Deploy Windows Security Baseline
A Microsoft-curated baseline of hundreds of Windows hardening settings (UAC, SmartScreen, attack surface reduction, credential protection) deployed as an Intune policy and pinned to a recent version.
Reinventing a Windows hardening baseline is two weeks of engineering time you do not need to spend. Microsoft publishes one and updates it. Skipping it is the difference between secure-by-default and the registry equivalent of "factory settings."
Intune admin center, Endpoint security, Security baselines, Windows Security Baseline. Create a profile, accept the recommended settings, scope to All Devices excluding Personal, and watch the deployment metrics.
