Baseline Documentation
Technical guides, admin manuals, and reference documentation for the CONFIG365 Modern Workplace Baseline platform.
Platform Documentation
Baseline Security Groups
3 min readReference for all security groups in the Modern Workplace Baseline — device groups, user groups, and AppLocker exclusion groups with dynamic membership rules.
Conditional Access Policies
4 min readHow CONFIG365 deploys and manages CA policies and named locations — JSON structure, state sync modes (preserve / baseline / enableOnly), exclusions, optional applications, and per-tenant overrides.
Custom Security Attributes for CA App Exclusions
2 min readTag Enterprise Applications with a Custom Security Attribute to dynamically exclude them from Conditional Access policies — no policy edits required. Covers AVD, Azure VPN, and VDI scenarios.
VDI / Azure Virtual Desktop
4 min readRegister the AVD egress IP as a trusted named location and keep session hosts in the dedicated device group so physical-device policies are not applied to virtual hosts.
Group Management
4 min readHow CONFIG365 deploys and manages baseline security groups — JSON structure, dynamic membership rules, the {{GROUP:name}} placeholder system, and idempotent deployment behavior.
Application Deployment
5 min readDeploy Win32 LOB apps from Chocolatey and WinGet, push Intune mobile apps, and manage Enterprise App registrations — all from JSON definitions in your baseline repository.
Authentication Policies
3 min readConfigure MFA method policies — FIDO2, Temporary Access Pass, Microsoft Authenticator, and SMS — deployed via the Authentication Methods API across all tenants.
Entra ID Settings
3 min readDevice registration settings, Windows LAPS configuration, and SSPR policies deployed as code — ensuring consistent identity platform configuration across every tenant.
SharePoint Settings
4 min readTenant-wide SharePoint sharing policies, external sharing restrictions, OneDrive sync controls, Graph tenant settings, and SpoTenant configuration deployed from the baseline.
Information Protection
4 min readSensitivity labels, publishing policies, auto-labeling, and DLP via Security & Compliance PowerShell — plus Exchange IRM/OME under deployExchange.
Consent & Permissions
3 min readUser and admin consent settings, OAuth app permission classifications, admin consent workflows, and delegated permission governance deployed via Graph.