Platform Documentation

Baseline Security Groups

The Intune environment is granularly configurable using security groups. Groups are either Device or User groups, identifiable by their prefix. Two main groups control enrollment; all other groups provide opt-in or opt-out controls.

3 min read Updated February 15, 2025

Device Control Security Groups

Device groups are prefixed Baseline – Devices. They control Intune configuration profiles, BitLocker, AppLocker, and credential providers on a per-machine basis.

Baseline – Modern Workplace Devices

All devices in this group are targeted with all Intune policies and applications. Membership rules should be changed to dynamically include all devices after onboarding completion.

Baseline – Devices Bitlocker TPM Excluded

For devices that do not support TPM. Pre-boot BitLocker password is configurable. Should not be used — replacing the device is preferable.

Baseline – Devices Exclude Credential Provider

Disables legacy password-based sign-in on devices. Should be set to dynamically include all devices. Cloud sign-in is enabled, allowing web sign-in with MFA push.

Baseline – Devices Exclude Credential Provider Excluded

Can be used to temporarily exclude devices from the credential provider policy applied in the group above.

Baseline – Devices Physical Hello For Business MFA Excluded

By default Windows MFA is enabled. This group can be used to disable this functionality. Users can sign in with two factors: PIN + Bluetooth phone, fingerprint + camera, or a combination.

Baseline – Devices Unenrollment Block Excluded

Unenrolling devices from Entra is blocked by default. Devices can be assigned to this group to allow un-enrollment.

AppLocker Exclusion Groups

These groups are suffixed Excluded and relax AppLocker restrictions on a per-device basis. Each group corresponds to a specific execution category.

Baseline – Devices Applocker Script Excluded

Devices in this group do not have script execution restrictions.

Baseline – Devices Applocker MSI Excluded

Devices in this group do not have installer execution restrictions.

Baseline – Devices Applocker EXE Excluded

Devices in this group do not have EXE execution restrictions.

Baseline – Devices Applocker APPX Excluded

Devices in this group do not have signed MSIX package restrictions.

User Control Security Groups

User groups are prefixed Baseline – Users. They control Conditional Access behaviour, local admin rights, device lock times, and mobile policies on a per-user basis.

Baseline – Modern Workplace Users

All users in this group are targeted with user policies and strict Conditional Access rules. Membership rules should dynamically include all users with values in given name and surname — this allows shared mailboxes and service accounts to be excluded.

Dynamic membership rule
(user.accountEnabled -eq true) and (user.givenName -ne $null) and (user.surname -ne $null) and (user.displayName -notContains "azavd")
Baseline – Users Azure AD Joined Device Local Administrator

Users in this group have local admin rights on all devices.

Baseline – Users Local Admin Strip Excluded

Users in this group are not stripped from local admin rights on their devices.

Baseline – Users DeviceLock 15min / 30min

The default lock time is set to 5 minutes. These groups can be used to increase the period.

Baseline – Users Web Require Strong Authentication Excluded

Signing into browsers from non-managed devices is only allowed with strong MFA methods. Users in this group are allowed to access the environment using a browser with normal MFA. By default, this group includes no users.

Baseline – Users Web Require Intune Compliance Excluded

Signing in from browsers is only allowed from compliant devices unless the user is in this group. By default, this dynamically includes all users.

Baseline – Users Allow Unencrypted USB

Users in this group are allowed to read and write to USB drives not protected by BitLocker.

Baseline – Users Mobile Intune Excluded

Users in this group are not required to enroll with Intune. By default, this dynamically includes all users.

Baseline – Users Mobile App Protection Less Restrictive

Allows users to use Microsoft-protected applications on mobile devices without storage or copy/paste restrictions. Requires Intune Enrollment.