPC over TCP
    • Authentication protocol to use for incoming RPC connections: (Device) Baseline default: Negotiate
  • Configure RPC over TCP port Baseline default: EnabledLearn more

    • RPC over TCP port (Device) Baseline default: 0
  • Limits print driver installation to Administrators Baseline default: EnabledLearn more

  • Manage processing of Queue-specific files Baseline default: EnabledLearn more

    • Manage processing of Queue-Specific files: (Device) Baseline default: Limit Queue-specific files to Color profiles

Start Menu and Taskbar > Notifications

  • Turn off toast notifications on the lock screen (User) Baseline default: EnabledLearn more

System > Audit Process Creation

  • Include command line in process creation events Baseline default: EnabledLearn more

System > Credentials Delegation

  • Encryption Oracle Remediation Baseline default: EnabledLearn more

    • Protection Level: (Device) Baseline default: Force Updated Clients
  • Remote host allows delegation of non-exportable credentials Baseline default: EnabledLearn more

System > Device Installation > Device Installation Restrictions

  • Prevent installation of devices using drivers that match these device setup classes Baseline default: EnabledLearn more
    • Also apply to matching devices that are already installed Baseline default: True
    • Prevented Classes Baseline default: {d48179be-ec20-11d1-b6b8-00c04fa372a7}

System > Early Launch Antimalware

  • Boot-Start Driver Initialization Policy Baseline default: EnabledLearn more
    • Choose the boot-start drivers that can be initialized: Baseline default: Good, unknown and bad but critical

System > Group Policy

  • Configure registry policy processing Baseline default: EnabledLearn more
    • Do not apply during periodic background processing (Device) Baseline default: False
    • Process even if the Group Policy objects have not changed (Device) Baseline default: True

System > Internet Communication Management > Internet Communication settings

  • Turn off downloading of print drivers over HTTP Baseline default: EnabledLearn more
  • Turn off Internet download for Web publishing and online ordering wizards Baseline default: EnabledLearn more

System > Local Security Authority

  • Allow Custom SSPs and APs to be loaded into LSASS Baseline default: DisabledLearn more

System > Power Management > Sleep Settings

  • Allow standby states (S1-S3) when sleeping (on battery) Baseline default: DisabledLearn more
  • Allow standby states (S1-S3) when sleeping (plugged in) Baseline default: DisabledLearn more
  • Require a password when a computer wakes (on battery) Baseline default: EnabledLearn more
  • Require a password when a computer wakes (plugged in) Baseline default: EnabledLearn more

System > Remote Assistance

  • Configure Solicited Remote Assistance Baseline default: DisabledLearn more

System > Remote Procedure Call

  • Restrict Unauthenticated RPC clients Baseline default: EnabledLearn more
    • RPC Runtime Unauthenticated Client Restriction to Apply: Baseline default: Authenticated

Windows Components > App runtime

  • Allow Microsoft accounts to be optional Baseline default: EnabledLearn more

Windows Components > AutoPlay Policies

  • Disallow Autoplay for non-volume devices Baseline default: EnabledLearn more

  • Set the default behavior for AutoRun Baseline default: EnabledLearn more

    • Default AutoRun Behavior Baseline default: Do not execute any autorun commands
  • Turn off Autoplay Baseline default: EnabledLearn more

    • Turn off Autoplay on: Baseline default: All drives

Windows Components > BitLocker Drive Encryption > Fixed Data Drives

  • Deny write access to fixed drives not protected by BitLocker Baseline default: DisabledLearn more

Windows Components > BitLocker Drive Encryption > Removable Data Drives

  • Deny write access to removable drives not protected by BitLocker Baseline default: EnabledLearn more
    • Do not allow write access to devices configured in another organization Baseline default: False

Windows Components > Credential User Interface

  • Enumerate administrator accounts on elevation Baseline default: DisabledLearn more

Windows Components > Event Log Service > Application

  • Specify the maximum log file size (KB) Baseline default: EnabledLearn more
    • Maximum Log Size (KB) Baseline default: 32768

Windows Components > Event Log Service > Security

  • Specify the maximum log file size (KB) Baseline default: EnabledLearn more
    • Maximum Log Size (KB) Baseline default: 196608

Windows Components > Event Log Service > System

  • Specify the maximum log file size (KB) Baseline default: EnabledLearn more
    • Maximum Log Size (KB) Baseline default: 32768

Windows Components > File Explorer

  • Configure Windows Defender SmartScreen Baseline default: EnabledLearn more

    • Pick one of the following settings: (Device) Baseline default: Warn and prevent bypass
  • Turn off Data Execution Prevention for Explorer Baseline default: DisabledLearn more

  • Turn off heap termination on corruption Baseline default: DisabledLearn more

Windows Components > Internet Explorer

  • Disable Internet Explorer 11 Launch Via COM Automation Baseline default: EnabledLearn more

  • Prevent bypassing SmartScreen Filter warnings Baseline default: EnabledLearn more

  • Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet Baseline default: EnabledLearn more

  • Prevent managing SmartScreen Filter Baseline default: EnabledLearn more

    • Select SmartScreen Filter mode Baseline default: On
  • Prevent per-user installation of ActiveX controls Baseline default: EnabledLearn more

  • Security Zones: Do not allow users to add/delete sites Baseline default: EnabledLearn more

  • Security Zones: Do not allow users to change policies Baseline default: EnabledLearn more

  • Security Zones: Use only machine settings Baseline default: EnabledLearn more

  • Specify use of ActiveX Installer Service for installation of ActiveX controls Baseline default: EnabledLearn more

  • Turn off Crash Detection Baseline default: EnabledLearn more

  • Turn off the Security Settings Check feature Baseline default: DisabledLearn more

  • Turn on the auto-complete feature for user names and passwords on forms (User) Baseline default: DisabledLearn more

Windows Components > Internet Explorer > Internet Control Panel

  • Prevent ignoring certificate errors Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Internet Control Panel > Advanced Page

  • Allow software to run or install even if the signature is invalid Baseline default: DisabledLearn more

  • Check for server certificate revocation Baseline default: EnabledLearn more

  • Check for signatures on downloaded programs Baseline default: EnabledLearn more

  • Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled Baseline default: EnabledLearn more

  • Turn off encryption support Baseline default: EnabledLearn more

    • Secure Protocol combinations Baseline default: Use TLS 1.2 and TLS 1.3
  • Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows Baseline default: EnabledLearn more

  • Turn on Enhanced Protected Mode Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Internet Control Panel > Security Page

  • Intranet Sites: Include all network paths (UNCs) Baseline default: DisabledLearn more
  • Turn on certificate address mismatch warning Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone

  • Access data sources across domains Baseline default: EnabledLearn more

    • Access data sources across domains Baseline default: Disable
  • Allow cut, copy or paste operations from the clipboard via script Baseline default: EnabledLearn more

    • Allow paste operations via script Baseline default: Disable
  • Allow drag and drop or copy and paste files Baseline default: EnabledLearn more

    • Allow drag and drop or copy and paste files Baseline default: Disable
  • Allow loading of XAML files Baseline default: EnabledLearn more

    • XAML Files Baseline default: Disable
  • Allow only approved domains to use ActiveX controls without prompt Baseline default: EnabledLearn more

    • Only allow approved domains to use ActiveX controls without prompt Baseline default: Enable
  • Allow only approved domains to use the TDC ActiveX control Baseline default: EnabledLearn more

    • Only allow approved domains to use the TDC ActiveX control Baseline default: Enable
  • Allow script-initiated windows without size or position constraints Baseline default: EnabledLearn more

    • Allow script-initiated windows without size or position constraints Baseline default: Disable
  • Allow scripting of Internet Explorer WebBrowser controls Baseline default: EnabledLearn more

    • Internet Explorer web browser control Baseline default: Disable
  • Allow scriptlets Baseline default: EnabledLearn more

    • Scriptlets Baseline default: Disable
  • Allow updates to status bar via script Baseline default: EnabledLearn more

    • Status bar updates via script Baseline default: Disable
  • Allow VBScript to run in Internet Explorer Baseline default: EnabledLearn more

    • Allow VBScript to run in Internet Explorer Baseline default: Disable
  • Automatic prompting for file downloads Baseline default: EnabledLearn more

    • Automatic prompting for file downloads Baseline default: Disable
  • Don't run antimalware programs against ActiveX controls Baseline default: EnabledLearn more

    • Don't run antimalware programs against ActiveX controls Baseline default: Disable
  • Download signed ActiveX controls Baseline default: EnabledLearn more

    • Download signed ActiveX controls Baseline default: Disable
  • Download unsigned ActiveX controls Baseline default: EnabledLearn more

    • Download unsigned ActiveX controls Baseline default: Disable
  • Enable dragging of content from different domains across windows Baseline default: EnabledLearn more

    • Enable dragging of content from different domains across windows Baseline default: Disable
  • Enable dragging of content from different domains within a window Baseline default: EnabledLearn more

    • Enable dragging of content from different domains within a window Baseline default: Disable
  • Include local path when user is uploading files to a server Baseline default: EnabledLearn more

    • Include local directory path when uploading files to a server Baseline default: Disable
  • Initialize and script ActiveX controls not marked as safe Baseline default: EnabledLearn more

    • Initialize and script ActiveX controls not marked as safe Baseline default: Disable
  • Java permissions Baseline default: EnabledLearn more

    • Java permissions Baseline default: Disable Java
  • Launching applications and files in an IFRAME Baseline default: EnabledLearn more

    • Launching applications and files in an IFRAME Baseline default: Disable
  • Logon options Baseline default: EnabledLearn more

    • Logon options Baseline default: Prompt for user name and password
  • Navigate windows and frames across different domains Baseline default: EnabledLearn more

    • Navigate windows and frames across different domains Baseline default: Disable
  • Run .NET Framework-reliant components not signed with Authenticode Baseline default: EnabledLearn more

    • Run .NET Framework-reliant components not signed with Authenticode Baseline default: Disable
  • Run .NET Framework-reliant components signed with Authenticode Baseline default: EnabledLearn more

    • Run .NET Framework-reliant components signed with Authenticode Baseline default: Disable
  • Show security warning for potentially unsafe files Baseline default: EnabledLearn more

    • Launching programs and unsafe files Baseline default: Prompt
  • Turn on Cross-Site Scripting Filter Baseline default: EnabledLearn more

    • Turn on Cross-Site Scripting (XSS) Filter Baseline default: Enable
  • Turn on Protected Mode Baseline default: EnabledLearn more

    • Protected Mode Baseline default: Enable
  • Turn on SmartScreen Filter scan Baseline default: EnabledLearn more

    • Use SmartScreen Filter Baseline default: Enable
  • Use Pop-up Blocker Baseline default: EnableLearn more

    • Use Pop-up Blocker Baseline default: Enable
  • Userdata persistence Baseline default: EnabledLearn more

    • Userdata persistence Baseline default: Disable
  • Web sites in less privileged Web content zones can navigate into this zone Baseline default: EnabledLearn more

    • Web sites in less privileged Web content zones can navigate into this zone Baseline default: Disable

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone

  • Don't run antimalware programs against ActiveX controls Baseline default: EnabledLearn more

    • Don't run antimalware programs against ActiveX controls Baseline default: Disable
  • Initialize and script ActiveX controls not marked as safe Baseline default: EnabledLearn more

    • Initialize and script ActiveX controls not marked as safe Baseline default: Disable
  • Java permissions Baseline default: EnabledLearn more

    • Java permissions Baseline default: High safety

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone

  • Don't run antimalware programs against ActiveX controls Baseline default: EnabledLearn more

    • Don't run antimalware programs against ActiveX controls Baseline default: Disable
  • Java permissions Baseline default: EnabledLearn more

    • Java permissions Baseline default: Disable Java

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone

  • Turn on SmartScreen Filter scan Baseline default: EnabledLearn more
    • Use SmartScreen Filter Baseline default: Enable

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone

  • Java permissions Baseline default: EnabledLearn more
    • Java permissions Baseline default: Disable Java

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone

  • Java permissions Baseline default: EnabledLearn more
    • Java permissions Baseline default: Disable Java

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone

  • Java permissions Baseline default: EnabledLearn more

    • Java permissions Baseline default: Disable Java
  • Turn on SmartScreen Filter scan Baseline default: EnabledLearn more

    • Use SmartScreen Filter Baseline default: Enable

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone

  • Java permissions Baseline default: EnabledLearn more
    • Java permissions Baseline default: Disable Java

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone

  • Access data sources across domains Baseline default: EnabledLearn more

    • Access data sources across domains Baseline default: Disable
  • Allow active scripting Baseline default: EnabledLearn more

    • Allow active scripting Baseline default: Disable
  • Allow binary and script behaviors Baseline default: EnabledLearn more

    • Allow binary and script Behaviors Baseline default: Disable
  • Allow cut, copy or paste operations from the clipboard via script Baseline default: EnabledLearn more

    • Allow paste operations via script Baseline default: Disable
  • Allow drag and drop or copy and paste files Baseline default: EnabledLearn more

    • Allow drag and drop or copy and paste files Baseline default: Disable
  • Allow file downloads Baseline default: EnabledLearn more

    • Allow file downloads Baseline default: Disable
  • Allow loading of XAML files Baseline default: EnabledLearn more

    • XAML Files Baseline default: Disable
  • Allow META REFRESH Baseline default: EnabledLearn more

    • Allow META REFRESH Baseline default: Disable
  • Allow only approved domains to use ActiveX controls without prompt Baseline default: EnabledLearn more

    • Only allow approved domains to use ActiveX controls without prompt Baseline default: Enable
  • Allow only approved domains to use the TDC ActiveX control Baseline default: EnabledLearn more

    • Only allow approved domains to use the TDC ActiveX control Baseline default: Enable
  • Allow script-initiated windows without size or position constraints Baseline default: EnabledLearn more

    • Allow script-initiated windows without size or position constraints Baseline default: Disable
  • Allow scripting of Internet Explorer WebBrowser controls Baseline default: EnabledLearn more

    • Internet Explorer web browser control Baseline default: Disable
  • Allow scriptlets Baseline default: EnabledLearn more

    • Scriptlets Baseline default: Disable
  • Allow updates to status bar via script Baseline default: EnabledLearn more

    • Status bar updates via script Baseline default: Disable
  • Allow VBScript to run in Internet Explorer Baseline default: EnabledLearn more

    • Allow VBScript to run in Internet Explorer Baseline default: Disable
  • Automatic prompting for file downloads Baseline default: EnabledLearn more

    • Automatic prompting for file downloads Baseline default: Disable
  • Don't run antimalware programs against ActiveX controls Baseline default: EnabledLearn more

    • Don't run antimalware programs against ActiveX controls Baseline default: Disable
  • Download signed ActiveX controls Baseline default: EnabledLearn more

    • Download signed ActiveX controls Baseline default: Disable
  • Download unsigned ActiveX controls Baseline default: EnabledLearn more

    • Download unsigned ActiveX controls Baseline default: Disable
  • Enable dragging of content from different domains across windows Baseline default: EnabledLearn more

    • Enable dragging of content from different domains across windows Baseline default: Disable
  • Enable dragging of content from different domains within a window Baseline default: EnabledLearn more

    • Enable dragging of content from different domains within a window Baseline default: Disable
  • Include local path when user is uploading files to a server Baseline default: EnabledLearn more

    • Include local directory path when uploading files to a server Baseline default: Disable
  • Initialize and script ActiveX controls not marked as safe Baseline default: EnabledLearn more

    • Initialize and script ActiveX controls not marked as safe Baseline default: Disable
  • Java permissions Baseline default: EnabledLearn more

    • Java permissions Baseline default: Disable Java
  • Launching applications and files in an IFRAME Baseline default: EnabledLearn more

    • Launching applications and files in an IFRAME Baseline default: Disable
  • Logon options Baseline default: EnabledLearn more

    • Logon options Baseline default: Anonymous logon
  • Navigate windows and frames across different domains Baseline default: EnabledLearn more

    • Navigate windows and frames across different domains Baseline default: Disable
  • Run .NET Framework-reliant components not signed with Authenticode Baseline default: EnabledLearn more

    • Run .NET Framework-reliant components not signed with Authenticode Baseline default: Disable
  • Run .NET Framework-reliant components signed with Authenticode Baseline default: EnabledLearn more

    • Run .NET Framework-reliant components signed with Authenticode Baseline default: Disable
  • Run ActiveX controls and plugins Baseline default: EnabledLearn more

    • Run ActiveX controls and plugins Baseline default: Disable
  • Script ActiveX controls marked safe for scripting Baseline default: EnabledLearn more

    • Script ActiveX controls marked safe for scripting Baseline default: Disable
  • Scripting of Java applets Baseline default: EnabledLearn more

    • Scripting of Java applets Baseline default: Disable
  • Show security warning for potentially unsafe files Baseline default: EnabledLearn more

    • Launching programs and unsafe files Baseline default: Disable
  • Turn on Cross-Site Scripting Filter Baseline default: EnabledLearn more

    • Turn on Cross-Site Scripting (XSS) Filter Baseline default: Enabled
  • Turn on Protected Mode Baseline default: EnabledLearn more

    • Protected Mode Baseline default: Enabled
  • Turn on SmartScreen Filter scan Baseline default: EnabledLearn more

    • Use SmartScreen Filter Baseline default: Enabled
  • Use Pop-up Blocker Baseline default: EnabledLearn more

    • Use Pop-up Blocker Baseline default: Enabled
  • Userdata persistence Baseline default: EnabledLearn more

    • Userdata persistence Baseline default: Disable
  • Web sites in less privileged Web content zones can navigate into this zone Baseline default: EnabledLearn more

    • Web sites in less privileged Web content zones can navigate into this zone Baseline default: Disable

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone

  • Don't run antimalware programs against ActiveX controls Baseline default: EnabledLearn more

    • Don't run antimalware programs against ActiveX controls Baseline default: Disable
  • Initialize and script ActiveX controls not marked as safe Baseline default: EnabledLearn more

    • Initialize and script ActiveX controls not marked as safe Baseline default: Disable
  • Java permissions Baseline default: EnabledLearn more

    • Java permissions Baseline default: High safety

Windows Components > Internet Explorer > Security Features

  • Allow fallback to SSL 3.0 (Internet Explorer) Baseline default: EnabledLearn more
    • Allow insecure fallback for: Baseline default: No Sites

Windows Components > Internet Explorer > Security Features > Add-on Management

  • Remove "Run this time" button for outdated ActiveX controls in Internet Explorer Baseline default: EnabledLearn more
  • Turn off blocking of outdated ActiveX controls for Internet Explorer Baseline default: DisabledLearn more

Windows Components > Internet Explorer > Security Features > Consistent Mime Handling

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > Mime Sniffing Safety Feature

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > MK Protocol Security Restriction

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > Notification bar

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > Protection From Zone Elevation

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > Restrict ActiveX Install

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > Restrict File Download

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Internet Explorer > Security Features > Scripted Window Security Restrictions

  • Internet Explorer Processes Baseline default: EnabledLearn more

Windows Components > Microsoft Defender Antivirus

  • Turn off routine remediation Baseline default: DisabledLearn more

Windows Components > Microsoft Defender Antivirus > MAPS

  • Configure the 'Block at First Sight' feature Baseline default: EnabledLearn more

Windows Components > Microsoft Defender Antivirus > Real-time Protection

  • Turn on process scanning whenever real-time protection is enabled Baseline default: EnabledLearn more

Windows Components > Remote Desktop Services > Remote Desktop Connection Client

  • Do not allow passwords to be saved Baseline default: EnabledLearn more

Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection

  • Do not allow drive redirection Baseline default: EnabledLearn more

Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security

  • Always prompt for password upon connection Baseline default: EnabledLearn more

  • Require secure RPC communication Baseline default: EnabledLearn more

  • Set client connection encryption level Baseline default: EnabledLearn more

    • Encryption Level Baseline default: High Level

Windows Components > RSS Feeds

  • Prevent downloading of enclosures Baseline default: EnabledLearn more

Windows Components > Windows Logon Options

  • Configure the transmission of the user's password in the content of MPR notifications sent by winlogon Baseline default: DisabledLearn more
  • Sign-in and lock last interactive user automatically after a restart Baseline default: DisabledLearn more

Windows Components > Windows PowerShell

  • Turn on PowerShell Script Block Logging Baseline default: EnabledLearn more
    • Log script block invocation start / stop events: Baseline default: False

Windows Components > Windows Remote Management (WinRM) > WinRM Client

  • Allow Basic authentication Baseline default: DisabledLearn more
  • Allow unencrypted traffic Baseline default: DisabledLearn more
  • Disallow Digest authentication Baseline default: EnabledLearn more

Windows Components > Windows Remote Management (WinRM) > WinRM Service

  • Allow Basic authentication Baseline default: DisabledLearn more
  • Allow unencrypted traffic Baseline default: DisabledLearn more
  • Disallow WinRM from storing RunAs credentials Baseline default: EnabledLearn more

Auditing

  • Account Logon Audit Credential Validation Baseline default: Success+ FailureLearn more
  • Account Logon Logoff Audit Account Lockout Baseline default: FailureLearn more
  • Account Logon Logoff Audit Group Membership Baseline default: SuccessLearn more
  • Account Logon Logoff Audit Logon Baseline default: Success+ FailureLearn more
  • Audit Authentication Policy Change Baseline default: SuccessLearn more
  • Audit Changes to Audit Policy Baseline default: SuccessLearn more
  • Audit File Share Access Baseline default: Success+ FailureLearn more
  • Audit Other Logon Logoff Events Baseline default: Success+ FailureLearn more
  • Audit Security Group Management Baseline default: SuccessLearn more
  • Audit Security System Extension Baseline default: SuccessLearn more
  • Audit Special Logon Baseline default: SuccessLearn more
  • Audit User Account Management Baseline default: Success+ FailureLearn more
  • Detailed Tracking Audit PNP Activity Baseline default: SuccessLearn more
  • Detailed Tracking Audit Process Creation Baseline default: SuccessLearn more
  • Object Access Audit Detailed File Share Baseline default: FailureLearn more
  • Object Access Audit Other Object Access Events Baseline default: Success+ FailureLearn more
  • Object Access Audit Removable Storage Baseline default: Success+ FailureLearn more
  • Policy Change Audit MPSSVC Rule Level Policy Change Baseline default: Success+ FailureLearn more
  • Policy Change Audit Other Policy Change Events Baseline default: FailureLearn more
  • Privilege Use Audit Sensitive Privilege Use Baseline default: SuccessLearn more
  • System Audit Other System Events Baseline default: Success+ FailureLearn more
  • System Audit Security State Change Baseline default: SuccessLearn more
  • System Audit System Integrity Baseline default: Success+ FailureLearn more

Browser

  • Allow Password Manager Baseline default: BlockLearn more
  • Allow Smart Screen Baseline default: AllowLearn more
  • Prevent Cert Error Overrides Baseline default: EnabledLearn more
  • Prevent Smart Screen Prompt Override Baseline default: EnabledLearn more
  • Prevent Smart Screen Prompt Override For Files Baseline default: EnabledLearn more

Data Protection

  • Allow Direct Memory Access Baseline default: BlockLearn more

Defender

  • Allow Archive Scanning Baseline default: Allowed. Scans the archive files.Learn more

  • Allow Behavior Monitoring Baseline default: Allowed. Turns on real-time behavior monitoring.Learn more

  • Allow Cloud Protection Baseline default: Allowed. Turns on Cloud Protection.Learn more

  • Allow Full Scan Removable Drive Scanning Baseline default: Allowed. Scans removable drives.Learn more

  • Allow On Access Protection Baseline default: Allowed.Learn more

  • Allow Realtime Monitoring Baseline default: Allowed. Turns on and runs the real-time monitoring service.Learn more

  • Allow scanning of all downloaded files and attachments Baseline default: Allowed.Learn more

  • Allow Script Scanning Baseline default: Allowed.Learn more

    • Block execution of potentially obfuscated scripts Baseline default: BlockLearn more
    • Block Win32 API calls from Office macros Baseline default: BlockLearn more
    • Block Office communication application from creating child processes Baseline default: BlockLearn more
    • Block all Office applications from creating child processes Baseline default: BlockLearn more
    • Block JavaScript or VBScript from launching downloaded executable content Baseline default: BlockLearn more
    • Block untrusted and unsigned processes that run from USB Baseline default: BlockLearn more
    • Block Adobe Reader from creating child processes Baseline default: BlockLearn more
    • Block credential stealing from the Windows local security authority subsystem Baseline default: BlockLearn more
    • Block process creations originating from PSExec and WMI commands Baseline default: AuditLearn more
    • Block Office applications from creating executable content Baseline default: BlockLearn more
    • Block Office applications from injecting code into other processes Baseline default: BlockLearn more
    • Block executable content from email client and webmail Baseline default: BlockLearn more
  • Cloud Block Level Baseline default: HighLearn more

  • Cloud Extended Timeout Baseline default: Configured Value: 50Learn more

  • Disable Local Admin Merge Baseline default: Disable Local Admin MergeLearn more

  • Enable Convert Warn To Block Baseline default: Warn verdicts are converted to blockLearn more

  • Enable File Hash Computation Baseline default: EnableLearn more

  • Enable Network Protection Baseline default: Enabled (block mode)Learn more

  • Hide Exclusions From Local Admins Baseline default: If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.Learn more

  • Oobe Enable Rtp And Sig Update Baseline default: If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.Learn more

  • Passive Remediation Baseline default: Configured Value: PASSIVEREMEDIATIONFLAGSENSEAUTOREMEDIATION: Passive Remediation Sense AutoRemediationLearn more

  • PUA Protection Baseline default: PUA Protection on. Detected items are blocked. They will show in history along with other threats.Learn more

  • Quick Scan Include Exclusions Baseline default: If you set this setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.Learn more

  • Real Time Scan Direction Baseline default: Monitor all files (bi-directional).Learn more

  • Submit Samples Consent Baseline default: Send all samples automatically.Learn more

Device Guard

  • Configure System Guard Launch Baseline default: Unmanaged Enables Secure Launch if supported by hardwareLearn more
  • Credential Guard Baseline default: (Enabled with UEFI lock) Turns on Credential Guard with UEFI lock.Learn more
  • Enable Virtualization Based Security Baseline default: Enable virtualization based security.Learn more
  • Machine Identity Isolation Baseline default: (Disabled) Machine password is only LSASS-bound and stored in $MACHINE.ACC registry key.Learn more
  • Require Platform Security Features Baseline default: Turns on VBS with Secure Boot.Learn more

Device Lock

  • Device Password Enabled Baseline default: EnabledLearn more
    • Device Password History Baseline default: Configured Value: 24Learn more
    • Min Device Password Length Baseline default: Configured Value: 14Learn more

Dma Guard

  • Device Enumeration Policy Baseline default: Block all (Most restrictive)Learn more

Experience

  • Allow Windows Spotlight (User) Baseline default: AllowLearn more
    • Allow Windows Consumer Features Baseline default: BlockLearn more
    • Allow Third Party Suggestions In Windows Spotlight (User) Baseline default: BlockLearn more

Firewall

  • Enable Domain Network Firewall Baseline default: TrueLearn more

    • Enable Log Success Connections Baseline default: Enable Logging Of Successful ConnectionsLearn more
    • Default Outbound Action Baseline default: AllowLearn more
    • Enable Log Dropped Packets Baseline default: Enable Logging Of Dropped PacketsLearn more
    • Disable Inbound Notifications Baseline default: TrueLearn more
    • Log Max File Size Baseline default: Configured Value: 16384Learn more
    • Default Inbound Action for Domain Profile Baseline default: BlockLearn more
  • Enable Private Network Firewall Baseline default: TrueLearn more

    • Log Max File Size Baseline default: Configured Value: 16384Learn more
    • Default Inbound Action for Private Profile Baseline default: BlockLearn more
    • Enable Log Success Connections Baseline default: Enable Logging Of Successful ConnectionsLearn more
    • Enable Log Dropped Packets Baseline default: Enable Logging Of Dropped PacketsLearn more
    • Default Outbound Action Baseline default: AllowLearn more
    • Disable Inbound Notifications Baseline default: TrueLearn more
  • Enable Public Network Firewall Baseline default: TrueLearn more

    • Enable Log Dropped Packets Baseline default: Enable Logging Of Dropped PacketsLearn more
    • Log Max File Size Baseline default: Configured Value: 16384Learn more
    • Default Outbound Action Baseline default: AllowLearn more
    • Disable Inbound Notifications Baseline default: TrueLearn more
    • Default Inbound Action for Public Profile Baseline default: BlockLearn more
    • Allow Local Policy Merge Baseline default: FalseLearn more
    • Enable Log Success Connections Baseline default: Enable Logging Of Successful ConnectionsLearn more
    • Allow Local Ipsec Policy Merge Baseline default: FalseLearn more

Kerberos

  • PK Init Hash Algorithm Configuration Baseline default: EnabledLearn more

    • PK Init Hash Algorithm SHA256 Baseline default: SupportedLearn more
    • PK Init Hash Algorithm SHA384 Baseline default: SupportedLearn more
    • PK Init Hash Algorithm SHA512 Baseline default: SupportedLearn more
    • PK Init Hash Algorithm SHA1 PK Init Hash Algorithm SHA1 Baseline default: Not SupportedLearn more

Lanman Server

  • Audit Client Does Not Support Encryption Baseline default: EnabledLearn more
  • Audit Client Does Not Support Signing Baseline default: EnabledLearn more
  • Audit Insecure Guest Logon Baseline default: EnabledLearn more
  • Auth Rate Limiter Delay In Ms Baseline default: Configured Value: 2000Learn more
  • Enable Auth Rate Limiter Baseline default: EnabledLearn more
  • Enable Mailslots Baseline default: DisabledLearn more
  • Max Smb2 Dialect Baseline default: SMB 3.1.1Learn more
  • Min Smb2 Dialect Baseline default: SMB 3.0.0Learn more

Lanman Workstation

  • Audit Insecure Guest Logon Baseline default: EnabledLearn more
  • Audit Server Does Not Support Encryption Baseline default: EnabledLearn more
  • Audit Server Does Not Support Signing Baseline default: EnabledLearn more
  • Enable Insecure Guest Logons Baseline default: DisabledLearn more
  • Enable Mailslots Baseline default: DisabledLearn more
  • Max SMB 2 Dialect Baseline default: SMB 3.1.1Learn more
  • Min SMB 2 Dialect Baseline default: SMB 3.0.0Learn more
  • Require Encryption Baseline default: DisabledLearn more

LAPS

  • Backup Directory Baseline default: Backup the password to Microsoft Entra ID onlyLearn more

Local Policies Security Options

  • Accounts Limit Local Account Use Of Blank Passwords To Console Logon Only Baseline default: EnabledLearn more
  • Interactive Logon Machine Inactivity Limit Baseline default: Configured Value: 900Learn more
  • Interactive Logon Smart Card Removal Behavior Baseline default: Lock WorkstationLearn more
  • Microsoft Network Client Digitally Sign Communications Always Baseline default: EnableLearn more
  • Microsoft Network Client Send Unencrypted Password To Third Party SMB Servers Baseline default: DisableLearn more
  • Microsoft Network Server Digitally Sign Communications Always Baseline default: EnableLearn more
  • Network Access Do Not Allow Anonymous Enumeration Of SAM Accounts Baseline default: EnabledLearn more
  • Network Access Do Not Allow Anonymous Enumeration Of Sam Accounts And Shares Baseline default: EnabledLearn more
  • Network Access Restrict Anonymous Access To Named Pipes And Shares Baseline default: EnableLearn more
  • Network Access Restrict Clients Allowed To Make Remote Calls To SAM Baseline default: Configured Value: O:BAG:BAD:(A;;RC;;;BA)Learn more
  • Network Security Do Not Store LAN Manager Hash Value On Next Password Change Baseline default: EnableLearn more
  • Network Security LAN Manager Authentication Level Baseline default: Send NTLMv2 responses only. Refuse LM and NTLMLearn more
  • Network Security Minimum Session Security For NTLMSSP Based Clients Baseline default: Require NTLM and 128-bit encryptionLearn more
  • Network Security Minimum Session Security For NTLMSSP Based Servers Baseline default: Require NTLM and 128-bit encryptionLearn more
  • User Account Control Behavior Of The Elevation Prompt For Administrators Baseline default: Prompt for consent on the secure desktopLearn more
  • User Account Control Behavior Of The Elevation Prompt For Standard Users Baseline default: Automatically deny elevation requestsLearn more
  • User Account Control Detect Application Installations And Prompt For Elevation Baseline default: EnableLearn more
  • User Account Control Only Elevate UI Access Applications That Are Installed In Secure Locations Baseline default: Enabled: Application runs with UIAccess integrity only if it resides in secure location.Learn more
  • User Account Control Run All Administrators In Admin Approval Mode Baseline default: EnabledLearn more
  • User Account Control Use Admin Approval Mode Baseline default: EnableLearn more
  • User Account Control Virtualize File And Registry Write Failures To Per User Locations Baseline default: EnabledLearn more

Local Security Authority

  • Configure Lsa Protected Process Baseline default: Enabled with UEFI lock. LSA will run as protected process and this configuration is UEFI locked.Learn more

Microsoft App Store

  • Allow Game DVR Baseline default: BlockLearn more
  • MSI Allow User Control Over Install Baseline default: DisabledLearn more
  • MSI Always Install With Elevated Privileges Baseline default: DisabledLearn more

Microsoft Edge

SmartScreen settings

  • Configure Microsoft Defender SmartScreen Baseline default: Enabled
  • Prevent bypassing Microsoft Defender SmartScreen prompts for sites Baseline default: Enabled

Privacy

  • Let Apps Activate With Voice Above Lock Baseline default: Force deny. Windows apps cannot be activated by voice while the screen is locked, and users cannot change it.Learn more

Search

  • Allow Indexing Encrypted Stores Or Items Baseline default: BlockLearn more

Smart Screen

  • Enable Smart Screen In Shell Baseline default: EnabledLearn more
  • Prevent Override For Files In Shell Baseline default: EnabledLearn more

Enhanced Phishing Protection

  • Notify Malicious Baseline default: Enabled
  • Notify Password Reuse Baseline default: Enabled
  • Notify Unsafe App Baseline default: Enabled
  • Service Enabled Baseline default: Enabled

Sudo

  • Enable Sudo Baseline default: Sudo is disabled.Learn more

System Services

  • Configure Xbox Accessory Management Service Startup Mode Baseline default: DisabledLearn more
  • Configure Xbox Live Auth Manager Service Startup Mode Baseline default: DisabledLearn more
  • Configure Xbox Live Game Save Service Startup Mode Baseline default: DisabledLearn more
  • Configure Xbox Live Networking Service Startup Mode Baseline default: DisabledLearn more

Task Scheduler

  • Enable Xbox Game Save Task Baseline default: DisabledLearn more

User Rights

  • Access From Network Baseline default: Configured Values: Administrators (*S-1-5-32-544), Remote Desktop Users (*S-1-5-32-555)Learn more
  • Allow Local Log On Baseline default: Configured Values: Administrators (*S-1-5-32-544), Users (*S-1-5-32-545)Learn more
  • Backup Files And Directories Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Create Global Objects Baseline default: Configured Values: Administrators (*S-1-5-32-544), Local Service (*S-1-5-19), Network Service (*S-1-5-20), Service (*S-1-5-6)Learn more
  • Create Page File Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Debug Programs Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Deny Access From Network Baseline default: Configured Value: NT AUTHORITY\Local Account (*S-1-5-113)Learn more
  • Deny Remote Desktop Services Log On Baseline default: Configured Value: NT AUTHORITY\Local Account (*S-1-5-113)Learn more
  • Impersonate Client Baseline default: Configured Values: Administrators (*S-1-5-32-544), Service (*S-1-5-6), Local Service (*S-1-5-19), Network Service (*S-1-5-20), Windows restricted services (*S-1-5-99-216390572-1995538116-3857911515-2404958512-2623887229)Learn more
  • Load Unload Device Drivers Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Manage Auditing And Security Log Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Manage Volume Baseline default: Configured Value: Administrators (*S-1-5-32-544) Learn more
  • Modify Firmware Environment Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Profile Single Process Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Remote Shutdown Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Restore Files And Directories Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more
  • Take Ownership Baseline default: Configured Value: Administrators (*S-1-5-32-544)Learn more

Virtualization Based Technology

  • Hypervisor Enforced Code Integrity Baseline default: (Enabled with UEFI lock) Turns on Hypervisor-Protected Code Integrity with UEFI lock.Learn more

Wi-Fi Settings

  • Allow Auto Connect To Wi Fi Sense Hotspots Baseline default: BlockLearn more
  • Allow Internet Sharing Baseline default: BlockLearn more

Windows Hello For Business

  • Facial Features Use Enhanced Anti Spoofing Baseline default: trueLearn more

Windows Ink Workspace

  • Allow Windows Ink Workspace Baseline default: Ink workspace is enabled (feature is turned on), but the user cannot access it above the lock screen.Learn more

::: zone-end

::: zone pivot="mdm-25h2"

Security Baseline for Windows, version 25H2

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…