Baseline

Baseline Documentation

Technical guides, admin manuals, and reference documentation for the CONFIG365 Modern Workplace Baseline platform.

Platform Documentation

Baseline Security Groups

3 min read

Reference for all security groups in the Modern Workplace Baseline — device groups, user groups, and AppLocker exclusion groups with dynamic membership rules.

Security GroupsIntuneConditional AccessAppLocker

Conditional Access Policies

4 min read

How CONFIG365 deploys and manages CA policies and named locations — JSON structure, state sync modes (preserve / baseline / enableOnly), exclusions, optional applications, and per-tenant overrides.

Conditional AccessNamed LocationsState SyncGraph APIZero Drift

Custom Security Attributes for CA App Exclusions

2 min read

Tag Enterprise Applications with a Custom Security Attribute to dynamically exclude them from Conditional Access policies — no policy edits required. Covers AVD, Azure VPN, and VDI scenarios.

Conditional AccessCustom Security AttributesAVDVDI

VDI / Azure Virtual Desktop

4 min read

Register the AVD egress IP as a trusted named location and keep session hosts in the dedicated device group so physical-device policies are not applied to virtual hosts.

AVDVDITrusted LocationConditional AccessIntune

Group Management

4 min read

How CONFIG365 deploys and manages baseline security groups — JSON structure, dynamic membership rules, the {{GROUP:name}} placeholder system, and idempotent deployment behavior.

Security GroupsDynamic MembershipPlaceholdersIntuneConditional Access

Application Deployment

5 min read

Deploy Win32 LOB apps from Chocolatey and WinGet, push Intune mobile apps, and manage Enterprise App registrations — all from JSON definitions in your baseline repository.

ChocolateyWinGetWin32 LOBEnterprise AppsIntune

Authentication Policies

3 min read

Configure MFA method policies — FIDO2, Temporary Access Pass, Microsoft Authenticator, and SMS — deployed via the Authentication Methods API across all tenants.

FIDO2TAPMFAAuthenticatorAuthentication Methods

Entra ID Settings

3 min read

Device registration settings, Windows LAPS configuration, and SSPR policies deployed as code — ensuring consistent identity platform configuration across every tenant.

Device RegistrationLAPSSSPREntra IDIdentity

SharePoint Settings

4 min read

Tenant-wide SharePoint sharing policies, external sharing restrictions, OneDrive sync controls, Graph tenant settings, and SpoTenant configuration deployed from the baseline.

SharePointExternal SharingOneDriveSpoTenantTenant Settings

Information Protection

4 min read

Sensitivity labels, publishing policies, auto-labeling, and DLP via Security & Compliance PowerShell — plus Exchange IRM/OME under deployExchange.

AIPSensitivity LabelsDLPPurviewAuto-Labeling

Consent & Permissions

3 min read

User and admin consent settings, OAuth app permission classifications, admin consent workflows, and delegated permission governance deployed via Graph.

OAuthConsentAdmin Consent WorkflowPermissionsApp Governance

Admin Manuals