Template family: Intune — device compliance
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Compliance → Templates → Augmentt Default

What this template is for

Baseline macOS compliance policy requiring FileVault encryption, Firewall enabled, SIP enabled, and minimum macOS 15.0. Gatekeeper configuration is handled separately via configuration policy. CIS v8: 4.3, 4.5, 7.3, 10.1.

What it actually does

Creates a macOSCompliancePolicy in Microsoft Intune configured as follows.

SettingValue
firewallEnabledtrue
osMinimumVersion15.0
passwordRequiredfalse
passwordBlockSimplefalse
passwordRequiredTypedeviceDefault
firewallBlockAllIncomingfalse
storageRequireEncryptiontrue
firewallEnableStealthModetrue
gatekeeperAllowedAppSourcenotConfigured
deviceThreatProtectionEnabledfalse
systemIntegrityProtectionEnabledtrue
deviceThreatProtectionRequiredSecurityLevelunavailable
advancedThreatProtectionRequiredSecurityLevelunavailable

Anything not listed keeps the Microsoft default.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.