[BP 4.6] The Intune Quick Checklist

Every row in the wave, tiered and by platform, with the observation that proves each one and the article that defends it.


Every row here is defended somewhere in this series, and the last column tells you where. Tier is C for critical, R for recommended and O for optional, meaning obligation rather than difficulty. Platform is new to this wave: filter to one and you have that platform’s baseline on a single screen. Nothing appears in this table that the series does not argue for.

How to read it

Critical means I will not hand a tenant over without it, and if one is missing I consider the environment unfinished and will say so in writing. Recommended is the professional default, where deviation is allowed but should be deliberate and recorded. Optional is genuine preference, where reasonable practitioners differ and the article lays out the trade rather than picking a side.

The Platform column reads All only where a control genuinely applies everywhere rather than because nobody checked. A Mac-only estate can read the macOS and All rows and skip the rest, and the same for Windows.

The How to check column is the point of the exercise. A baseline that cannot be verified is a description of how the tenant looked on the afternoon somebody finished it, so every row states an observation rather than an intention.


1. Enrollment

TierPlatformDo thisHow to checkSee
CAllConfigure the default platform restriction on every platform tabNo tab left at its shipped value; six tabs exist including tvOS and visionOSBP 4.1.1
CAllConfigure the default device limit restriction deliberatelyA number you can defend, not the shipped one; range is 1 to 15BP 4.1.1
CAllInventory which enrollment paths are liveSeven documented paths bypass group assignment and use the defaultBP 4.1
CWindowsProve the corporate identifier list is complete before uploading itCSV row count reconciles against the asset register and the Intune device listBP 4.1.1
CWindowsDecide personally-owned blocking only after the identifier list is provenEntra join at first sign-in is blocked by it; provisioning stops if the order is reversedBP 4.1
CAllEnumerate device enrollment manager accountsEach one bypasses both restriction types, up to 1,000 devicesBP 4.3
RAllAssign every non-default restriction to at least one groupAn unassigned restriction has no effect and produces no reportBP 4.1.1
RWin, macOS, iOSUse assignment filters where a group is too bluntFilters are unavailable on Android; the property set is reduced pre-enrollmentBP 4.1.1
RAllVerify priority order resolves as intendedLowest priority value wins whole; policies never mergeBP 4.1.1
OAndroidBlock device manufacturersAndroid only, and not expressible in Graph v1.0BP 4.1.1

2. Compliance

TierPlatformDo thisHow to checkSee
CAllSet Mark devices with no compliance policy assigned as to Not compliantRead the tenant-wide setting itself; it ships as CompliantBP 4.1
CAllHave at least one Conditional Access policy consuming device stateWithout it compliance is reporting; floor is Intune plus Entra ID P1 or P2BP 4.1
RAllShorten the compliance status validity period from 30 daysRange is 1 to 120; decides how long a silent device vouches for itselfBP 4.1
RAllChoose the Mark device noncompliant schedule rather than inheriting 0 daysZero means Conditional Access acts immediately; this setting is the grace periodBP 4.1
RAllKnow which devices sit in Not evaluatedAbsorbs userless Apple, Android dedicated and DEM-enrolled devicesBP 4.1
CWindowsRequire BitLocker, Secure Boot and code integrity in the Windows policyDefaults are Not configured throughoutBP 4.1
RWindowsSet a minimum OS version floorWindows 10 is allowed, not supportedBP 4.5
RmacOSRequire system integrity protection and disk encryptionFirewall defaults to Not configured, which allows trafficBP 4.1
CmacOSPair any password rule with a settings catalog policy using Change At Next Auth = FalseOtherwise it expires every local password including LAPS accountsBP 4.1, BP 4.2
CAndroidSet Minimum security patch levelThe named mitigation for the 31 October 2026 Play integrity changeBP 4.5
RAndroidBlock rooted devices and set a minimum OS versionPassword type Device default does not evaluate; choose a real typeBP 4.1
OWin, iOS, AndroidRequire a device threat level or machine risk scoreNot configured by default; macOS is not supported for this policyBP 4.1

3. Encryption

TierPlatformDo thisHow to checkSee
CWindowsSet Require Device Encryption enabled with Allow Standard User Encryption enabledSilent enablement fails on non-administrator machines without the secondBP 4.1
CWindowsSet the encryption algorithm before first encryptionSettings apply only at encryption start; changing later means decrypt and re-encryptBP 4.1
CWindowsConfirm recovery keys are escrowed to Entra IDCheck for escrowed keys per device, not that the policy is assignedBP 4.1
RWindowsInventory for third-party encryption before disabling Allow Warning For Other Disk EncryptionDocumented data loss and boot failure risk where other encryption existsBP 4.1
CWindowsBack up the recovery key and local admin credentials before retiring or deleting a deviceRetire and delete remove key protectors and suspend BitLocker on the OS volumeBP 4.1
RWindowsKnow that removing the policy does not decryptDisabling stops the prompt; encryption staysBP 4.1
OWindowsEnable client-driven recovery password rotationRequires Entra backup set to required; off by default on hybridBP 4.1
CmacOSEnable FileVault through the endpoint security disk encryption profileThe endpoint protection template is deprecated for new profilesBP 4.1
CmacOSMark devices corporate if the service desk must retrieve keysAdministrators can view keys only for corporate devicesBP 4.1
OmacOSUse the settings catalog where Setup Assistant enforcement is neededSetup Assistant enforcement is unique to that surfaceBP 4.1
RmacOSSet the personal recovery key rotation interval1 to 12 months; previous keys become invalid after rotationBP 4.1

4. Baselines, updates and apps

TierPlatformDo thisHow to checkSee
CAllEstablish the Defender for Endpoint connector and onboard endpointsCheck the device count on the connector, not the connector statusBP 4.1
CWindowsManage tamper protection from IntuneOnce Intune manages it, the Defender portal toggle stops affecting device stateBP 4.1
RWindowsRun a modular community baseline rather than a monolithic built-in oneFork by name; never edit a baseline policy in placeBP 4.2
RmacOSTreat proof-of-concept configuration output as a first draft you then ownPolicies renamed into your convention rather than left as generatedBP 4.2
RWindowsUse Autopatch where licensed; do not assign custom rings to Autopatch devicesBusiness Premium gets the product, not the support requestsBP 4.2
RWindowsDecide hotpatch rather than inherit itOn by default since the May 2026 security update; tenant opt-out existsBP 4.2, BP 4.5
OWindowsDisable CHPE on Arm64 only where those devices need hotpatch32-bit x86 apps can break; 32-bit Office on Arm loses updates December 2026BP 4.2
RWindowsUse the Windows scan source policy per update class during WSUS transitionDual scan is unsupported on Windows 11 and not recommended on 10BP 4.2
RiOS, AndroidApply app protection Level 2 for the population, Level 3 for high-risk rolesMatches Microsoft’s own published recommendationBP 4.2
CAndroidSet app protection Min OS version and Min patch versionThe mitigations for 31 October 2026; set before the dateBP 4.2, BP 4.5
OWindowsUse app protection for unmanaged contractor machinesEdge only; blocked entirely on managed devicesBP 4.2
RWindowsEnable Windows LAPS through the account protection policyOverrides GPO and legacy LAPS; one account per deviceBP 4.2
RmacOSEnable macOS LAPS on ADE-enrolled devicesADE after factory reset only; profiles renew paths are unsupportedBP 4.2

5. Privileged access

TierPlatformDo thisHow to checkSee
CAllEnumerate Intune Administrator membershipThe only role that can manage enrollment restrictions or create scope tagsBP 4.3
CAllRun the permissions assessment report before scoped permissions reach GAScoped behaviour becomes the default for all tenants at GABP 4.3
CAllCreate a custom role for LAPS password rotationNo built-in role carries it on Windows or macOSBP 4.3
RAllReview who can read LAPS passwords in Entra, not IntuneIt is a directory permission; the Intune console will not show itBP 4.3
RmacOSReview who holds Get FileVault keyRead Only Operator carries itBP 4.3
RAllAssign Intune Role Administrator to a named personLeast-privileged role for administering the model; separate from Global AdministratorBP 4.3
RAllEnable multi-admin approval on device actions and RBACSubmit a real change and confirm you cannot approve your ownBP 4.3
CAllMake the MAA approver group a security group assigned directly to an Intune roleOther group types silently fail to resolve membershipBP 4.3
RAllEnable the MAA role policy type lastAvoids the documented deadlock where roles cannot be changedBP 4.3
OAllDecide unlicensed admin access deliberatelyCannot be turned off once enabled; nested groups excludedBP 4.3, BP 4.4
RAllUse scope tags or decide against them explicitlyCreated and abandoned is the common findingBP 4.3

6. Licensing and the calendar

TierPlatformDo thisHow to checkSee
CAllRead tenant administration, add-ons, before buying anythingMid-redistribution, the tenant is the only accurate sourceBP 4.4
RAllWatch the message center for your thirty-day redistribution noticePer tenant; no global date existsBP 4.4
RAllBudget Entra ID P1 or P2 alongside IntuneWithout it, compliance policy is reportingBP 4.4
RWindowsCheck Windows Enterprise or Education licensing for granular BitLocker policyOn and off is unrestricted; algorithms and recovery options are notBP 4.4
RAllUse device-only licences only where no Conditional Access is acceptableThey do not support CA or app protection at allBP 4.4
CAndroidPrepare for Play integrity enforcement on 31 October 2026Devices without a security update in 12 months drop to device integrityBP 4.5
RAllDiary the Android floor review each OctoberOne or two versions retire annuallyBP 4.5
RAllDiary the certificate connector every six monthsSix-month support window, eighteen-month outer boundBP 4.5
RAllCheck firewall allowlists against the Azure Front Door service tagOld IP ranges break device and app managementBP 4.5
RWindowsTreat Windows 10 ESU as a licensing exercise outside IntuneNo Intune enablement path exists; the Intune answer is the upgradeBP 4.5
OAppleAudit against iOS 18 and macOS 15 before the 27 releases shipEnrolled devices stay; new devices below the floor cannot enrolBP 4.5

The four things I would check first in an inherited tenant

If somebody hands you an Intune tenant tomorrow and gives you an hour, this is the order.

Open the tenant-wide compliance setting and see whether unevaluated devices are being reported as compliant. It is one screen, it is usually still on the permissive value, and it silently undermines every Conditional Access policy built on device state.

Open the two default enrollment restrictions. Not the ones somebody built and assigned, the defaults underneath them, because those are what govern Autopilot, co-management, Windows 365 and every other path that is not user-driven.

Check whether recovery keys actually exist for the devices you believe are encrypted. The policy proves intent. The key proves outcome, and the gap between them is where the surprise lives.

And ask who can rotate a local administrator password. If the answer is that nobody has thought about it, then the permission sits in no built-in role, nobody holds it, and the shared local password everyone actually uses is still the real access model.

None of those four take long. All four are decisions somebody made by not making them, which is the whole argument of this series in a paragraph.


Best Practices
‹ Previous: [BP 4.5] Intune on a Clock: Retirements and the Defaults That Changed Under You