Setting up a security baseline
Security baselines are a quick start group of settings selected by Microsoft to quickly secure your tenant. They are available for Windows, Edge, Windows 365, and Microsoft Defender for Endpoint.
While they do not have the granularity of using the more bespoke Settings catalog-backed policies (covered in this chapter), they are a quick, easy, and useful way to get you up and running.
Should you decide to move to the more dedicated policies, make sure you change the associated setting in your baseline to Not configured; otherwise, you will find yourself with policy conflicts. There is an example JSON extract in this book’s GitHub repository that you can import (using the script found at https://andrewstaylor.com/2022/12/07/intune-backing-up-and-restoring-your-environment-new-and-improved/) into your environment and amend accordingly to get you started.
Microsoft also updates the baseline policies on a regular cadence to ensure you are always...