Template family: Intune — device compliance
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Compliance → Templates → Augmentt Default
What this template is for
Baseline macOS compliance policy requiring FileVault encryption, Firewall enabled, SIP enabled, and minimum macOS 15.0. Gatekeeper configuration is handled separately via configuration policy. CIS v8: 4.3, 4.5, 7.3, 10.1.
What it actually does
Creates a macOSCompliancePolicy in Microsoft Intune configured as follows.
| Setting | Value |
firewallEnabled | true |
osMinimumVersion | 15.0 |
passwordRequired | false |
passwordBlockSimple | false |
passwordRequiredType | deviceDefault |
firewallBlockAllIncoming | false |
storageRequireEncryption | true |
firewallEnableStealthMode | true |
gatekeeperAllowedAppSource | notConfigured |
deviceThreatProtectionEnabled | false |
systemIntegrityProtectionEnabled | true |
deviceThreatProtectionRequiredSecurityLevel | unavailable |
advancedThreatProtectionRequiredSecurityLevel | unavailable |
Anything not listed keeps the Microsoft default.
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
