Configuration Examples
JSON configuration examples for every policy type deployed by CONFIG365. All files live in the baseline repository.
Overview
All configurations are JSON files in the baseline repository. Files are named after their displayName (e.g. Baseline - Require MFA.json). Intune policies also have a paired .assignment.json.
Conditional Access
baseline/conditional-access/
Named Location (IP-based)
{
"displayName": "AVD",
"@odata.type": "#microsoft.graph.ipNamedLocation",
"isTrusted": true,
"ipRanges": [
{
"@odata.type": "#microsoft.graph.iPv4CidrRange",
"cidrAddress": "20.202.0.0/16"
}
]
} Require MFA (Report-Only)
{
"displayName": "Baseline - Require MFA for All Users",
"state": "enabledForReportingButNotEnforced",
"conditions": {
"clientAppTypes": ["all"],
"applications": { "includeApplications": ["All"] },
"users": {
"includeUsers": ["All"],
"excludeGroups": ["{{GROUP:Baseline - Emergency Access}}"]
}
},
"grantControls": {
"operator": "OR",
"builtInControls": ["mfa"]
}
} Block Legacy Authentication
{
"displayName": "Baseline - ALL BLOCK BASIC",
"state": "enabled",
"conditions": {
"clientAppTypes": ["exchangeActiveSync", "other"],
"applications": { "includeApplications": ["All"] },
"users": { "includeUsers": ["All"] }
},
"grantControls": {
"operator": "OR",
"builtInControls": ["block"]
}
} Optional Application Exclusions
The optional-applications.json file lists app IDs that can be optionally excluded from CA policies via the custom security attribute mechanism.
{
"applications": [
{ "appId": "0000002-0000-0ff1-ce00-000000000000", "displayName": "Office 365 Exchange Online" },
{ "appId": "00000003-0000-0ff1-ce00-000000000000", "displayName": "Office 365 SharePoint Online" }
]
} Groups
baseline/groups/
Static Security Group
{
"displayName": "Baseline - Users MFA Excluded",
"description": "Users excluded from MFA Conditional Access policies",
"mailEnabled": false,
"securityEnabled": true,
"mailNickname": "baseline-users-mfa-excluded"
} Dynamic Group
{
"displayName": "Baseline - Modern Workplace Users",
"description": "All licensed users in the tenant",
"mailEnabled": false,
"securityEnabled": true,
"mailNickname": "baseline-modern-workplace-users",
"groupTypes": ["DynamicMembership"],
"membershipRule": "(user.userType -eq \"Member\")",
"membershipRuleProcessingState": "On"
} Custom Security Attributes
baseline/custom-attributes/
Attribute Set
Define the attribute set first — attribute definitions belong to a set.
{
"id": "BaselineCSAAppExclusions",
"description": "Custom security attributes for Conditional Access policy application exclusions",
"maxAttributesPerSet": 500
} Attribute Definition
{
"isSearchable": true,
"id": "BaselineCSAAppExclusions_CAExclusion",
"type": "String",
"attributeSet": "BaselineCSAAppExclusions",
"description": "Application exclusion tags for Conditional Access policies",
"name": "CAExclusion",
"status": "Available",
"isCollection": true,
"usePreDefinedValuesOnly": true,
"_allowedValues": [
{ "id": "IntuneComplianceExcluded", "isActive": true },
{ "id": "BrowserIntuneComplianceExcluded", "isActive": true },
{ "id": "BrowserStrongAuthExcluded", "isActive": true },
{ "id": "MobileAppProtectionExcluded", "isActive": true },
{ "id": "MobileIntuneComplianceExcluded", "isActive": true },
{ "id": "ModernIntuneComplianceExcluded", "isActive": true }
]
} Consent & Permissions
baseline/entra-id-consentpermissions/
Authorization Policy
{
"id": "authorizationPolicy",
"allowInvitesFrom": "adminsAndGuestInviters",
"allowedToSignUpEmailBasedSubscriptions": true,
"allowUserConsentForRiskyApps": false,
"allowedToUseSSPR": true,
"allowEmailVerifiedUsersToJoinOrganization": false,
"defaultUserRolePermissions": {
"allowedToReadOtherUsers": true,
"allowedToCreateApps": false,
"allowedToCreateSecurityGroups": false,
"allowedToCreateTenants": false,
"permissionGrantPoliciesAssigned": "ManagePermissionGrantsForSelf.microsoft-user-default-low"
}
} Admin Consent Request Policy
{
"isEnabled": true,
"remindersEnabled": true,
"requestDurationInDays": 30,
"notifyReviewers": true,
"reviewers": [
{
"queryType": "MicrosoftGraph",
"query": "/beta/roleManagement/directory/roleAssignments?$filter=roleDefinitionId eq '62e90394-69f5-4237-9190-012177145e10'"
}
]
} Permission Classifications (Low Risk)
Defines which delegated permissions are classified as low-risk, allowing users to grant consent themselves without admin approval.
{
"permissions": [
{ "permissionId": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "classification": "low", "permissionName": "offline_access" },
{ "permissionId": "14dad69e-099b-42c9-810b-d002981feec1", "classification": "low", "permissionName": "profile" },
{ "permissionId": "37f7f235-527c-4136-accd-4a02d197296e", "classification": "low", "permissionName": "openid" },
{ "permissionId": "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", "classification": "low", "permissionName": "email" }
]
} Entra ID Settings
baseline/entra-id-device-settings/
Security Defaults & Tenant Settings
{
"SecurityDefaults": {
"IsEnabled": false,
"_comment": "Set to false when using Conditional Access policies"
}
} Device Registration Policy (LAPS)
{
"id": "deviceRegistrationPolicy",
"multiFactorAuthConfiguration": "notRequired",
"userDeviceQuota": 50,
"azureADRegistration": {
"isAdminConfigurable": false,
"allowedToRegister": {
"@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
}
},
"azureADJoin": {
"isAdminConfigurable": true,
"allowedToJoin": {
"@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
},
"localAdmins": {
"enableGlobalAdmins": true,
"registeringUsers": {
"@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
}
}
},
"localAdminPassword": {
"isEnabled": true
}
} Exchange Online
baseline/exchange/transport-rules/
Transport Rule — Flag HTML Attachments
{
"Name": "Baseline - html attachments set SCL",
"State": "Enabled",
"Mode": "Enforce",
"Priority": 1,
"FromScope": "NotInOrganization",
"AttachmentExtensionMatchesWords": ["htm", "html"],
"ExceptIfAttachmentExtensionMatchesWords": ["pdf", "xls"],
"SetSCL": "9",
"SetAuditSeverity": "High"
} Transport Rule — Flag Password Notifications
{
"Name": "Baseline - Password Notification set SCL",
"State": "Enabled",
"Mode": "Enforce",
"Priority": 2,
"FromScope": "NotInOrganization",
"SubjectContainsWords": ["password", "wachtwoord"],
"SetSCL": "5",
"SetAuditSeverity": "Medium"
} Intune
baseline/intune/
Assignment Files — How They Work
Every Intune policy file can have a paired .assignment.json alongside it. The filename must match exactly — just append .assignment.json. If no assignment file exists, the policy is created but not assigned to anyone.
{
"target": {
"@odata.type": "#microsoft.graph.groupAssignmentTarget",
"groupId": "{{GROUP:Baseline - Modern Workplace Devices}}"
}
} [
{
"target": {
"@odata.type": "#microsoft.graph.groupAssignmentTarget",
"groupId": "{{GROUP:Baseline - Modern Workplace Users}}"
}
},
{
"target": {
"@odata.type": "#microsoft.graph.exclusionGroupAssignmentTarget",
"groupId": "{{GROUP:Baseline - Users DeviceLock 15min}}"
}
},
{
"target": {
"@odata.type": "#microsoft.graph.exclusionGroupAssignmentTarget",
"groupId": "{{GROUP:Baseline - Users DeviceLock 30min}}"
}
}
] | @odata.type | Effect |
|---|---|
groupAssignmentTarget | Assign to a specific group (include) |
exclusionGroupAssignmentTarget | Exclude a specific group from the assignment |
allDevicesAssignmentTarget | Assign to all devices (no groupId needed) |
allLicensedUsersAssignmentTarget | Assign to all licensed users (no groupId needed) |
This pattern applies to all Intune sub-types: compliance policies, settings catalog, app protection, autopilot, platform scripts, update rings, feature updates, quality updates, and driver updates.
Compliance Policies intune/compliance-policies/
Windows Compliance Policy
{
"@odata.type": "#microsoft.graph.windows10CompliancePolicy",
"displayName": "Baseline - Win10_11 Default Policy",
"passwordRequired": true,
"passwordMinimumLength": 8,
"bitLockerEnabled": true,
"secureBootEnabled": true,
"codeIntegrityEnabled": true,
"activeFirewallRequired": true,
"defenderEnabled": true,
"defenderVersion": "",
"signatureOutOfDate": false
} Settings Catalog intune/settings-catalog/
Enable Tamper Protection
{
"@odata.type": "#microsoft.graph.deviceManagementConfigurationPolicy",
"name": "Baseline - Enable Tamper Protection",
"platforms": "windows10",
"technologies": "mdm,microsoftSense",
"templateReference": {
"templateFamily": "endpointSecurityAntivirus",
"templateDisplayName": "Windows Security Experience",
"templateId": "d948ff9b-99cb-4ee0-8012-1fbc09685377_1"
},
"settings": {
"settingInstance": {
"@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance",
"settingDefinitionId": "vendor_msft_defender_configuration_tamperprotection_options",
"choiceSettingValue": {
"value": "vendor_msft_defender_configuration_tamperprotection_options_0"
}
}
}
} App Protection Policies intune/app-protection/
Android App Protection Policy
Files are prefixed with the platform: Android_ or iOS_.
{
"@odata.type": "#microsoft.graph.androidManagedAppProtection",
"displayName": "Baseline - App Policy for Android devices",
"periodOfflineBeforeWipeIsEnforced": "P30D",
"periodOnlineBeforeAccessCheck": "PT30M",
"allowedOutboundDataTransferDestinations": "managedApps",
"allowedOutboundClipboardSharingLevel": "allApps",
"saveAsBlocked": true,
"organizationalCredentialsRequired": false
} Autopilot intune/autopilot/
Windows Autopilot Deployment Profile
{
"@odata.type": "#microsoft.graph.azureADWindowsAutopilotDeploymentProfile",
"displayName": "Baseline Windows Autopilot",
"deviceType": "windowsPc",
"hardwareHashExtractionEnabled": true,
"preprovisioningAllowed": false,
"outOfBoxExperienceSettings": {
"hideEULA": true,
"deviceUsageType": "singleUser",
"userType": "standard",
"skipKeyboardSelectionPage": true,
"hideEscapeLink": true,
"hidePrivacySettings": true
},
"enableWhiteGlove": false
} Platform Scripts intune/platform-scripts-powershell/ & intune/platform-scripts-bash/
Two-file convention
Each platform script is stored as two sibling files in the same folder. The JSON holds policy metadata only — no base64 body. The companion script file holds the readable source code.
| Script type | Folder | Companion file |
|---|---|---|
| Windows PowerShell | platform-scripts-powershell/ | .ps1 (same base name) |
| macOS Shell | platform-scripts-bash/ | .sh (same base name) |
The deploy pipeline reads the companion file and re-encodes it to base64 at runtime — you never manage base64 manually. The backup pipeline automatically decodes and saves the companion file when it backs up from Intune.
PowerShell Script — example files platform-scripts-powershell/
{
"@odata.type": "#microsoft.graph.deviceManagementScript",
"displayName": "Baseline - Local Admin Strip Script",
"fileName": "localadmin.ps1",
"runAsAccount": "user",
"runAs32Bit": false,
"enforceSignatureCheck": false
} # Remove the current user from the local Administrators group $user = whoami Remove-LocalGroupMember -Group "Administrators" -Member $user -ErrorAction Stop Write-Output "Removed $user from Administrators"
macOS Shell Script — example files platform-scripts-bash/
{
"@odata.type": "#microsoft.graph.deviceShellScript",
"displayName": "Baseline - Enable PUA Protection",
"fileName": "enable-pua.sh",
"runAsAccount": "system",
"retryCount": 3,
"blockExecutionOfOtherScripts": false
} #!/bin/bash defaults write /Library/Preferences/com.apple.SoftwareUpdate \ AutomaticallyInstallMacOSUpdates -bool true exit 0
Remediations (Proactive Remediations) intune/remediations/
Remediations follow the same pattern but produce two companion script files per policy.
intune/remediations/ ├── Check Disk Space.json # policy metadata ├── Check Disk Space.detection.ps1 # detection script └── Check Disk Space.remediation.ps1 # remediation script
Windows Update Rings intune/windows-updates/
{
"@odata.type": "#microsoft.graph.windowsUpdateForBusinessConfiguration",
"displayName": "Baseline - Update ring for Windows 10 and later",
"qualityUpdatesDeferralPeriodInDays": 7,
"qualityUpdatesPaused": false,
"allowWindows11Upgrade": false,
"deliveryOptimizationMode": "userDefined",
"deadlineGracePeriodInDays": 1,
"skipChecksBeforeRestart": false,
"userWindowsUpdateScanAccess": "enabled"
} Feature Updates intune/windows-feature-updates/
{
"@odata.type": "#microsoft.graph.windowsFeatureUpdateProfile",
"displayName": "Baseline - WUB FU Windows 11",
"featureUpdateVersion": "Windows 11, version 25H2",
"installLatestWindows10OnWindows11IneligibleDevice": false,
"installFeatureUpdatesOptional": false,
"rolloutSettings": {
"offerStartDateTimeInUTC": null,
"offerEndDateTimeInUTC": null,
"offerIntervalInDays": null
}
} Quality Updates intune/windows-quality-updates/
{
"@odata.type": "#microsoft.graph.windowsQualityUpdatePolicy",
"displayName": "Baseline - Quality Catchup",
"expeditedUpdateSettings": {
"qualityUpdateRelease": "2026-01-13T00:00:00Z",
"daysUntilForcedReboot": 1
}
} Driver Updates intune/windows-driver-updates/
{
"@odata.type": "#microsoft.graph.windowsDriverUpdateProfile",
"displayName": "Baseline - Driver Updates",
"approvalType": "automatic",
"deploymentDeferralInDays": 7
} Windows 10 Device Restrictions — Important Behavior
For windows10GeneralConfiguration policies, only properties present in your JSON file are compared — the Graph API returns 200+ properties with defaults.
| Action | Result |
|---|---|
| Add a property to baseline | ✅ Setting configured in tenant |
| Change a property value | ✅ Setting updated in tenant |
| Remove a property from baseline | ⚠️ Setting is IGNORED, not reset |
| Set property to false/default | ✅ Setting explicitly reset |
To unconfigure a setting, explicitly set it to false or "notConfigured".
Authentication Methods
baseline/authentication-policies/
FIDO2 / Passkeys
{
"@odata.type": "#microsoft.graph.fido2AuthenticationMethodConfiguration",
"id": "Fido2",
"state": "enabled",
"isSelfServiceRegistrationAllowed": true,
"isAttestationEnforced": false,
"includeTargets": [
{ "targetType": "group", "id": "all_users" }
]
} Microsoft Authenticator
{
"@odata.type": "#microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration",
"id": "MicrosoftAuthenticator",
"state": "enabled",
"isSoftwareOathEnabled": false,
"includeTargets": {
"authenticationMode": "any",
"isRegistrationRequired": false,
"id": "all_users",
"targetType": "group"
},
"featureSettings": {
"displayAppInformationRequiredState": {
"state": "default",
"includeTarget": { "id": "all_users", "targetType": "group" }
},
"displayLocationInformationRequiredState": {
"state": "default",
"includeTarget": { "id": "all_users", "targetType": "group" }
}
}
} Cross-Tenant Placeholders
Placeholders allow the same JSON file to work across all tenants. Before applying, the pipeline scripts resolve each placeholder by querying the target tenant.
{{GROUP:Baseline - Emergency Access}} Resolves to: Object ID of the group in the target tenant
Used in: excludeGroups, groupId
{{LOCATION:Corporate Offices}} Resolves to: Named location ID in the target tenant
Used in: includeLocations, excludeLocations
{{TENANTID}} Resolves to: The target tenant's Tenant ID
Used in: Cross-tenant app references
Resource Protection — CONFIG365:IGNORE
Any M365 resource whose Description field contains the text CONFIG365:IGNORE is skipped by the engine during both Plan and Apply stages. Use this to protect hand-crafted or client-managed resources from ever being overwritten by the baseline.
How to protect a resource
Add CONFIG365:IGNORE anywhere in the resource's Description field in Entra ID or Intune. It can appear alongside other description text — the engine checks for the presence of the marker string.
Managed manually by IT helpdesk. CONFIG365:IGNORE Custom compliance policy for Exec devices. CONFIG365:IGNORE Supported resource types
The protection marker is checked across all resource types that have a Description field:
Configuration — config365-options.json
The marker text and whether protection is active are controlled per-tenant in config365-options.json:
{
"protectionMarker": "CONFIG365:IGNORE",
"protectionMarkerEnabled": true
} Set protectionMarkerEnabled to false to disable protection globally for that tenant without removing the marker from individual resources.
Plan output
Protected resources are listed under a PROTECTED RESOURCES section in the pipeline's Plan (WhatIf) output. They are never modified or deleted — even if listed in baseline-remove/.
Advanced Patterns
Exclude Specific Tenants from a Policy
Create a .baseline-ignore file in the tenant repo:
# Tenant has a legacy app that needs legacy auth conditional-access/policies/Baseline - ALL BLOCK BASIC.json # Skip all Windows Update rings for this tenant intune/windows-updates/*
Remove Resources from Tenants
Add a minimal JSON to baseline-remove/ — the pipeline will delete any resource matching that displayName:
{ "displayName": "Old Deprecated Policy" } Best Practices
Always deploy CA policies with state: "enabledForReportingButNotEnforced" initially, then switch to "enabled" after testing.
Roll out baseline changes to a single tenant first, verify the results, then deploy to the rest.
Use clear, descriptive displayNames. The "Baseline -" prefix is recommended for all baseline resources.
Deploy groups before policies that reference them. The pipeline runs groups first.
Keep Intune assignments in separate .assignment.json files alongside the policy file.
Use descriptive commit messages for all baseline changes — they serve as a change log.