Sorry my bad as well - Endpoint Security contains baselines for Windows, Defender and Edge. These are prio 1 from MS point of view. Other features from Endpoint Security is up to you, but you probably want to manage Antivirus, Firewall and Bitlocker at least. It is important that whatever you do, you don't overlap same settings from multiple sources/profiles. Also, if you start using Defender for Endpoint, you will realize you might need ASR for example, to cover all security recommendations.
Detect conflincting setting profiles
Hi
We can configure different kind of settings, in Endpoint portal, by using Security Baseline profiles, Configuration profiles and Endpoint Security profiles. All of these are equal so if there is two different configuration for same setting, these profiles will conflict.
Do we have any kind of way to scan these profiles for situations, where several profiles configures the same setting, either using the same configuration or conflicting configuration?
4 additional answers
Sort by: Most helpful
-
Pavel yannara Mirochnitchenko 10,771 Reputation points
2022-10-19T12:15:52.677+00:00 - First, you should apply security baseline, configure additional settings you want with Settings Catalog. Admin templates and restrictions are becomming obsolete.
- You should able to see conflict between configuration profiles, when you navigate to single device in intune portal and see its configurations. It should list you all green, confict, error or not applicable.
- If Intune console does not reveal you the actual reason, you go to Event Viewer \ Applications and service logs\ Microsoft \ DeviceManagement-Enterprice-Diagnostic Provider. This event location should reveal you the root cause.
-
IMK 361 Reputation points
2022-10-19T13:20:23.283+00:00 Hi
What about Endpoint Security profiles? We are using Endpoint portal to configure Defender settings (AV, EDR and so on).
Should we use the Endpoint Security profiles or is it recommended to instead use Configuration profiles/Settings Catalog settings?
-
IMK 361 Reputation points
2022-10-19T16:43:00.99+00:00 Sorry, got a bit confused..
First is to configure Endpoint Security profiles.
Second is to configure Configuration/Settings Catalog profiles.
Does this leave need or should I use Baseline profiles at all? Or should I check from Baseline profiles some succestions on how to configure Endpoint Sec and Configuration profiles?
-