Every row here is defended somewhere in this series, and the last column tells you where. Tier is C for critical, R for recommended and O for optional, meaning obligation rather than difficulty. Platform is new to this wave: filter to one and you have that platform’s baseline on a single screen. Nothing appears in this table that the series does not argue for.
How to read it
Critical means I will not hand a tenant over without it, and if one is missing I consider the environment unfinished and will say so in writing. Recommended is the professional default, where deviation is allowed but should be deliberate and recorded. Optional is genuine preference, where reasonable practitioners differ and the article lays out the trade rather than picking a side.
The Platform column reads All only where a control genuinely applies everywhere rather than because nobody checked. A Mac-only estate can read the macOS and All rows and skip the rest, and the same for Windows.
The How to check column is the point of the exercise. A baseline that cannot be verified is a description of how the tenant looked on the afternoon somebody finished it, so every row states an observation rather than an intention.
1. Enrollment
| Tier | Platform | Do this | How to check | See |
|---|---|---|---|---|
| C | All | Configure the default platform restriction on every platform tab | No tab left at its shipped value; six tabs exist including tvOS and visionOS | BP 4.1.1 |
| C | All | Configure the default device limit restriction deliberately | A number you can defend, not the shipped one; range is 1 to 15 | BP 4.1.1 |
| C | All | Inventory which enrollment paths are live | Seven documented paths bypass group assignment and use the default | BP 4.1 |
| C | Windows | Prove the corporate identifier list is complete before uploading it | CSV row count reconciles against the asset register and the Intune device list | BP 4.1.1 |
| C | Windows | Decide personally-owned blocking only after the identifier list is proven | Entra join at first sign-in is blocked by it; provisioning stops if the order is reversed | BP 4.1 |
| C | All | Enumerate device enrollment manager accounts | Each one bypasses both restriction types, up to 1,000 devices | BP 4.3 |
| R | All | Assign every non-default restriction to at least one group | An unassigned restriction has no effect and produces no report | BP 4.1.1 |
| R | Win, macOS, iOS | Use assignment filters where a group is too blunt | Filters are unavailable on Android; the property set is reduced pre-enrollment | BP 4.1.1 |
| R | All | Verify priority order resolves as intended | Lowest priority value wins whole; policies never merge | BP 4.1.1 |
| O | Android | Block device manufacturers | Android only, and not expressible in Graph v1.0 | BP 4.1.1 |
2. Compliance
| Tier | Platform | Do this | How to check | See |
|---|---|---|---|---|
| C | All | Set Mark devices with no compliance policy assigned as to Not compliant | Read the tenant-wide setting itself; it ships as Compliant | BP 4.1 |
| C | All | Have at least one Conditional Access policy consuming device state | Without it compliance is reporting; floor is Intune plus Entra ID P1 or P2 | BP 4.1 |
| R | All | Shorten the compliance status validity period from 30 days | Range is 1 to 120; decides how long a silent device vouches for itself | BP 4.1 |
| R | All | Choose the Mark device noncompliant schedule rather than inheriting 0 days | Zero means Conditional Access acts immediately; this setting is the grace period | BP 4.1 |
| R | All | Know which devices sit in Not evaluated | Absorbs userless Apple, Android dedicated and DEM-enrolled devices | BP 4.1 |
| C | Windows | Require BitLocker, Secure Boot and code integrity in the Windows policy | Defaults are Not configured throughout | BP 4.1 |
| R | Windows | Set a minimum OS version floor | Windows 10 is allowed, not supported | BP 4.5 |
| R | macOS | Require system integrity protection and disk encryption | Firewall defaults to Not configured, which allows traffic | BP 4.1 |
| C | macOS | Pair any password rule with a settings catalog policy using Change At Next Auth = False | Otherwise it expires every local password including LAPS accounts | BP 4.1, BP 4.2 |
| C | Android | Set Minimum security patch level | The named mitigation for the 31 October 2026 Play integrity change | BP 4.5 |
| R | Android | Block rooted devices and set a minimum OS version | Password type Device default does not evaluate; choose a real type | BP 4.1 |
| O | Win, iOS, Android | Require a device threat level or machine risk score | Not configured by default; macOS is not supported for this policy | BP 4.1 |
3. Encryption
| Tier | Platform | Do this | How to check | See |
|---|---|---|---|---|
| C | Windows | Set Require Device Encryption enabled with Allow Standard User Encryption enabled | Silent enablement fails on non-administrator machines without the second | BP 4.1 |
| C | Windows | Set the encryption algorithm before first encryption | Settings apply only at encryption start; changing later means decrypt and re-encrypt | BP 4.1 |
| C | Windows | Confirm recovery keys are escrowed to Entra ID | Check for escrowed keys per device, not that the policy is assigned | BP 4.1 |
| R | Windows | Inventory for third-party encryption before disabling Allow Warning For Other Disk Encryption | Documented data loss and boot failure risk where other encryption exists | BP 4.1 |
| C | Windows | Back up the recovery key and local admin credentials before retiring or deleting a device | Retire and delete remove key protectors and suspend BitLocker on the OS volume | BP 4.1 |
| R | Windows | Know that removing the policy does not decrypt | Disabling stops the prompt; encryption stays | BP 4.1 |
| O | Windows | Enable client-driven recovery password rotation | Requires Entra backup set to required; off by default on hybrid | BP 4.1 |
| C | macOS | Enable FileVault through the endpoint security disk encryption profile | The endpoint protection template is deprecated for new profiles | BP 4.1 |
| C | macOS | Mark devices corporate if the service desk must retrieve keys | Administrators can view keys only for corporate devices | BP 4.1 |
| O | macOS | Use the settings catalog where Setup Assistant enforcement is needed | Setup Assistant enforcement is unique to that surface | BP 4.1 |
| R | macOS | Set the personal recovery key rotation interval | 1 to 12 months; previous keys become invalid after rotation | BP 4.1 |
4. Baselines, updates and apps
| Tier | Platform | Do this | How to check | See |
|---|---|---|---|---|
| C | All | Establish the Defender for Endpoint connector and onboard endpoints | Check the device count on the connector, not the connector status | BP 4.1 |
| C | Windows | Manage tamper protection from Intune | Once Intune manages it, the Defender portal toggle stops affecting device state | BP 4.1 |
| R | Windows | Run a modular community baseline rather than a monolithic built-in one | Fork by name; never edit a baseline policy in place | BP 4.2 |
| R | macOS | Treat proof-of-concept configuration output as a first draft you then own | Policies renamed into your convention rather than left as generated | BP 4.2 |
| R | Windows | Use Autopatch where licensed; do not assign custom rings to Autopatch devices | Business Premium gets the product, not the support requests | BP 4.2 |
| R | Windows | Decide hotpatch rather than inherit it | On by default since the May 2026 security update; tenant opt-out exists | BP 4.2, BP 4.5 |
| O | Windows | Disable CHPE on Arm64 only where those devices need hotpatch | 32-bit x86 apps can break; 32-bit Office on Arm loses updates December 2026 | BP 4.2 |
| R | Windows | Use the Windows scan source policy per update class during WSUS transition | Dual scan is unsupported on Windows 11 and not recommended on 10 | BP 4.2 |
| R | iOS, Android | Apply app protection Level 2 for the population, Level 3 for high-risk roles | Matches Microsoft’s own published recommendation | BP 4.2 |
| C | Android | Set app protection Min OS version and Min patch version | The mitigations for 31 October 2026; set before the date | BP 4.2, BP 4.5 |
| O | Windows | Use app protection for unmanaged contractor machines | Edge only; blocked entirely on managed devices | BP 4.2 |
| R | Windows | Enable Windows LAPS through the account protection policy | Overrides GPO and legacy LAPS; one account per device | BP 4.2 |
| R | macOS | Enable macOS LAPS on ADE-enrolled devices | ADE after factory reset only; profiles renew paths are unsupported | BP 4.2 |
5. Privileged access
| Tier | Platform | Do this | How to check | See |
|---|---|---|---|---|
| C | All | Enumerate Intune Administrator membership | The only role that can manage enrollment restrictions or create scope tags | BP 4.3 |
| C | All | Run the permissions assessment report before scoped permissions reach GA | Scoped behaviour becomes the default for all tenants at GA | BP 4.3 |
| C | All | Create a custom role for LAPS password rotation | No built-in role carries it on Windows or macOS | BP 4.3 |
| R | All | Review who can read LAPS passwords in Entra, not Intune | It is a directory permission; the Intune console will not show it | BP 4.3 |
| R | macOS | Review who holds Get FileVault key | Read Only Operator carries it | BP 4.3 |
| R | All | Assign Intune Role Administrator to a named person | Least-privileged role for administering the model; separate from Global Administrator | BP 4.3 |
| R | All | Enable multi-admin approval on device actions and RBAC | Submit a real change and confirm you cannot approve your own | BP 4.3 |
| C | All | Make the MAA approver group a security group assigned directly to an Intune role | Other group types silently fail to resolve membership | BP 4.3 |
| R | All | Enable the MAA role policy type last | Avoids the documented deadlock where roles cannot be changed | BP 4.3 |
| O | All | Decide unlicensed admin access deliberately | Cannot be turned off once enabled; nested groups excluded | BP 4.3, BP 4.4 |
| R | All | Use scope tags or decide against them explicitly | Created and abandoned is the common finding | BP 4.3 |
6. Licensing and the calendar
| Tier | Platform | Do this | How to check | See |
|---|---|---|---|---|
| C | All | Read tenant administration, add-ons, before buying anything | Mid-redistribution, the tenant is the only accurate source | BP 4.4 |
| R | All | Watch the message center for your thirty-day redistribution notice | Per tenant; no global date exists | BP 4.4 |
| R | All | Budget Entra ID P1 or P2 alongside Intune | Without it, compliance policy is reporting | BP 4.4 |
| R | Windows | Check Windows Enterprise or Education licensing for granular BitLocker policy | On and off is unrestricted; algorithms and recovery options are not | BP 4.4 |
| R | All | Use device-only licences only where no Conditional Access is acceptable | They do not support CA or app protection at all | BP 4.4 |
| C | Android | Prepare for Play integrity enforcement on 31 October 2026 | Devices without a security update in 12 months drop to device integrity | BP 4.5 |
| R | All | Diary the Android floor review each October | One or two versions retire annually | BP 4.5 |
| R | All | Diary the certificate connector every six months | Six-month support window, eighteen-month outer bound | BP 4.5 |
| R | All | Check firewall allowlists against the Azure Front Door service tag | Old IP ranges break device and app management | BP 4.5 |
| R | Windows | Treat Windows 10 ESU as a licensing exercise outside Intune | No Intune enablement path exists; the Intune answer is the upgrade | BP 4.5 |
| O | Apple | Audit against iOS 18 and macOS 15 before the 27 releases ship | Enrolled devices stay; new devices below the floor cannot enrol | BP 4.5 |
The four things I would check first in an inherited tenant
If somebody hands you an Intune tenant tomorrow and gives you an hour, this is the order.
Open the tenant-wide compliance setting and see whether unevaluated devices are being reported as compliant. It is one screen, it is usually still on the permissive value, and it silently undermines every Conditional Access policy built on device state.
Open the two default enrollment restrictions. Not the ones somebody built and assigned, the defaults underneath them, because those are what govern Autopilot, co-management, Windows 365 and every other path that is not user-driven.
Check whether recovery keys actually exist for the devices you believe are encrypted. The policy proves intent. The key proves outcome, and the gap between them is where the surprise lives.
And ask who can rotate a local administrator password. If the answer is that nobody has thought about it, then the permission sits in no built-in role, nobody holds it, and the shared local password everyone actually uses is still the real access model.
None of those four take long. All four are decisions somebody made by not making them, which is the whole argument of this series in a paragraph.
Best Practices
‹ Previous: [BP 4.5] Intune on a Clock: Retirements and the Defaults That Changed Under You




