Operations

Configuration Examples

JSON configuration examples for every policy type deployed by CONFIG365. All files live in the baseline repository.

12 min read Updated March 22, 2026

Overview

All configurations are JSON files in the baseline repository. Files are named after their displayName (e.g. Baseline - Require MFA.json). Intune policies also have a paired .assignment.json.

Conditional Access

baseline/conditional-access/

Named Location (IP-based)

named-locations/AVD.json
{
  "displayName": "AVD",
  "@odata.type": "#microsoft.graph.ipNamedLocation",
  "isTrusted": true,
  "ipRanges": [
    {
      "@odata.type": "#microsoft.graph.iPv4CidrRange",
      "cidrAddress": "20.202.0.0/16"
    }
  ]
}

Require MFA (Report-Only)

policies/Baseline - Require MFA.json
{
  "displayName": "Baseline - Require MFA for All Users",
  "state": "enabledForReportingButNotEnforced",
  "conditions": {
    "clientAppTypes": ["all"],
    "applications": { "includeApplications": ["All"] },
    "users": {
      "includeUsers": ["All"],
      "excludeGroups": ["{{GROUP:Baseline - Emergency Access}}"]
    }
  },
  "grantControls": {
    "operator": "OR",
    "builtInControls": ["mfa"]
  }
}

Block Legacy Authentication

policies/Baseline - ALL BLOCK BASIC.json
{
  "displayName": "Baseline - ALL BLOCK BASIC",
  "state": "enabled",
  "conditions": {
    "clientAppTypes": ["exchangeActiveSync", "other"],
    "applications": { "includeApplications": ["All"] },
    "users": { "includeUsers": ["All"] }
  },
  "grantControls": {
    "operator": "OR",
    "builtInControls": ["block"]
  }
}

Optional Application Exclusions

The optional-applications.json file lists app IDs that can be optionally excluded from CA policies via the custom security attribute mechanism.

optional-applications.json
{
  "applications": [
    { "appId": "0000002-0000-0ff1-ce00-000000000000", "displayName": "Office 365 Exchange Online" },
    { "appId": "00000003-0000-0ff1-ce00-000000000000", "displayName": "Office 365 SharePoint Online" }
  ]
}

Groups

baseline/groups/

Static Security Group

Baseline - Users MFA Excluded.json
{
  "displayName": "Baseline - Users MFA Excluded",
  "description": "Users excluded from MFA Conditional Access policies",
  "mailEnabled": false,
  "securityEnabled": true,
  "mailNickname": "baseline-users-mfa-excluded"
}

Dynamic Group

Baseline - Modern Workplace Users.json
{
  "displayName": "Baseline - Modern Workplace Users",
  "description": "All licensed users in the tenant",
  "mailEnabled": false,
  "securityEnabled": true,
  "mailNickname": "baseline-modern-workplace-users",
  "groupTypes": ["DynamicMembership"],
  "membershipRule": "(user.userType -eq \"Member\")",
  "membershipRuleProcessingState": "On"
}

Custom Security Attributes

baseline/custom-attributes/

Attribute Set

Define the attribute set first — attribute definitions belong to a set.

attribute-sets/BaselineCSAAppExclusions.json
{
  "id": "BaselineCSAAppExclusions",
  "description": "Custom security attributes for Conditional Access policy application exclusions",
  "maxAttributesPerSet": 500
}

Attribute Definition

attribute-definitions/BaselineCSAAppExclusions_CAExclusion.json
{
  "isSearchable": true,
  "id": "BaselineCSAAppExclusions_CAExclusion",
  "type": "String",
  "attributeSet": "BaselineCSAAppExclusions",
  "description": "Application exclusion tags for Conditional Access policies",
  "name": "CAExclusion",
  "status": "Available",
  "isCollection": true,
  "usePreDefinedValuesOnly": true,
  "_allowedValues": [
    { "id": "IntuneComplianceExcluded", "isActive": true },
    { "id": "BrowserIntuneComplianceExcluded", "isActive": true },
    { "id": "BrowserStrongAuthExcluded", "isActive": true },
    { "id": "MobileAppProtectionExcluded", "isActive": true },
    { "id": "MobileIntuneComplianceExcluded", "isActive": true },
    { "id": "ModernIntuneComplianceExcluded", "isActive": true }
  ]
}

Entra ID Settings

baseline/entra-id-device-settings/

Security Defaults & Tenant Settings

entra-id-settings.json
{
  "SecurityDefaults": {
    "IsEnabled": false,
    "_comment": "Set to false when using Conditional Access policies"
  }
}

Device Registration Policy (LAPS)

device-registration-policy.json
{
  "id": "deviceRegistrationPolicy",
  "multiFactorAuthConfiguration": "notRequired",
  "userDeviceQuota": 50,
  "azureADRegistration": {
    "isAdminConfigurable": false,
    "allowedToRegister": {
      "@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
    }
  },
  "azureADJoin": {
    "isAdminConfigurable": true,
    "allowedToJoin": {
      "@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
    },
    "localAdmins": {
      "enableGlobalAdmins": true,
      "registeringUsers": {
        "@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
      }
    }
  },
  "localAdminPassword": {
    "isEnabled": true
  }
}

Exchange Online

baseline/exchange/transport-rules/

Transport Rule — Flag HTML Attachments

transport-rules/Baseline - html attachments set SCL.json
{
  "Name": "Baseline - html attachments set SCL",
  "State": "Enabled",
  "Mode": "Enforce",
  "Priority": 1,
  "FromScope": "NotInOrganization",
  "AttachmentExtensionMatchesWords": ["htm", "html"],
  "ExceptIfAttachmentExtensionMatchesWords": ["pdf", "xls"],
  "SetSCL": "9",
  "SetAuditSeverity": "High"
}

Transport Rule — Flag Password Notifications

transport-rules/Baseline - Password Notification set SCL.json
{
  "Name": "Baseline - Password Notification set SCL",
  "State": "Enabled",
  "Mode": "Enforce",
  "Priority": 2,
  "FromScope": "NotInOrganization",
  "SubjectContainsWords": ["password", "wachtwoord"],
  "SetSCL": "5",
  "SetAuditSeverity": "Medium"
}

Intune

baseline/intune/

Assignment Files — How They Work

Every Intune policy file can have a paired .assignment.json alongside it. The filename must match exactly — just append .assignment.json. If no assignment file exists, the policy is created but not assigned to anyone.

Single group assignment
{
  "target": {
    "@odata.type": "#microsoft.graph.groupAssignmentTarget",
    "groupId": "{{GROUP:Baseline - Modern Workplace Devices}}"
  }
}
Multiple assignments (include + exclusion groups) — use an array
[
  {
    "target": {
      "@odata.type": "#microsoft.graph.groupAssignmentTarget",
      "groupId": "{{GROUP:Baseline - Modern Workplace Users}}"
    }
  },
  {
    "target": {
      "@odata.type": "#microsoft.graph.exclusionGroupAssignmentTarget",
      "groupId": "{{GROUP:Baseline - Users DeviceLock 15min}}"
    }
  },
  {
    "target": {
      "@odata.type": "#microsoft.graph.exclusionGroupAssignmentTarget",
      "groupId": "{{GROUP:Baseline - Users DeviceLock 30min}}"
    }
  }
]
@odata.type Effect
groupAssignmentTarget Assign to a specific group (include)
exclusionGroupAssignmentTarget Exclude a specific group from the assignment
allDevicesAssignmentTarget Assign to all devices (no groupId needed)
allLicensedUsersAssignmentTarget Assign to all licensed users (no groupId needed)

This pattern applies to all Intune sub-types: compliance policies, settings catalog, app protection, autopilot, platform scripts, update rings, feature updates, quality updates, and driver updates.

Compliance Policies intune/compliance-policies/

Windows Compliance Policy

Baseline - Win10_11 Default Policy.json
{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "displayName": "Baseline - Win10_11 Default Policy",
  "passwordRequired": true,
  "passwordMinimumLength": 8,
  "bitLockerEnabled": true,
  "secureBootEnabled": true,
  "codeIntegrityEnabled": true,
  "activeFirewallRequired": true,
  "defenderEnabled": true,
  "defenderVersion": "",
  "signatureOutOfDate": false
}

Settings Catalog intune/settings-catalog/

Enable Tamper Protection

Baseline - Enable Tamper Protection.json
{
  "@odata.type": "#microsoft.graph.deviceManagementConfigurationPolicy",
  "name": "Baseline - Enable Tamper Protection",
  "platforms": "windows10",
  "technologies": "mdm,microsoftSense",
  "templateReference": {
    "templateFamily": "endpointSecurityAntivirus",
    "templateDisplayName": "Windows Security Experience",
    "templateId": "d948ff9b-99cb-4ee0-8012-1fbc09685377_1"
  },
  "settings": {
    "settingInstance": {
      "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance",
      "settingDefinitionId": "vendor_msft_defender_configuration_tamperprotection_options",
      "choiceSettingValue": {
        "value": "vendor_msft_defender_configuration_tamperprotection_options_0"
      }
    }
  }
}

App Protection Policies intune/app-protection/

Android App Protection Policy

Files are prefixed with the platform: Android_ or iOS_.

Android_Baseline - App Policy for Android devices.json
{
  "@odata.type": "#microsoft.graph.androidManagedAppProtection",
  "displayName": "Baseline - App Policy for Android devices",
  "periodOfflineBeforeWipeIsEnforced": "P30D",
  "periodOnlineBeforeAccessCheck": "PT30M",
  "allowedOutboundDataTransferDestinations": "managedApps",
  "allowedOutboundClipboardSharingLevel": "allApps",
  "saveAsBlocked": true,
  "organizationalCredentialsRequired": false
}

Autopilot intune/autopilot/

Windows Autopilot Deployment Profile

Baseline Windows Autopilot.json
{
  "@odata.type": "#microsoft.graph.azureADWindowsAutopilotDeploymentProfile",
  "displayName": "Baseline Windows Autopilot",
  "deviceType": "windowsPc",
  "hardwareHashExtractionEnabled": true,
  "preprovisioningAllowed": false,
  "outOfBoxExperienceSettings": {
    "hideEULA": true,
    "deviceUsageType": "singleUser",
    "userType": "standard",
    "skipKeyboardSelectionPage": true,
    "hideEscapeLink": true,
    "hidePrivacySettings": true
  },
  "enableWhiteGlove": false
}

Platform Scripts intune/platform-scripts-powershell/ & intune/platform-scripts-bash/

Two-file convention

Each platform script is stored as two sibling files in the same folder. The JSON holds policy metadata only — no base64 body. The companion script file holds the readable source code.

Script type Folder Companion file
Windows PowerShell platform-scripts-powershell/ .ps1 (same base name)
macOS Shell platform-scripts-bash/ .sh (same base name)

The deploy pipeline reads the companion file and re-encodes it to base64 at runtime — you never manage base64 manually. The backup pipeline automatically decodes and saves the companion file when it backs up from Intune.

PowerShell Script — example files platform-scripts-powershell/

Baseline - Local Admin Strip Script.json
{
  "@odata.type": "#microsoft.graph.deviceManagementScript",
  "displayName": "Baseline - Local Admin Strip Script",
  "fileName": "localadmin.ps1",
  "runAsAccount": "user",
  "runAs32Bit": false,
  "enforceSignatureCheck": false
}
Baseline - Local Admin Strip Script.ps1
# Remove the current user from the local Administrators group
$user = whoami
Remove-LocalGroupMember -Group "Administrators" -Member $user -ErrorAction Stop
Write-Output "Removed $user from Administrators"

macOS Shell Script — example files platform-scripts-bash/

Baseline - Enable PUA Protection.json
{
  "@odata.type": "#microsoft.graph.deviceShellScript",
  "displayName": "Baseline - Enable PUA Protection",
  "fileName": "enable-pua.sh",
  "runAsAccount": "system",
  "retryCount": 3,
  "blockExecutionOfOtherScripts": false
}
Baseline - Enable PUA Protection.sh
#!/bin/bash
defaults write /Library/Preferences/com.apple.SoftwareUpdate \
  AutomaticallyInstallMacOSUpdates -bool true
exit 0

Remediations (Proactive Remediations) intune/remediations/

Remediations follow the same pattern but produce two companion script files per policy.

intune/remediations/
├── Check Disk Space.json              # policy metadata
├── Check Disk Space.detection.ps1    # detection script
└── Check Disk Space.remediation.ps1  # remediation script

Windows Update Rings intune/windows-updates/

Baseline - Update ring for Windows 10 and later.json
{
  "@odata.type": "#microsoft.graph.windowsUpdateForBusinessConfiguration",
  "displayName": "Baseline - Update ring for Windows 10 and later",
  "qualityUpdatesDeferralPeriodInDays": 7,
  "qualityUpdatesPaused": false,
  "allowWindows11Upgrade": false,
  "deliveryOptimizationMode": "userDefined",
  "deadlineGracePeriodInDays": 1,
  "skipChecksBeforeRestart": false,
  "userWindowsUpdateScanAccess": "enabled"
}

Feature Updates intune/windows-feature-updates/

Baseline - WUB FU Windows 11.json
{
  "@odata.type": "#microsoft.graph.windowsFeatureUpdateProfile",
  "displayName": "Baseline - WUB FU Windows 11",
  "featureUpdateVersion": "Windows 11, version 25H2",
  "installLatestWindows10OnWindows11IneligibleDevice": false,
  "installFeatureUpdatesOptional": false,
  "rolloutSettings": {
    "offerStartDateTimeInUTC": null,
    "offerEndDateTimeInUTC": null,
    "offerIntervalInDays": null
  }
}

Quality Updates intune/windows-quality-updates/

Baseline - Quality Catchup.json
{
  "@odata.type": "#microsoft.graph.windowsQualityUpdatePolicy",
  "displayName": "Baseline - Quality Catchup",
  "expeditedUpdateSettings": {
    "qualityUpdateRelease": "2026-01-13T00:00:00Z",
    "daysUntilForcedReboot": 1
  }
}

Driver Updates intune/windows-driver-updates/

Baseline - Driver Updates.json
{
  "@odata.type": "#microsoft.graph.windowsDriverUpdateProfile",
  "displayName": "Baseline - Driver Updates",
  "approvalType": "automatic",
  "deploymentDeferralInDays": 7
}

Windows 10 Device Restrictions — Important Behavior

For windows10GeneralConfiguration policies, only properties present in your JSON file are compared — the Graph API returns 200+ properties with defaults.

Action Result
Add a property to baseline ✅ Setting configured in tenant
Change a property value ✅ Setting updated in tenant
Remove a property from baseline ⚠️ Setting is IGNORED, not reset
Set property to false/default ✅ Setting explicitly reset

To unconfigure a setting, explicitly set it to false or "notConfigured".

Authentication Methods

baseline/authentication-policies/

FIDO2 / Passkeys

passkeys-fido2.json
{
  "@odata.type": "#microsoft.graph.fido2AuthenticationMethodConfiguration",
  "id": "Fido2",
  "state": "enabled",
  "isSelfServiceRegistrationAllowed": true,
  "isAttestationEnforced": false,
  "includeTargets": [
    { "targetType": "group", "id": "all_users" }
  ]
}

Microsoft Authenticator

microsoft-authenticator.json
{
  "@odata.type": "#microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration",
  "id": "MicrosoftAuthenticator",
  "state": "enabled",
  "isSoftwareOathEnabled": false,
  "includeTargets": {
    "authenticationMode": "any",
    "isRegistrationRequired": false,
    "id": "all_users",
    "targetType": "group"
  },
  "featureSettings": {
    "displayAppInformationRequiredState": {
      "state": "default",
      "includeTarget": { "id": "all_users", "targetType": "group" }
    },
    "displayLocationInformationRequiredState": {
      "state": "default",
      "includeTarget": { "id": "all_users", "targetType": "group" }
    }
  }
}

SharePoint Settings

baseline/sharepoint-settings/

Sharing Capability

sharepoint-sharingCapability.json
{
  "sharingCapability": "externalUserSharingOnly"
}

Valid values: disabled, externalUserSharingOnly, externalUserAndGuestSharing, existingExternalUserSharingOnly

Cross-Tenant Placeholders

Placeholders allow the same JSON file to work across all tenants. Before applying, the pipeline scripts resolve each placeholder by querying the target tenant.

{{GROUP:Baseline - Emergency Access}}

Resolves to: Object ID of the group in the target tenant

Used in: excludeGroups, groupId

{{LOCATION:Corporate Offices}}

Resolves to: Named location ID in the target tenant

Used in: includeLocations, excludeLocations

{{TENANTID}}

Resolves to: The target tenant's Tenant ID

Used in: Cross-tenant app references

Resource Protection — CONFIG365:IGNORE

Any M365 resource whose Description field contains the text CONFIG365:IGNORE is skipped by the engine during both Plan and Apply stages. Use this to protect hand-crafted or client-managed resources from ever being overwritten by the baseline.

How to protect a resource

Add CONFIG365:IGNORE anywhere in the resource's Description field in Entra ID or Intune. It can appear alongside other description text — the engine checks for the presence of the marker string.

Security Group — Description field in Entra ID
Managed manually by IT helpdesk. CONFIG365:IGNORE
Intune policy — Description field
Custom compliance policy for Exec devices. CONFIG365:IGNORE

Supported resource types

The protection marker is checked across all resource types that have a Description field:

Security Groups
Conditional Access Policies
CA Named Locations
Intune Policies (all types)
Enterprise Apps
Autopilot Profiles
Assignment Filters
Custom Security Attributes

Configuration — config365-options.json

The marker text and whether protection is active are controlled per-tenant in config365-options.json:

{
  "protectionMarker": "CONFIG365:IGNORE",
  "protectionMarkerEnabled": true
}

Set protectionMarkerEnabled to false to disable protection globally for that tenant without removing the marker from individual resources.

Plan output

Protected resources are listed under a PROTECTED RESOURCES section in the pipeline's Plan (WhatIf) output. They are never modified or deleted — even if listed in baseline-remove/.

Advanced Patterns

Exclude Specific Tenants from a Policy

Create a .baseline-ignore file in the tenant repo:

# Tenant has a legacy app that needs legacy auth
conditional-access/policies/Baseline - ALL BLOCK BASIC.json

# Skip all Windows Update rings for this tenant
intune/windows-updates/*

Remove Resources from Tenants

Add a minimal JSON to baseline-remove/ — the pipeline will delete any resource matching that displayName:

baseline-remove/conditional-access/Old Policy.json
{ "displayName": "Old Deprecated Policy" }

Best Practices

Report-Only First

Always deploy CA policies with state: "enabledForReportingButNotEnforced" initially, then switch to "enabled" after testing.

Test with One Tenant

Roll out baseline changes to a single tenant first, verify the results, then deploy to the rest.

Meaningful Names

Use clear, descriptive displayNames. The "Baseline -" prefix is recommended for all baseline resources.

Group Dependencies

Deploy groups before policies that reference them. The pipeline runs groups first.

Separate Assignments

Keep Intune assignments in separate .assignment.json files alongside the policy file.

Commit Messages

Use descriptive commit messages for all baseline changes — they serve as a change log.