Template family: Intune — device configuration
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Configuration → Templates → Augmentt Default
What this template is for
Security Guideline Benchmarks per NIST Checklist 1161 Version 4.0.0 https://ncp.nist.gov/checklist/1161
Notes: 49.3 (L1) Configure 'Accounts: Rename administrator account' (Automated) AMAdministrator 49.4 (L1) Configure 'Accounts: Rename guest account' (Automated) AMGuest 49.9 (L1) Configure 'Interactive logon: Message text for users attempting to log on' (Automated) (NOT SET) 49.10 (L1) Configure 'Interactive logon: Message title for users attempting to log on' (Automated) (NOT SET) 4.11.7.2.14 (BL) Ensure 'Enforce drive encryption type on operating system drives: Select the encryption type: (device)' is set to 'Enabled: Full encryption' 22.9 (L1) Ensure 'ASR: Block all Office applications from creating child processes' is set to 'Audit'
Exceptions: 4.6.11.1 (L1) Ensure 'Hardened UNC Paths' is set to 'Enabled, with "Require Mutual Authentication", "Require Integrity", and “Require Privacy” set for all NETLOGON and SYSVOL shares'
What it actually does
| Setting | Value |
platforms | windows10 |
technologies | mdm |
templateReference.templateId | (empty) |
templateReference.templateFamily | none |
Anything not listed keeps the Microsoft default.
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
