Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article is a reference for the settings that are available in the Windows Mobile Device Management (MDM) security baseline for Microsoft Intune.
About this reference article
Each security baseline is a group of preconfigured Windows settings that help you apply and enforce granular security settings that the relevant security teams recommend. You can also customize each baseline you deploy to enforce only those settings and values you require. When you create a security baseline profile in Intune, you're creating a template that consists of multiple device configuration settings.
The details that display in this article are based on baseline version you select at the top of the article. For each version, this article displays:
- A list of each setting with its configuration as found in the default instance of that baseline version.
- When available, a link to the underlying configuration service provider (CSP) documentation or other related content from the relevant product group that provides context and possibly additional details for a settings use.
When a new version of a baseline becomes available, it replaces the previous version. Profile instances that you've created prior to the availability of a new version:
- Become read-only. You can continue to use those profiles but can't edit them to change their configuration.
- Can be updated to the current version. After you update a profile to the current baseline version, you can edit the profile to modify settings.
To learn more about using security baselines, see:
Security Baseline for Windows, version 25H2
The settings in this baseline are taken from the Windows 11 version 25H2 security baseline as found in the Security Compliance Toolkit and Baselines from the Microsoft Download Center, and include only the settings that apply to Windows devices managed through Intune. When available, the setting name links to the source Configuration Service Provider (CSP), and then displays that settings default configuration in the baseline.
Note
The Disable Internet Explorer 11 Launch Via COM Automation setting was added to the version 25H2 baseline in the June 2026 service update, after the baseline first released. Profiles you created before this update don't apply the new setting automatically:
- For a profile you deployed before this update, edit the profile and save it. The setting appears with its baseline default value, and Intune deploys the change to the assigned groups at the next device check-in. If you don't edit and save the profile, the setting doesn't take effect.
- Profiles that you create with the version 25H2 baseline, or that you update to version 25H2, include the setting by default.
Administrative Templates
Control Panel > Personalization
Prevent enabling lock screen camera
Baseline default: Enabled
Learn morePrevent enabling lock screen slide show
Baseline default: Enabled
Learn more
MS Security Guide
Apply UAC restrictions to local accounts on network logons
Baseline default: Enabled
Learn moreConfigure SMB v1 client driver
Baseline default: Enabled
Learn more- Configure MrxSmb10 driver
Baseline default: Disable driver (recommended)
- Configure MrxSmb10 driver
Configure SMB v1 server
Baseline default: Disabled
Learn moreEnable Structured Exception Handling Overwrite Protection (SEHOP)
Baseline default: Enabled
Learn more
MSS (Legacy)
MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)
Baseline default: Enabled
Learn more- DisableIPSourceRouting IPv6 (Device)
Baseline default: Highest protection, source routing is completely disabled
- DisableIPSourceRouting IPv6 (Device)
MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)
Baseline default: Enabled
Learn more- DisableIPSourceRouting (Device)
Baseline default: Highest protection, source routing is completely disabled
- DisableIPSourceRouting (Device)
MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes
Baseline default: Disabled
Learn moreMSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers
Baseline default: Enabled
Learn more
Network > DNS Client
- Turn off multicast name resolution
Baseline default: Enabled
Learn more
Network > Network Connections
- Prohibit use of Internet Connection Sharing on your DNS domain network
Baseline default: Enabled
Learn more
Network > Network Provider
- Hardened UNC Paths
Baseline default: Enabled
Learn moreHardened UNC Paths: (Device)
Baseline defaults:Name Value \\*\SYSVOLRequireMutualAuthentication=1,RequireIntegrity=1 \\*\NETLOGONRequireMutualAuthentication=1,RequireIntegrity=1
Network > Windows Connection Manager
- Prohibit connection to non-domain networks when connected to domain authenticated network
Baseline default: Enabled
Learn more
Printers
Configure Redirection Guard
Baseline default: Enabled Learn more- Redirection Guard Options (Device)
Baseline default: Redirection Guard Enabled
- Redirection Guard Options (Device)
Configure RPC connection settings
Baseline default: Enabled
Learn more- Use authentication for outgoing RPC connections: (Device)
Baseline default: Default - Protocol to use for outgoing RPC connections: (Device)
Baseline default: RPC over TCP
- Use authentication for outgoing RPC connections: (Device)
Configure RPC listener settings
Baseline default: Enabled
Learn more- Protocols to allow for incoming RPC connections: (Device)
Baseline default: RPC over TCP - Authentication protocol to use for incoming RPC connections: (Device)
Baseline default: Negotiate
- Protocols to allow for incoming RPC connections: (Device)
Configure RPC over TCP port
Baseline default: Enabled
Learn more- RPC over TCP port (Device)
Baseline default: 0
- RPC over TCP port (Device)
Limits print driver installation to Administrators
Baseline default: Enabled
Learn moreManage processing of Queue-specific files
Baseline default: Enabled
Learn more- Manage processing of Queue-Specific files: (Device)
Baseline default: Limit Queue-specific files to Color profiles
- Manage processing of Queue-Specific files: (Device)
Start Menu and Taskbar > Notifications
- Turn off toast notifications on the lock screen (User)
Baseline default: Enabled
Learn more
System > Audit Process Creation
- Include command line in process creation events
Baseline default: Enabled
Learn more
System > Credentials Delegation
Encryption Oracle Remediation
Baseline default: Enabled
Learn more- Protection Level: (Device)
Baseline default: Force Updated Clients
- Protection Level: (Device)
Remote host allows delegation of non-exportable credentials
Baseline default: Enabled
Learn more
System > Device Installation > Device Installation Restrictions
- Prevent installation of devices using drivers that match these device setup classes
Baseline default: Enabled
Learn more- Also apply to matching devices that are already installed
Baseline default: True - Prevented Classes
Baseline default: {d48179be-ec20-11d1-b6b8-00c04fa372a7}
- Also apply to matching devices that are already installed
System > Early Launch Antimalware
- Boot-Start Driver Initialization Policy
Baseline default: Enabled
Learn more- Choose the boot-start drivers that can be initialized:
Baseline default: Good, unknown and bad but critical
- Choose the boot-start drivers that can be initialized:
System > Group Policy
- Configure registry policy processing
Baseline default: Enabled
Learn more- Do not apply during periodic background processing (Device)
Baseline default: False - Process even if the Group Policy objects have not changed (Device)
Baseline default: True
- Do not apply during periodic background processing (Device)
System > Internet Communication Management > Internet Communication settings
Turn off downloading of print drivers over HTTP
Baseline default: Enabled
Learn moreTurn off Internet download for Web publishing and online ordering wizards
Baseline default: Enabled
Learn more
System > Local Security Authority
- Allow Custom SSPs and APs to be loaded into LSASS
Baseline default: Disabled
Learn more
System > Power Management > Sleep Settings
Allow standby states (S1-S3) when sleeping (on battery)
Baseline default: Disabled
Learn moreAllow standby states (S1-S3) when sleeping (plugged in)
Baseline default: Disabled
Learn moreRequire a password when a computer wakes (on battery)
Baseline default: Enabled
Learn moreRequire a password when a computer wakes (plugged in)
Baseline default: Enabled
Learn more
System > Remote Assistance
- Configure Solicited Remote Assistance
Baseline default: Disabled
Learn more
System > Remote Procedure Call
- Restrict Unauthenticated RPC clients
Baseline default: Enabled
Learn more- RPC Runtime Unauthenticated Client Restriction to Apply:
Baseline default: Authenticated
- RPC Runtime Unauthenticated Client Restriction to Apply:
Windows Components > App runtime
- Allow Microsoft accounts to be optional
Baseline default: Enabled
Learn more
Windows Components > AutoPlay Policies
Disallow Autoplay for non-volume devices
Baseline default: Enabled
Learn moreSet the default behavior for AutoRun
Baseline default: Enabled
Learn more- Default AutoRun Behavior
Baseline default: Do not execute any autorun commands
- Default AutoRun Behavior
Turn off Autoplay
Baseline default: Enabled
Learn more- Turn off Autoplay on:
Baseline default: All drives
- Turn off Autoplay on:
Windows Components > BitLocker Drive Encryption > Fixed Data Drives
- Deny write access to fixed drives not protected by BitLocker
Baseline default: Disabled
Learn more
Windows Components > BitLocker Drive Encryption > Removable Data Drives
- Deny write access to removable drives not protected by BitLocker
Baseline default: Enabled
Learn more- Do not allow write access to devices configured in another organization
Baseline default: False
- Do not allow write access to devices configured in another organization
Windows Components > Credential User Interface
- Enumerate administrator accounts on elevation
Baseline default: Disabled
Learn more
Windows Components > Event Log Service > Application
- Specify the maximum log file size (KB)
Baseline default: Enabled
Learn more- Maximum Log Size (KB)
Baseline default: 32768
- Maximum Log Size (KB)
Windows Components > Event Log Service > Security
- Specify the maximum log file size (KB)
Baseline default: Enabled
Learn more- Maximum Log Size (KB)
Baseline default: 196608
- Maximum Log Size (KB)
Windows Components > Event Log Service > System
- Specify the maximum log file size (KB)
Baseline default: Enabled
Learn more- Maximum Log Size (KB)
Baseline default: 32768
- Maximum Log Size (KB)
Windows Components > File Explorer
Configure Windows Defender SmartScreen
Baseline default: Enabled
Learn more- Pick one of the following settings: (Device)
Baseline default: Warn and prevent bypass
- Pick one of the following settings: (Device)
Turn off Data Execution Prevention for Explorer
Baseline default: Disabled
Learn moreTurn off heap termination on corruption
Baseline default: Disabled
Learn more
Windows Components > Internet Explorer
Disable Internet Explorer 11 Launch Via COM Automation
Baseline default: Enabled
Learn morePrevent bypassing SmartScreen Filter warnings
Baseline default: Enabled
Learn morePrevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet
Baseline default: Enabled
Learn morePrevent managing SmartScreen Filter
Baseline default: Enabled
Learn more- Select SmartScreen Filter mode
Baseline default: On
- Select SmartScreen Filter mode
Prevent per-user installation of ActiveX controls
Baseline default: Enabled
Learn moreSecurity Zones: Do not allow users to add/delete sites
Baseline default: Enabled
Learn moreSecurity Zones: Do not allow users to change policies
Baseline default: Enabled
Learn moreSecurity Zones: Use only machine settings
Baseline default: Enabled
Learn moreSpecify use of ActiveX Installer Service for installation of ActiveX controls
Baseline default: Enabled
Learn moreTurn off Crash Detection
Baseline default: Enabled
Learn moreTurn off the Security Settings Check feature
Baseline default: Disabled
Learn moreTurn on the auto-complete feature for user names and passwords on forms (User)
Baseline default: Disabled
Learn more
Windows Components > Internet Explorer > Internet Control Panel
- Prevent ignoring certificate errors
Baseline default: Enabled
Learn more
Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Allow software to run or install even if the signature is invalid
Baseline default: Disabled
Learn moreCheck for server certificate revocation
Baseline default: Enabled
Learn moreCheck for signatures on downloaded programs
Baseline default: Enabled
Learn moreDo not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled
Baseline default: Enabled
Learn moreTurn off encryption support
Baseline default: Enabled
Learn more- Secure Protocol combinations
Baseline default: Use TLS 1.1 and TLS 1.2
- Secure Protocol combinations
Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows
Baseline default: Enabled
Learn moreTurn on Enhanced Protected Mode
Baseline default: Enabled
Learn more
Windows Components > Internet Explorer > Internet Control Panel > Security Page
Intranet Sites: Include all network paths (UNCs)
Baseline default: Disabled
Learn moreTurn on certificate address mismatch warning
Baseline default: Enabled
Learn more
Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Access data sources across domains
Baseline default: Enabled
Learn more- Access data sources across domains
Baseline default: Disable
- Access data sources across domains
Allow cut, copy or paste operations from the clipboard via script
Baseline default: Enabled
Learn more- Allow paste operations via script
Baseline default: Disable
- Allow paste operations via script
Allow drag and drop or copy and paste files
Baseline default: Enabled
Learn more- Allow drag and drop or copy and paste files
Baseline default: Disable
- Allow drag and drop or copy and paste files
Allow loading of XAML files
Baseline default: Enabled
Learn more- XAML Files
Baseline default: Disable
- XAML Files
Allow only approved domains to use ActiveX controls without prompt
Baseline default: Enabled
Learn more- Only allow approved domains to use ActiveX controls without prompt
Baseline default: Enable
- Only allow approved domains to use ActiveX controls without prompt
Allow only approved domains to use the TDC ActiveX control
Baseline default: Enabled
Learn more- Only allow approved domains to use the TDC ActiveX control
Baseline default: Enable
- Only allow approved domains to use the TDC ActiveX control
Allow script-initiated windows without size or position constraints
Baseline default: Enabled
Learn more- Allow script-initiated windows without size or position constraints
Baseline default: Disable
- Allow script-initiated windows without size or position constraints
Allow scripting of Internet Explorer WebBrowser controls
Baseline default: Enabled
Learn more- Internet Explorer web browser control
Baseline default: Disable
- Internet Explorer web browser control
Allow scriptlets
Baseline default: Enabled
Learn more- Scriptlets
Baseline default: Disable
- Scriptlets
Allow updates to status bar via script
Baseline default: Enabled
Learn more- Status bar updates via script
Baseline default: Disable
- Status bar updates via script
Allow VBScript to run in Internet Explorer
Baseline default: Enabled
Learn more- Allow VBScript to run in Internet Explorer
Baseline default: Disable
- Allow VBScript to run in Internet Explorer
Automatic prompting for file downloads
Baseline default: Enabled
Learn more- Automatic prompting for file downloads
Baseline default: Disable
- Automatic prompting for file downloads
Don't run antimalware programs against ActiveX controls
Baseline default: Enabled
Learn more- Don't run antimalware programs against ActiveX controls
Baseline default: Disable
- Don't run antimalware programs against ActiveX controls
Download signed ActiveX controls
Baseline default: Enabled
Learn more- Download signed ActiveX controls
Baseline default: Disable
- Download signed ActiveX controls
Download unsigned ActiveX controls
Baseline default: Enabled
Learn more- Download unsigned ActiveX controls
Baseline default: Disable
- Download unsigned ActiveX controls
Enable dragging of content from different domains across windows
Baseline default: Enabled
Learn more- Enable dragging of content from different domains across windows
Baseline default: Disable
- Enable dragging of content from different domains across windows
Enable dragging of content from different domains within a window
Baseline default: Enabled
Learn more- Enable dragging of content from different domains within a window
Baseline default: Disable
- Enable dragging of content from different domains within a window
Include local path when user is uploading files to a server
Baseline default: Enabled
Learn more- Include local directory path when uploading files to a server
Baseline default: Disable
- Include local directory path when uploading files to a server
Initialize and script ActiveX controls not marked as safe
Baseline default: Enabled
Learn more- Initialize and script ActiveX controls not marked as safe
Baseline default: Disable
- Initialize and script ActiveX controls not marked as safe
Java permissions
Baseline default: Enabled
Learn more- Java permissions
Baseline default: Disable Java
- Java permissions
Launching applications and files in an IFRAME
Baseline default: Enabled
Learn more- Launching applications and files in an IFRAME
Baseline default: Disable
- Launching applications and files in an IFRAME
Logon options
Baseline default: Enabled
Learn more- Logon options
Baseline default: Prompt for user name and password
- Logon options
Navigate windows and frames across different domains
Baseline default: Enabled
Learn more- Navigate windows and frames across different domains
Baseline default: Disable
- Navigate windows and frames across different domains
Run .NET Framework-reliant components not signed with Authenticode
Baseline default: Enabled
Learn more- Run .NET Framework-reliant components not signed with Authenticode
Baseline default: Disable
- Run .NET Framework-reliant components not signed with Authenticode
Run .NET Framework-reliant components signed with Authenticode
Baseline default: Enabled
Learn more- Run .NET Framework-reliant components signed with Authenticode
Baseline default: Disable
- Run .NET Framework-reliant components signed with Authenticode
Show security warning for potentially unsafe files
Baseline default: Enabled
Learn more- Launching programs and unsafe files
Baseline default: Prompt
- Launching programs and unsafe files
Turn on Cross-Site Scripting Filter
Baseline default: Enabled
Learn more- Turn on Cross-Site Scripting (XSS) Filter
Baseline default: Enable
- Turn on Cross-Site Scripting (XSS) Filter
Turn on Protected Mode
Baseline default: Enabled
Learn more- Protected Mode
Baseline default: Enable
- Protected Mode
Turn on SmartScreen Filter scan
Baseline default: Enabled
Learn more- Use SmartScreen Filter
Baseline default: Enable
- Use SmartScreen Filter
Use Pop-up Blocker
Baseline default: Enable
Learn more- Use Pop-up Blocker
Baseline default: Enable
- Use Pop-up Blocker
Userdata persistence
Baseline default: Enabled
Learn more- Userdata persistence
Baseline default: Disable
- Userdata persistence
Web sites in less privileged Web content zones can navigate into this zone
Baseline default: Enabled
Learn more- Web sites in less privileged Web content zones can navigate into this zone
Baseline default: Disable
- Web sites in less privileged Web content zones can navigate into this zone
Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Don't run antimalware programs against ActiveX controls
Baseline default: Enabled
Learn more- Don't run antimalware programs against ActiveX controls
Baseline default: Disable
- Don't run antimalware programs against ActiveX controls
Initialize and script ActiveX controls not marked as safe
Baseline default: Enabled
Learn more- Initialize and script ActiveX controls not marked as safe
Baseline default: Disable
- Initialize and script ActiveX controls not marked as safe
Java permissions
Baseline default: Enabled
Learn more- Java permissions
Baseline default: High safety
- Java permissions
Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Don't run antimalware programs against ActiveX controls
Baseline default: Enabled
Learn more- Don't run antimalware programs against ActiveX controls
Baseline default: Disable
- Don't run antimalware programs against ActiveX controls
Java permissions
Baseline default: Enabled
Learn more- Java permissions
Baseline default: Disable Java
- Java permissions
Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
- Turn on SmartScreen Filter scan
Baseline default: Enabled
Learn more