Establishing compliance with security baseline assessments
As part of the MDVM add-on capabilities, you can use industry benchmarks to monitor endpoint security posture. Microsoft's own Security Baselines, CIS, or STIG options are available. At the time of writing, CIS can be applied to Windows 10/11 and Windows Server 2008 R2 or later; however, STIG benchmarks are only available for Windows 10 and Windows Server 2019. As time goes on, you can expect to see more benchmarks and OSs being supported.
Security baseline assessments are managed at security.microsoft.com under Endpoints | Vulnerability management | Baselines assessment. You’ll land on the Overview tab which, to start with, will be empty. To get started, go to the Profiles tab and click + Create. The steps that follow will guide you through the profile creation process:
- The first wizard page lets you enter a Name and Description (optional). You can choose Activate profile or leave this unticked, which...