Skip to content
Back to all tools
Category

SecurityTools

Enhance security monitoring and compliance in your environment

12tools available
Best Security tools
Documentation
Curated

Conditional Access Baseline

Conditional Access Baseline is a ready-to-use Intune baseline aligned with the Microsoft Conditional Access Baseline. It provides a reduced but comprehensive set of CA policies across identities, apps, and platforms, enforcing MFA, blocking legacy authentication, and applying risk-based controls. The baseline includes guidance to automate policy import (via IntuneManagementTool) and recommends adding break-glass accounts to the exclusion group CA-BreakGlassAccounts - Exclude.

Web App
Verified

Device Control Policy Editor for macOS

Defender Device Control macOS Policy Manager is a browser-based editor for authoring and exporting Microsoft Defender for Endpoint device-control policies as Apple .mobileconfig profiles. It combines a Monaco JSON editor, visual Groups/Rules/Entries, a recursive query builder, live validation, and a policy simulator, plus import/export to standard .mobileconfig for deployment via Jamf, Intune, or any MDM.

PS Script
Verified

Intune Make Enrollment User Admin

This Intune-deployable script elevates the enrollment user to a local administrator on Windows devices. Packaged as an .INTUNEWIN app, it is deployed through Microsoft Intune to targeted users with install and uninstall commands to grant or revoke admin rights after enrollment. It uses a requirements check for detection and can be reconfigured later, providing an Autopilot-like capability fully managed by Intune.

Niklas Rast
Niklas Rast
Security
PS Script
5/6 checks passed

IntuneStatefulDeviceFingerprinting

KuShu-Shimon Intune Stateful Device Fingerprinting (ISDF) provides a tamper-resistant device fingerprint for enrolled Windows devices, enforced via Intune Custom Compliance and DPAPI-encrypted baselines. In Cloud mode it attests fingerprints to Entra ID through APIM and a Logic App to enable trusted device filters, dynamic groups, and stronger Conditional Access policies. The solution collects on-device signals, stores encrypted baselines, self-heals missing keys, and reports ISDF booleans for compliant state.

Graham Hild
Graham Hild
Security
Web App
Curated

KQL Search

A specialized search engine for discovering Kusto Query Language (KQL) queries. Features query discovery across Microsoft Sentinel, Defender, and Azure Data Explorer, along with a Query Assistant, Query Generator, Query Lab for testing, and Device Query functionality. Aggregates community-contributed hunting queries and detection rules for threat hunting, vulnerability management, and incident response.

Ugur Koc
Ugur Koc
Security
PS Script
Verified

LAPS Reader

LAPS Reader is a Windows PowerShell/WPF GUI tool that retrieves Windows LAPS passwords stored in Intune (Entra) via Microsoft Graph. It signs in to Graph, resolves a device by display name, and displays the local account, password, backup time, and account SID with a one-click copy. Intended for IT/helpdesk staff, it requires the Microsoft.Graph.Authentication module and permissions DeviceLocalCredential.Read.All and Device.Read.All.

Other
Curated

Mace

M.A.C.E. is a native macOS app that lets security teams build, customize, audit, and deploy macOS compliance baselines using the mSCP 2.0 framework without scripting. It offers a visual, three-panel editor with 500+ rules, real-time audit results, and exportable configuration profiles for MDMs such as Intune and Jamf. The tool prioritizes ease of use, cross-MDM readiness, and reproducible baselines.

Cody Keats
Cody Keats
Security
PowerShell Module
Verified

MDEValidator

A PowerShell module for validating Microsoft Defender for Endpoint configurations. Checks service status, real-time protection, cloud protection, ASR rules, network protection, tamper protection, SmartScreen policies, and MDE onboarding status with HTML and console reporting.

Documentation
Verified

OpenIntuneBaseline

A community-driven security baseline framework for Microsoft Intune. Provides pre-configured security policies for Windows, Windows 365, and macOS aligned with NCSC, CIS Benchmarks, ACSC Essential Eight, and Microsoft best practices. Importable via IntuneManagement tool or native Intune import.

Web App
Curated

PIMBuddy

PIMBuddy helps you get a better overview about your PIM. It even let's you deploy PIM Policies and Groups within Seconds.

Roman Padrun
Roman Padrun
Security
Desktop App
Verified

Run as Domain User

A wrapper app that uses ShellRunAs to launch a target executable under a defined Active Directory domain user from non-domain-joined Windows devices. It enables cloud-managed devices to run legacy on-prem tools (RSAT) by prompting for domain credentials and launching the configured app with elevated rights. It relies on simple domain.txt and app.txt configuration and is packaged for Intune with explicit install/uninstall commands and a Start Menu entry.

Niklas Rast
Niklas Rast
Security