Edit

Windows MDM security baseline settings reference for Microsoft Intune

This article is a reference for the settings that are available in the Windows Mobile Device Management (MDM) security baseline for Microsoft Intune.

About this reference article

Each security baseline is a group of preconfigured Windows settings that help you apply and enforce granular security settings that the relevant security teams recommend. You can also customize each baseline you deploy to enforce only those settings and values you require. When you create a security baseline profile in Intune, you're creating a template that consists of multiple device configuration settings.

The details that display in this article are based on baseline version you select at the top of the article. For each version, this article displays:

  • A list of each setting with its configuration as found in the default instance of that baseline version.
  • When available, a link to the underlying configuration service provider (CSP) documentation or other related content from the relevant product group that provides context and possibly additional details for a settings use.

When a new version of a baseline becomes available, it replaces the previous version. Profile instances that you've created prior to the availability of a new version:

  • Become read-only. You can continue to use those profiles but can't edit them to change their configuration.
  • Can be updated to the current version. After you update a profile to the current baseline version, you can edit the profile to modify settings.

To learn more about using security baselines, see:

Security Baseline for Windows, version 25H2

The settings in this baseline are taken from the Windows 11 version 25H2 security baseline as found in the Security Compliance Toolkit and Baselines from the Microsoft Download Center, and include only the settings that apply to Windows devices managed through Intune. When available, the setting name links to the source Configuration Service Provider (CSP), and then displays that settings default configuration in the baseline.

Note

The Disable Internet Explorer 11 Launch Via COM Automation setting was added to the version 25H2 baseline in the June 2026 service update, after the baseline first released. Profiles you created before this update don't apply the new setting automatically:

  • For a profile you deployed before this update, edit the profile and save it. The setting appears with its baseline default value, and Intune deploys the change to the assigned groups at the next device check-in. If you don't edit and save the profile, the setting doesn't take effect.
  • Profiles that you create with the version 25H2 baseline, or that you update to version 25H2, include the setting by default.

Administrative Templates

Control Panel > Personalization

  • Prevent enabling lock screen camera
    Baseline default: Enabled
    Learn more

  • Prevent enabling lock screen slide show
    Baseline default: Enabled
    Learn more

MS Security Guide

  • Apply UAC restrictions to local accounts on network logons
    Baseline default: Enabled
    Learn more

  • Configure SMB v1 client driver
    Baseline default: Enabled
    Learn more

    • Configure MrxSmb10 driver
      Baseline default: Disable driver (recommended)
  • Configure SMB v1 server
    Baseline default: Disabled
    Learn more

  • Enable Structured Exception Handling Overwrite Protection (SEHOP)
    Baseline default: Enabled
    Learn more

MSS (Legacy)

  • MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)
    Baseline default: Enabled
    Learn more

    • DisableIPSourceRouting IPv6 (Device)
      Baseline default: Highest protection, source routing is completely disabled
  • MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)
    Baseline default: Enabled
    Learn more

    • DisableIPSourceRouting (Device)
      Baseline default: Highest protection, source routing is completely disabled
  • MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes
    Baseline default: Disabled
    Learn more

  • MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers
    Baseline default: Enabled
    Learn more

Network > DNS Client

  • Turn off multicast name resolution
    Baseline default: Enabled
    Learn more

Network > Network Connections

  • Prohibit use of Internet Connection Sharing on your DNS domain network
    Baseline default: Enabled
    Learn more

Network > Network Provider

  • Hardened UNC Paths
    Baseline default: Enabled
    Learn more
    • Hardened UNC Paths: (Device)
      Baseline defaults:

      Name Value
      \\*\SYSVOL RequireMutualAuthentication=1,RequireIntegrity=1
      \\*\NETLOGON RequireMutualAuthentication=1,RequireIntegrity=1

Network > Windows Connection Manager

  • Prohibit connection to non-domain networks when connected to domain authenticated network
    Baseline default: Enabled
    Learn more

Printers

  • Configure Redirection Guard
    Baseline default: Enabled Learn more

    • Redirection Guard Options (Device)
      Baseline default: Redirection Guard Enabled
  • Configure RPC connection settings
    Baseline default: Enabled
    Learn more

    • Use authentication for outgoing RPC connections: (Device)
      Baseline default: Default
    • Protocol to use for outgoing RPC connections: (Device)
      Baseline default: RPC over TCP
  • Configure RPC listener settings
    Baseline default: Enabled
    Learn more

    • Protocols to allow for incoming RPC connections: (Device)
      Baseline default: RPC over TCP
    • Authentication protocol to use for incoming RPC connections: (Device)
      Baseline default: Negotiate
  • Configure RPC over TCP port
    Baseline default: Enabled
    Learn more

    • RPC over TCP port (Device)
      Baseline default: 0
  • Limits print driver installation to Administrators
    Baseline default: Enabled
    Learn more

  • Manage processing of Queue-specific files
    Baseline default: Enabled
    Learn more

    • Manage processing of Queue-Specific files: (Device)
      Baseline default: Limit Queue-specific files to Color profiles

Start Menu and Taskbar > Notifications

  • Turn off toast notifications on the lock screen (User)
    Baseline default: Enabled
    Learn more

System > Audit Process Creation

  • Include command line in process creation events
    Baseline default: Enabled
    Learn more

System > Credentials Delegation

  • Encryption Oracle Remediation
    Baseline default: Enabled
    Learn more

    • Protection Level: (Device)
      Baseline default: Force Updated Clients
  • Remote host allows delegation of non-exportable credentials
    Baseline default: Enabled
    Learn more

System > Device Installation > Device Installation Restrictions

  • Prevent installation of devices using drivers that match these device setup classes
    Baseline default: Enabled
    Learn more
    • Also apply to matching devices that are already installed
      Baseline default: True
    • Prevented Classes
      Baseline default: {d48179be-ec20-11d1-b6b8-00c04fa372a7}

System > Early Launch Antimalware

  • Boot-Start Driver Initialization Policy
    Baseline default: Enabled
    Learn more
    • Choose the boot-start drivers that can be initialized:
      Baseline default: Good, unknown and bad but critical

System > Group Policy

  • Configure registry policy processing
    Baseline default: Enabled
    Learn more
    • Do not apply during periodic background processing (Device)
      Baseline default: False
    • Process even if the Group Policy objects have not changed (Device)
      Baseline default: True

System > Internet Communication Management > Internet Communication settings

  • Turn off downloading of print drivers over HTTP
    Baseline default: Enabled
    Learn more

  • Turn off Internet download for Web publishing and online ordering wizards
    Baseline default: Enabled
    Learn more

System > Local Security Authority

  • Allow Custom SSPs and APs to be loaded into LSASS
    Baseline default: Disabled
    Learn more

System > Power Management > Sleep Settings

  • Allow standby states (S1-S3) when sleeping (on battery)
    Baseline default: Disabled
    Learn more

  • Allow standby states (S1-S3) when sleeping (plugged in)
    Baseline default: Disabled
    Learn more

  • Require a password when a computer wakes (on battery)
    Baseline default: Enabled
    Learn more

  • Require a password when a computer wakes (plugged in)
    Baseline default: Enabled
    Learn more

System > Remote Assistance

  • Configure Solicited Remote Assistance
    Baseline default: Disabled
    Learn more

System > Remote Procedure Call

  • Restrict Unauthenticated RPC clients
    Baseline default: Enabled
    Learn more
    • RPC Runtime Unauthenticated Client Restriction to Apply:
      Baseline default: Authenticated

Windows Components > App runtime

  • Allow Microsoft accounts to be optional
    Baseline default: Enabled
    Learn more

Windows Components > AutoPlay Policies

  • Disallow Autoplay for non-volume devices
    Baseline default: Enabled
    Learn more

  • Set the default behavior for AutoRun
    Baseline default: Enabled
    Learn more

    • Default AutoRun Behavior
      Baseline default: Do not execute any autorun commands
  • Turn off Autoplay
    Baseline default: Enabled
    Learn more

    • Turn off Autoplay on:
      Baseline default: All drives

Windows Components > BitLocker Drive Encryption > Fixed Data Drives

  • Deny write access to fixed drives not protected by BitLocker
    Baseline default: Disabled
    Learn more

Windows Components > BitLocker Drive Encryption > Removable Data Drives

  • Deny write access to removable drives not protected by BitLocker
    Baseline default: Enabled
    Learn more
    • Do not allow write access to devices configured in another organization
      Baseline default: False

Windows Components > Credential User Interface

  • Enumerate administrator accounts on elevation
    Baseline default: Disabled
    Learn more

Windows Components > Event Log Service > Application

  • Specify the maximum log file size (KB)
    Baseline default: Enabled
    Learn more
    • Maximum Log Size (KB)
      Baseline default: 32768

Windows Components > Event Log Service > Security

  • Specify the maximum log file size (KB)
    Baseline default: Enabled
    Learn more
    • Maximum Log Size (KB)
      Baseline default: 196608

Windows Components > Event Log Service > System

  • Specify the maximum log file size (KB)
    Baseline default: Enabled
    Learn more
    • Maximum Log Size (KB)
      Baseline default: 32768

Windows Components > File Explorer

  • Configure Windows Defender SmartScreen
    Baseline default: Enabled
    Learn more

    • Pick one of the following settings: (Device)
      Baseline default: Warn and prevent bypass
  • Turn off Data Execution Prevention for Explorer
    Baseline default: Disabled
    Learn more

  • Turn off heap termination on corruption
    Baseline default: Disabled
    Learn more

Windows Components > Internet Explorer

  • Disable Internet Explorer 11 Launch Via COM Automation
    Baseline default: Enabled
    Learn more

  • Prevent bypassing SmartScreen Filter warnings
    Baseline default: Enabled
    Learn more

  • Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet
    Baseline default: Enabled
    Learn more

  • Prevent managing SmartScreen Filter
    Baseline default: Enabled
    Learn more

    • Select SmartScreen Filter mode
      Baseline default: On
  • Prevent per-user installation of ActiveX controls
    Baseline default: Enabled
    Learn more

  • Security Zones: Do not allow users to add/delete sites
    Baseline default: Enabled
    Learn more

  • Security Zones: Do not allow users to change policies
    Baseline default: Enabled
    Learn more

  • Security Zones: Use only machine settings
    Baseline default: Enabled
    Learn more

  • Specify use of ActiveX Installer Service for installation of ActiveX controls
    Baseline default: Enabled
    Learn more

  • Turn off Crash Detection
    Baseline default: Enabled
    Learn more

  • Turn off the Security Settings Check feature
    Baseline default: Disabled
    Learn more

  • Turn on the auto-complete feature for user names and passwords on forms (User)
    Baseline default: Disabled
    Learn more

Windows Components > Internet Explorer > Internet Control Panel

  • Prevent ignoring certificate errors
    Baseline default: Enabled
    Learn more

Windows Components > Internet Explorer > Internet Control Panel > Advanced Page

  • Allow software to run or install even if the signature is invalid
    Baseline default: Disabled
    Learn more

  • Check for server certificate revocation
    Baseline default: Enabled
    Learn more

  • Check for signatures on downloaded programs
    Baseline default: Enabled
    Learn more

  • Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled
    Baseline default: Enabled
    Learn more

  • Turn off encryption support
    Baseline default: Enabled
    Learn more

    • Secure Protocol combinations
      Baseline default: Use TLS 1.1 and TLS 1.2
  • Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows
    Baseline default: Enabled
    Learn more

  • Turn on Enhanced Protected Mode
    Baseline default: Enabled
    Learn more

Windows Components > Internet Explorer > Internet Control Panel > Security Page

  • Intranet Sites: Include all network paths (UNCs)
    Baseline default: Disabled
    Learn more

  • Turn on certificate address mismatch warning
    Baseline default: Enabled
    Learn more

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone

  • Access data sources across domains
    Baseline default: Enabled
    Learn more

    • Access data sources across domains
      Baseline default: Disable
  • Allow cut, copy or paste operations from the clipboard via script
    Baseline default: Enabled
    Learn more

    • Allow paste operations via script
      Baseline default: Disable
  • Allow drag and drop or copy and paste files
    Baseline default: Enabled
    Learn more

    • Allow drag and drop or copy and paste files
      Baseline default: Disable
  • Allow loading of XAML files
    Baseline default: Enabled
    Learn more

    • XAML Files
      Baseline default: Disable
  • Allow only approved domains to use ActiveX controls without prompt
    Baseline default: Enabled
    Learn more

    • Only allow approved domains to use ActiveX controls without prompt
      Baseline default: Enable
  • Allow only approved domains to use the TDC ActiveX control
    Baseline default: Enabled
    Learn more

    • Only allow approved domains to use the TDC ActiveX control
      Baseline default: Enable
  • Allow script-initiated windows without size or position constraints
    Baseline default: Enabled
    Learn more

    • Allow script-initiated windows without size or position constraints
      Baseline default: Disable
  • Allow scripting of Internet Explorer WebBrowser controls
    Baseline default: Enabled
    Learn more

    • Internet Explorer web browser control
      Baseline default: Disable
  • Allow scriptlets
    Baseline default: Enabled
    Learn more

    • Scriptlets
      Baseline default: Disable
  • Allow updates to status bar via script
    Baseline default: Enabled
    Learn more

    • Status bar updates via script
      Baseline default: Disable
  • Allow VBScript to run in Internet Explorer
    Baseline default: Enabled
    Learn more

    • Allow VBScript to run in Internet Explorer
      Baseline default: Disable
  • Automatic prompting for file downloads
    Baseline default: Enabled
    Learn more

    • Automatic prompting for file downloads
      Baseline default: Disable
  • Don't run antimalware programs against ActiveX controls
    Baseline default: Enabled
    Learn more

    • Don't run antimalware programs against ActiveX controls
      Baseline default: Disable
  • Download signed ActiveX controls
    Baseline default: Enabled
    Learn more

    • Download signed ActiveX controls
      Baseline default: Disable
  • Download unsigned ActiveX controls
    Baseline default: Enabled
    Learn more

    • Download unsigned ActiveX controls
      Baseline default: Disable
  • Enable dragging of content from different domains across windows
    Baseline default: Enabled
    Learn more

    • Enable dragging of content from different domains across windows
      Baseline default: Disable
  • Enable dragging of content from different domains within a window
    Baseline default: Enabled
    Learn more

    • Enable dragging of content from different domains within a window
      Baseline default: Disable
  • Include local path when user is uploading files to a server
    Baseline default: Enabled
    Learn more

    • Include local directory path when uploading files to a server
      Baseline default: Disable
  • Initialize and script ActiveX controls not marked as safe
    Baseline default: Enabled
    Learn more

    • Initialize and script ActiveX controls not marked as safe
      Baseline default: Disable
  • Java permissions
    Baseline default: Enabled
    Learn more

    • Java permissions
      Baseline default: Disable Java
  • Launching applications and files in an IFRAME
    Baseline default: Enabled
    Learn more

    • Launching applications and files in an IFRAME
      Baseline default: Disable
  • Logon options
    Baseline default: Enabled
    Learn more

    • Logon options
      Baseline default: Prompt for user name and password
  • Navigate windows and frames across different domains
    Baseline default: Enabled
    Learn more

    • Navigate windows and frames across different domains
      Baseline default: Disable
  • Run .NET Framework-reliant components not signed with Authenticode
    Baseline default: Enabled
    Learn more

    • Run .NET Framework-reliant components not signed with Authenticode
      Baseline default: Disable
  • Run .NET Framework-reliant components signed with Authenticode
    Baseline default: Enabled
    Learn more

    • Run .NET Framework-reliant components signed with Authenticode
      Baseline default: Disable
  • Show security warning for potentially unsafe files
    Baseline default: Enabled
    Learn more

    • Launching programs and unsafe files
      Baseline default: Prompt
  • Turn on Cross-Site Scripting Filter
    Baseline default: Enabled
    Learn more

    • Turn on Cross-Site Scripting (XSS) Filter
      Baseline default: Enable
  • Turn on Protected Mode
    Baseline default: Enabled
    Learn more

    • Protected Mode
      Baseline default: Enable
  • Turn on SmartScreen Filter scan
    Baseline default: Enabled
    Learn more

    • Use SmartScreen Filter
      Baseline default: Enable
  • Use Pop-up Blocker
    Baseline default: Enable
    Learn more

    • Use Pop-up Blocker
      Baseline default: Enable
  • Userdata persistence
    Baseline default: Enabled
    Learn more

    • Userdata persistence
      Baseline default: Disable
  • Web sites in less privileged Web content zones can navigate into this zone
    Baseline default: Enabled
    Learn more

    • Web sites in less privileged Web content zones can navigate into this zone
      Baseline default: Disable

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone

  • Don't run antimalware programs against ActiveX controls
    Baseline default: Enabled
    Learn more

    • Don't run antimalware programs against ActiveX controls
      Baseline default: Disable
  • Initialize and script ActiveX controls not marked as safe
    Baseline default: Enabled
    Learn more

    • Initialize and script ActiveX controls not marked as safe
      Baseline default: Disable
  • Java permissions
    Baseline default: Enabled
    Learn more

    • Java permissions
      Baseline default: High safety

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone

  • Don't run antimalware programs against ActiveX controls
    Baseline default: Enabled
    Learn more

    • Don't run antimalware programs against ActiveX controls
      Baseline default: Disable
  • Java permissions
    Baseline default: Enabled
    Learn more

    • Java permissions
      Baseline default: Disable Java

Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone

  • Turn on SmartScreen Filter scan
    Baseline default: Enabled
    Learn more