Skip to content
Documentation
Curated

Conditional Access Baseline

Conditional Access Baseline is a ready-to-use Intune baseline aligned with the Microsoft Conditional Access Baseline. It provides a reduced but comprehensive set of CA policies across identities, apps, and platforms, enforcing MFA, blocking legacy authentication, and applying risk-based controls. The baseline includes guidance to automate policy import (via IntuneManagementTool) and recommends adding break-glass accounts to the exclusion group CA-BreakGlassAccounts - Exclude.

Screenshots

1 / 2

Swipe to see more

Security Analysis

Curated Tool

This tool has been reviewed and selected for inclusion in our collection. Source code is not publicly available for security scanning.

You might also like

Documentation

OpenIntuneBaseline

A community-driven security baseline framework for Microsoft Intune. Provides pre-configured security policies for Windows, Windows 365, and macOS aligned with NCSC, CIS Benchmarks, ACSC Essential Eight, and Microsoft best practices. Importable via IntuneManagement tool or native Intune import.

James RobinsonJames Robinson
PS Script

IntuneStatefulDeviceFingerprinting

KuShu-Shimon Intune Stateful Device Fingerprinting (ISDF) provides a tamper-resistant device fingerprint for enrolled Windows devices, enforced via Intune Custom Compliance and DPAPI-encrypted baselines. In Cloud mode it attests fingerprints to Entra ID through APIM and a Logic App to enable trusted device filters, dynamic groups, and stronger Conditional Access policies. The solution collects on-device signals, stores encrypted baselines, self-heals missing keys, and reports ISDF booleans for compliant state.

Graham HildGraham Hild
Web App

Device Control Policy Editor for macOS

Defender Device Control macOS Policy Manager is a browser-based editor for authoring and exporting Microsoft Defender for Endpoint device-control policies as Apple .mobileconfig profiles. It combines a Monaco JSON editor, visual Groups/Rules/Entries, a recursive query builder, live validation, and a policy simulator, plus import/export to standard .mobileconfig for deployment via Jamf, Intune, or any MDM.

Sascha StumplerSascha Stumpler
PS Script

Intune Make Enrollment User Admin

This Intune-deployable script elevates the enrollment user to a local administrator on Windows devices. Packaged as an .INTUNEWIN app, it is deployed through Microsoft Intune to targeted users with install and uninstall commands to grant or revoke admin rights after enrollment. It uses a requirements check for detection and can be reconfigured later, providing an Autopilot-like capability fully managed by Intune.

Niklas RastNiklas Rast