@Joe Kwok , For Intune, it is a cloud service and can help deploy the policy to devices . Like the policies under Attack surface reduction. If you have other methods to deploy the policy setting like script. I think you can work without Intune.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.