Skip to Content
ReportsIntune ReportsSecurity Baselines Report

Security Baselines Report

Security baseline assignment status and compliance across managed Windows devices. Track how well your devices align with Microsoft recommended security configurations.

Overview

The Security Baselines Report shows how your managed devices comply with Microsoft security baselines. These baselines represent Microsoft recommended security configurations for Windows, Microsoft Edge, Microsoft Defender for Endpoint, and Microsoft 365 Apps.

Report Columns

ColumnDescription
BaselineName of the security baseline
VersionBaseline version number
AssignedNumber of devices targeted
CompliantDevices meeting all baseline settings
ErrorDevices where baseline application failed
ConflictDevices with conflicting settings
Not ApplicableDevices where baseline does not apply
Compliance RatePercentage of fully compliant devices

Available Baselines

BaselineDescription
Windows Security BaselineCore Windows security settings
Microsoft Edge BaselineBrowser security and configuration
Defender for Endpoint BaselineEndpoint protection settings
Microsoft 365 Apps BaselineOffice application security
Windows 365 BaselineCloud PC security configuration

Per-Setting Compliance

For each baseline, drill down into individual settings:

  • Compliant Settings — Settings applied and matching the baseline
  • Non-compliant Settings — Settings that deviate from the baseline
  • Error Settings — Settings that could not be evaluated
  • Conflict Settings — Settings conflicting with other profiles

Filters

  • Baseline — Filter by specific security baseline
  • Status — Compliant, Non-compliant, Error, Conflict
  • Device Group — Filter by Intune device group
  • Tenant — Filter by managed tenant

Best Practices

  1. Start with the Windows Security Baseline as your foundation
  2. Layer additional baselines (Edge, Defender) for comprehensive coverage
  3. Review and resolve conflicts between baselines and custom profiles
  4. Update to the latest baseline version when Microsoft releases updates
  5. Test baseline changes with a pilot group before broad deployment

Graph API Data Sources

  • GET /deviceManagement/templates
  • GET /deviceManagement/configurationPolicies

API Reference

  • GET /api/reports/intune/security-baselines — Get security baselines report
  • GET /api/reports/intune/security-baselines/{baselineId} — Get specific baseline details
  • POST /api/reports/intune/security-baselines/export — Export report data
Last updated on