Intune Baseline Assessment (86 controls)
Registry v2.1.0 — windows, macos, ios, android — corporate ownership
Job ID: demo-tune-0422
Policy Insights
We found 7 settings that exist in multiple Intune policies. Including 3 value conflicts where policies disagree on the correct setting. 3 redundant settings could be consolidated. 1 unassigned duplicates are inactive and can be cleaned up.
Remediation Planner
AI analyzes your assessment results and generates a remediation plan — classifying each control for auto-deployment, runbook generation, or risk exception.
- Auto-deploy fixes for non-compliant Intune policies
- Generate runbooks for manual remediation steps
- Set risk exceptions and document justifications
Assessment Results
Assessment Score
Scanned: 4/22/2026, 3:06:12 PM — 132s
68%
ProtectionProtectionShare of controls configured correctly AND assigned to users or devices — what’s actively defending your fleet right now.passed / total
Actively enforced
76%
ReadinessReadinessShare of controls configured correctly, whether or not they’re assigned. Counts policies that exist with the right settings but haven’t been deployed to a scope yet.(passed + not-enforced) / totalThe gap between Readiness and Protection is your fastest compliance win — the work is done, it just needs an assignment.
Configured correctly
60
Passing
5
Not Assigned
3
Report-Only
14
Misconfigured
4
Missing
Score Breakdown
Control Status
8% gap from policies not enforced
5 controls correctly configured but not assigned to any device group. Assign these policies to close the gap.
Assign Existing Policies
5 controls across 5 policies are correctly configured but not assigned to any device or user group. Assigning them is a one-click fix that lifts your adjusted score immediately.
Enrollment Restriction Mismatches (1)
iOS personal enrollment is not blocked. Corporate devices ownership model is set but personal enrollments are accepted.
See how your protection score improves with each remediation step:
+8.2% gain
+13.7% gain
Control Results
86 of 86 controls
🔴 Misconfigured14
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
Policy value does not match the required baseline. Current value diverges from expected; update in place or create override.
🟡 Not Enforced5
Policy is configured correctly but not assigned to any group. Assign to target devices/users.
Policy is configured correctly but not assigned to any group. Assign to target devices/users.
Policy is configured correctly but not assigned to any group. Assign to target devices/users.
Policy is configured correctly but not assigned to any group. Assign to target devices/users.
Policy is configured correctly but not assigned to any group. Assign to target devices/users.
⚪ Missing4
No matching Intune policy found. Create a new policy from the curated Veri-Tune baseline.
No matching Intune policy found. Create a new policy from the curated Veri-Tune baseline.
No matching Intune policy found. Create a new policy from the curated Veri-Tune baseline.
No matching Intune policy found. Create a new policy from the curated Veri-Tune baseline.
✅ Passing60
Configured and assigned correctly via 'Device Compliance — Require FileVault on macOS'.
Configured and assigned correctly via 'Device Compliance — Block rooted Android devices'.
Configured and assigned correctly via 'Device Compliance — iOS minimum OS version'.
Configured and assigned correctly via 'Endpoint Security — ASR — Block Win32'.
Configured and assigned correctly via 'Endpoint Security — macOS System Integrity Protection'.
Configured and assigned correctly via 'Endpoint Security — Disk encryption — recovery'.
Configured and assigned correctly via 'Device Compliance — Require BitLocker on Windows'.
Configured and assigned correctly via 'Device Compliance — Android minimum OS version'.
Configured and assigned correctly via 'Device Compliance — Device password required (Android)'.
Configured and assigned correctly via 'Device Compliance — Valid operating system (Windows)'.
Configured and assigned correctly via 'Device Compliance — Valid operating system (macOS)'.
Configured and assigned correctly via 'Device Compliance — Require compliant device for'.
Configured and assigned correctly via 'App Protection — Android App Protection —'.
Configured and assigned correctly via 'App Protection — iOS APP — block'.
Configured and assigned correctly via 'App Protection — Android APP — block'.
Configured and assigned correctly via 'App Protection — Android APP — offline'.
Configured and assigned correctly via 'App Protection — Android APP — block'.
Configured and assigned correctly via 'Endpoint Security — Windows Defender — real-time'.
Configured and assigned correctly via 'Endpoint Security — Windows Defender — cloud-delivered'.
Configured and assigned correctly via 'Endpoint Security — macOS XProtect — latest'.
Configured and assigned correctly via 'Endpoint Security — Disk encryption — BitLocker'.
Configured and assigned correctly via 'Device Configuration — Disable AutoPlay on all'.
Configured and assigned correctly via 'Device Configuration — Android — block debugging'.
Configured and assigned correctly via 'Enrollment — Autopilot deployment profile —'.
Configured and assigned correctly via 'Enrollment — Enrollment restrictions — require'.
Configured and assigned correctly via 'Device Compliance — macOS minimum OS version'.
Configured and assigned correctly via 'Device Compliance — Device password required (Windows)'.
Configured and assigned correctly via 'Device Compliance — Device password required (macOS)'.
Configured and assigned correctly via 'Device Compliance — Device password required (iOS)'.
Configured and assigned correctly via 'Device Compliance — Defender ATP risk score'.
Configured and assigned correctly via 'Device Compliance — Android Google Play Protect'.
Configured and assigned correctly via 'App Protection — iOS App Protection —'.
Configured and assigned correctly via 'App Protection — iOS APP — require'.
Configured and assigned correctly via 'App Protection — Android APP — require'.
Configured and assigned correctly via 'App Protection — iOS APP — offline'.
Configured and assigned correctly via 'App Configuration — Edge — block personal'.
Configured and assigned correctly via 'App Configuration — Outlook mobile — block'.
Configured and assigned correctly via 'App Configuration — Microsoft Authenticator — require'.
Configured and assigned correctly via 'Endpoint Security — ASR — Block obfuscated'.
Configured and assigned correctly via 'Endpoint Security — ASR — Block persistence'.
Configured and assigned correctly via 'Endpoint Security — Windows Defender — PUA'.
Configured and assigned correctly via 'Device Configuration — Block USB mass storage'.
Configured and assigned correctly via 'Device Configuration — Require TPM 2.0 present'.
Configured and assigned correctly via 'Device Configuration — Secure Boot enabled'.
Configured and assigned correctly via 'Device Configuration — Screen lock timeout —'.
Configured and assigned correctly via 'Device Configuration — Screen lock timeout —'.
Configured and assigned correctly via 'Device Configuration — Block guest account access'.
Configured and assigned correctly via 'Device Configuration — Android — require Work'.
Configured and assigned correctly via 'Update Rings — Windows 10/11 Update Ring'.
Configured and assigned correctly via 'Update Rings — Windows 10/11 Update Ring'.
❓ report-only3
Policy is deployed in report-only mode. Flip to enforced when ready.
Policy is deployed in report-only mode. Flip to enforced when ready.
Policy is deployed in report-only mode. Flip to enforced when ready.
Registry v2.1.0 | Tenant: demo-ver... | Powered by Veri-Tune
