Introduction
Compliance settings in CM (also known as Desired Configuration Management (DCM) in the past- CM07) have improved greatly since CM12. While CM12 introduced the Remediation feature which could enforce a list of settings, CM Current Branch brings Compliance Settings to a whole new level by leveraging that existing feature to manage Mobile Devices without CM agent installed (enrolled via Microsoft Intune).
In CM Current Branch, Compliance Settings is used for two purposes:
Enforce compliance settings to CM agent installed machines (such as Windows 10, Mac OS X, and Windows clients and servers).
Enforce security policies to agentless mobile devices (such as iOS, Android, or Windows 10 Mobile devices).
This chapter will cover the first scenario and the following chapter will cover the mobile device scenario case.
There are a variety of ways to use compliance settings. The one you are already aware of is Software Updates, which are nothing more than a bunch of Configuration Items (CIs)...