Baseline Security Groups
The Intune environment is granularly configurable using security groups. Groups are either Device or User groups, identifiable by their prefix. Two main groups control enrollment; all other groups provide opt-in or opt-out controls.
Device Control Security Groups
Device groups are prefixed Baseline – Devices. They control Intune configuration profiles, BitLocker, AppLocker, and credential providers on a per-machine basis.
All devices in this group are targeted with all Intune policies and applications. Membership rules should be changed to dynamically include all devices after onboarding completion.
For devices that do not support TPM. Pre-boot BitLocker password is configurable. Should not be used — replacing the device is preferable.
Disables legacy password-based sign-in on devices. Should be set to dynamically include all devices. Cloud sign-in is enabled, allowing web sign-in with MFA push.
Can be used to temporarily exclude devices from the credential provider policy applied in the group above.
By default Windows MFA is enabled. This group can be used to disable this functionality. Users can sign in with two factors: PIN + Bluetooth phone, fingerprint + camera, or a combination.
Unenrolling devices from Entra is blocked by default. Devices can be assigned to this group to allow un-enrollment.
AppLocker Exclusion Groups
These groups are suffixed Excluded and relax AppLocker restrictions on a per-device basis. Each group corresponds to a specific execution category.
Devices in this group do not have script execution restrictions.
Devices in this group do not have installer execution restrictions.
Devices in this group do not have EXE execution restrictions.
Devices in this group do not have signed MSIX package restrictions.
User Control Security Groups
User groups are prefixed Baseline – Users. They control Conditional Access behaviour, local admin rights, device lock times, and mobile policies on a per-user basis.
All users in this group are targeted with user policies and strict Conditional Access rules. Membership rules should dynamically include all users with values in given name and surname — this allows shared mailboxes and service accounts to be excluded.
(user.accountEnabled -eq true) and (user.givenName -ne $null) and (user.surname -ne $null) and (user.displayName -notContains "azavd") Users in this group have local admin rights on all devices.
Users in this group are not stripped from local admin rights on their devices.
The default lock time is set to 5 minutes. These groups can be used to increase the period.
Signing into browsers from non-managed devices is only allowed with strong MFA methods. Users in this group are allowed to access the environment using a browser with normal MFA. By default, this group includes no users.
Signing in from browsers is only allowed from compliant devices unless the user is in this group. By default, this dynamically includes all users.
Users in this group are allowed to read and write to USB drives not protected by BitLocker.
Users in this group are not required to enroll with Intune. By default, this dynamically includes all users.
Allows users to use Microsoft-protected applications on mobile devices without storage or copy/paste restrictions. Requires Intune Enrollment.