Assignment of Microsoft 365 Apps for Enterprise Security Baseline

Pavel yannara Mirochnitchenko 11,986 Reputation points MVP
2023-09-12T06:11:38.47+00:00

So, the Microsoft 365 Apps for Enterprise Security Baseline creates some confusion in out Best Practise model, because it is the only baseline which has both Device and User based settings inside. I understand that some settings of Office needs to be assigned to User Context. But the publication of this kind of baseline brings some headache to our Best Practises. I am wondering, how others are dealing with this. Do you just assign it as-is for all users, or do you split it to 2 different baselines, devices vs. users? Our Intune BP is build on traditional assignment method (taken from Group Policy and SCCM ages), where all the standard system stuff is assigned to Devices and all the special role based non-mandatory stuff are assgned to users. Share your thoughts please :)

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,750 questions
Microsoft Intune Grouping
Microsoft Intune Grouping
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Grouping: The arrangement or formation of people or things in a group or groups.
41 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,479 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Lu Dai-MSFT 28,356 Reputation points
    2023-09-13T01:47:42.0666667+00:00

    @Pavel yannara Mirochnitchenko Thanks for posting in our Q&A.

    Not sure which is a best practise. I usually prefer Device based settings. If a setting doesn't have Device based setting, I will use the User based setting.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments