> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/secure/intune/device-configuration.md).

# Device Configuration

{% hint style="info" %}
This page is a branch of [Intune](/modules/secure/intune.md), covering the **Device Configuration** policy category specifically. See that page first for how Templates, Baselines, and Policies relate to each other in general — everything below assumes that model.
{% endhint %}

Device Configuration profiles push device-level settings — restrictions, security hardening, update behavior, kiosk mode, VPN/Wi-Fi/certificate profiles, and dozens of other OS-level controls — onto enrolled devices. This is the largest and most detailed of the Intune policy categories in Augmentt, both in the number of settings a template can hold and in the number of built-in default templates Augmentt ships.

## What this category controls

A Device Configuration template captures the settings for **one** Intune device configuration profile — everything from "require a PIN" to a 500-setting security baseline. Under Microsoft Graph, Augmentt's Device Configuration category actually spans **two** different Graph APIs, and which one a given template uses depends on how it was built:

* **`/deviceManagement/deviceConfigurations`** — the classic, purpose-built profile types (Endpoint Protection, Device Restrictions, Identity Protection, Windows Health Monitoring, Update Rings, etc.), each with a fixed schema (`@odata.type` like `#microsoft.graph.windows10EndpointProtectionConfiguration`).
* **`/deviceManagement/configurationPolicies`** — the newer **Settings Catalog** model, where a policy is an arbitrary collection of individual `settingInstance` entries (each identified by a `settingDefinitionId` like `passcode_maximumfailedattempts`), letting a single profile mix settings that used to require several classic profile types. Most of Augmentt's own default templates (the CIS Windows 11 benchmark, the macOS DDM profiles, ASR, Credential Guard, BitLocker, and others below) are built this way.

Augmentt doesn't force you to pick one or the other explicitly — when you import a policy from a tenant, Augmentt captures whichever type it already is; when you deploy a default template, it recreates it as the type it was authored as.

{% hint style="warning" %}
Editing a deployed Device Configuration policy from Augmentt works for both API shapes, but the edit UI differs: classic `deviceConfigurations` policies show grouped settings you can toggle directly; Settings Catalog `configurationPolicies` policies show the flat list of settings as captured, and if the policy structure isn't one Augmentt recognizes, settings display read-only and you're pointed back to the Intune admin center or a data resync.
{% endhint %}

## Configuration surface

Because Device Configuration covers the largest slice of what Intune can configure, the settings surface below is organized by platform, matching how the Intune admin center groups them and how Augmentt's own template picker presents them.

### Windows

* **Device restrictions / kiosk** — kiosk mode (single full-screen Win32 app vs. multi-app), user logon type (auto-logon vs. local standard "visitor" account), Microsoft Edge kiosk mode (public browsing/InPrivate vs. digital signage), idle browser refresh, and a maintenance window (recurrence, day of week/month, start time) for app restarts.
* **Windows Update rings / Windows Update for Business** — update deferral and deadline settings, automatic update mode, delivery optimization mode, business-ready-updates-only gating, and — as shipped in Augmentt's default templates — Autopatch-driven update policies for both Microsoft 365 Apps and Microsoft Edge (deadline/deferral/channel).
* **Endpoint protection / security** — BitLocker (base settings, OS drive settings, fixed data-drive settings, removable data-drive settings), Windows Firewall (per-network-profile enable, block-all-incoming, stealth mode), Attack Surface Reduction rules (block/audit toggles per ASR rule, e.g. credential-stealing from LSASS, Office child-process creation, USB-run untrusted binaries), Microsoft Defender Credential Guard (UEFI lock, Windows Hello for Business PIN policy), Local Administrator Password Solution (LAPS) settings (account name, backup destination, password age/length/complexity, post-authentication actions), User Account Control elevation-prompt behavior, LAN Manager authentication level, and Microsoft Defender SmartScreen (enable, block potentially-unwanted apps).
* **Networking** — Wi-Fi profiles (security type), wired (Ethernet) network profiles (interface, EAP type, inner authentication, auth mode), and VPN profiles (auth type, connection type).
* **Identity / SSO** — certificate-based authentication settings (PKCS certificate key storage provider) and related credential provider configuration.
* **Applicability rules** — Assign/don't-assign conditions on OS edition, OS version range, or device mode (standard vs. shared), so a single template can self-exclude on devices it shouldn't apply to.
* **OneDrive** — known-folder redirection control, silent sign-in and silent move of known folders, Files On-Demand, low-disk-space warning threshold, sync health reporting, and file-type exclusions from upload.

### macOS

* **Passcode** — minimum length, complexity, failed-attempt limits and reset window, grace period, and maximum passcode age (via the Settings Catalog / Declarative Device Management passcode payload).
* **FileVault** — enable during Setup Assistant, with recovery-key escrow to Microsoft Entra ID.
* **Gatekeeper** — allowed app sources (Anywhere / Mac App Store / Mac App Store and identified developers / not configured), plus related system-policy controls (identified-developer allowance, XProtect malware-upload reporting, and preventing users from overriding the policy).
* **Firewall** — enable, block all incoming, stealth mode.
* **System restrictions** — Guest account disable and other best-practice lockdowns.
* **Power management** — display-sleep and system-sleep timers (AC and battery), Wake-on-LAN.
* **Screensaver / screen lock** — idle-activation timer, password-on-wake requirement, delay, and login-window idle timeout.
* **Network Time Protocol** — NTP server assignment.
* **Software update policy** — update deferral/scheduling for macOS.
* **Microsoft Edge and Microsoft Office configuration** (macOS) — Edge browser policy (certificate management, network policy, system integration settings) and Office auto-update behavior (grace period, update-check interval, update channel, app registration on launch, New Outlook opt-in).
* **Entra Platform SSO** — Platform Single Sign-On configuration for Entra ID authentication on macOS.

### iOS/iPadOS

* **Device features** — asset tag template, lock-screen footnote, home-screen grid/dock/pages layout, wallpaper (lock and/or home screen).
* **Single sign-on** — SSO extension configuration (including the deprecated legacy extension type), Kerberos principal name/realm, PKINIT certificate, credential renewal certificate, and allowed apps/URLs the SSO extension applies to.
* **Web content filter.**
* **Notifications** — per-app notification settings (enabled, alert type, badges, sounds, preview visibility, Notification Center visibility).
* **AirPrint** — destination list (IP, resource path, port), Force TLS.
* **Software update** — desired OS version, scheduled install days, UTC time offset, enforced delay, and update-schedule type (always / outside active hours / during or outside specific time windows, with custom windows defined by start/end day and time).
* **VPN** — base VPN and Automatic VPN (type, targeted apps, proxy use).
* **Device type applicability** — iPad vs. iPhone/iPod scoping.

### Android

* **Enrollment type scoping** — Android Enterprise (fully managed / personal / dedicated / corporate-owned work profile), Android device administrator, Android (AOSP), each with their own settings subset.
* **Work profile / device owner restrictions** — the settings surface here is large and grouped into device-owner and work-profile subsections (keyguard features, app restrictions, and more) mirroring the Intune admin center's Android restriction categories.
* **Google Play Services** configuration check.

### Cross-platform / general

* **Assignment** — target all users, all devices, or specific Entra groups, with include/exclude group support (a group can't be both included and excluded).
* **Applicability rules** (Windows) as noted above.
* **Scope tags** — carried through on import/edit but treated as read-only on PATCH (Graph rejects changes to `supportsScopeTags` via update).

## Default templates Augmentt ships

Augmentt ships **24 built-in Device Configuration templates**, unaffiliated with any customer tenant, available alongside your own imported templates in the template picker. Nearly all cite the specific CIS Controls v8 safeguard(s) they help satisfy in their description. Exact settings are reproduced below at the level Augmentt stores them (the full CIS Windows 11 benchmark and Windows Firewall templates run to hundreds of individual Settings Catalog entries and are summarized rather than reproduced setting-by-setting).

### macOS

| Template                           | Key settings                                                                                                                                                                                             | CIS v8           |
| ---------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------- |
| **DDM Passcode Configuration**     | Passcode required; failed-attempt reset window 0 min; max grace period 0 min; max failed attempts before wipe/lock **11**; max passcode age **365 days**; min complex characters **1**; min length **6** | —                |
| **Edge Browser Level 1 Basic**     | Enhanced Microsoft Edge baseline (certificate management, network policy, system integration) addressing gap-analysis findings                                                                           | 9.2, 9.3         |
| **Antivirus - Microsoft Defender** | Cloud-delivered protection enabled; automatic security-intelligence updates; real-time protection enabled; tamper protection enabled                                                                     | 10.1, 10.4, 10.7 |
| **Gatekeeper Security**            | App-source security assessment enabled; identified developers allowed; XProtect malware-upload reporting enabled; users prevented from overriding policy                                                 | 7.3, 7.4         |
| **Entra Platform SSO**             | Platform SSO configured for Entra ID authentication                                                                                                                                                      | —                |
| **FileVault Disk Encryption**      | FileVault enabled during Setup Assistant; recovery key escrowed to Microsoft Endpoint Manager (Entra ID)                                                                                                 | 3.6              |
| **Firewall Enabled**               | macOS Firewall enabled                                                                                                                                                                                   | 4.5              |
| **Power Management**               | Display sleep **5 min**, system sleep **10 min** (AC and battery); Wake on LAN disabled                                                                                                                  | 4.8              |
| **System Restrictions**            | Guest account disabled plus other best-practice restrictions                                                                                                                                             | 4.7, 10.3        |
| **Network Time Protocol**          | NTP server set to `time.apple.com`                                                                                                                                                                       | —                |
| **Screensaver Security**           | Idle activation **10 min**; password required on wake; delay and login-window idle timeout configured                                                                                                    | 4.3              |
| **Microsoft Office Configuration** | Auto-update enabled (3-day grace period); update check every **240 minutes**; register app on launch; update channel **Current**; New Outlook enabled                                                    | —                |
| **Software Update Policy**         | macOS software update scheduling                                                                                                                                                                         | 7.3              |

### Windows

| Template                                                                      | Key settings                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | CIS v8                                      |
| ----------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
| **Disable Remote Assistance**                                                 | Unsolicited Remote Assistance disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | 4.8                                         |
| **Antivirus - Windows**                                                       | Archive scanning, behavior monitoring, cloud protection, email scanning, intrusion prevention, download/attachment scanning, real-time monitoring, network-file scanning, script scanning, full removable-drive scan all allowed/enabled; PUA protection enabled (block + log)                                                                                                                                                                                                                                              | 10.1, 10.4, 10.7                            |
| **Attack Surface Reduction**                                                  | Block: exploited signed drivers, Adobe Reader child processes, Office child processes, LSASS credential theft, email/webmail executable content, unsigned/low-prevalence executables, JS/VBScript-launched downloads, Office executable-content creation, Office code injection, WMI event-subscription persistence, untrusted USB processes, Office macro Win32 API calls; Audit: obfuscated scripts, Office communication-app child processes, PSExec/WMI-originated process creation; ransomware protection set to Audit | 10.5                                        |
| **CIS Microsoft Intune for Windows 11 Benchmark - 2025**                      | Full CIS/NIST Checklist 1161 v4.0.0 benchmark — hundreds of Settings Catalog entries covering account policies, local security options, BitLocker, ASR, credential protection, and more. Notable documented deviations from the raw checklist: administrator/guest account renamed to `AMAdministrator`/`AMGuest`; interactive logon messages left not set; drive-encryption type forced to Full Encryption; the Office child-process ASR rule set to Audit (not Block); Hardened UNC Paths **excluded**                    | full benchmark (NIST checklist 1161 v4.0.0) |
| **Screen Inactivity**                                                         | Automatic device lock after **15 minutes**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | 4.3                                         |
| **Windows Firewall**                                                          | Firewall enabled for Domain, Private (Internal), and Public (External) profiles                                                                                                                                                                                                                                                                                                                                                                                                                                             | 4.5                                         |
| **OneDrive Folder Sync**                                                      | Users blocked from moving/redirecting OneDrive or known folders; personal-account sync blocked; known folders silently moved to OneDrive; silent sign-in with Windows credentials; auto-start on sign-in; Files On-Demand enabled; low-disk-space warning at **5000 MB**; sync health reporting enabled; Office file sync-conflict handling left to user choice; file-type exclusions not configured                                                                                                                        | —                                           |
| **LAPS**                                                                      | Administrator account name `am-admin`; password backed up to Microsoft Entra ID; password age **30 days**; complexity: large + small letters + numbers + special characters; length **15**; post-authentication actions: reset password, log off managed account, and terminate interactive sessions, reset after **1 hour**                                                                                                                                                                                                | 5.2                                         |
| **Microsoft Edge - Microsoft Defender Smart Screen**                          | SmartScreen enabled; block potentially unwanted apps                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | 10.5                                        |
| **Microsoft Defender - Credential Guard**                                     | Credential Guard enabled with UEFI lock; PIN history **14**; minimum PIN length **6**; upper/lowercase letters allowed in PIN; Windows Hello for Business required                                                                                                                                                                                                                                                                                                                                                          | 10.5                                        |
| **Microsoft 365 Apps Update Policy - Autopatch - Scheduled - Stable Release** | Update deadline/deferral for Microsoft 365 Apps, required by the Windows Autopatch service                                                                                                                                                                                                                                                                                                                                                                                                                                  | 7.3                                         |
| **Edge Update Policy - Autopatch - Automatic - Stable Release**               | Automatic Edge Stable-channel update deployment, required by Windows Autopatch                                                                                                                                                                                                                                                                                                                                                                                                                                              | 7.3                                         |
| **Bitlocker**                                                                 | Device encryption required; BitLocker enabled with best-practice settings; end user allowed to encrypt on Entra ID join; OS drive recovery key synced to Entra ID                                                                                                                                                                                                                                                                                                                                                           | 3.6                                         |

## Resolves posture check(s)

Augmentt's automated posture/compliance-audit engine (`SECURE_CHECK_TYPES` / `COMPLIANCE_AUDIT.*`) does not currently include dedicated automated checks that grade a tenant's live Device Configuration policies the way it does for Conditional Access and Defender templates. Instead, each default template's value is expressed as the specific external framework control(s) it satisfies, embedded directly in the template description:

* **CIS Controls v8** safeguards — cited per-template above (e.g., 3.6 Encrypt data on removable/end-user devices; 4.3/4.5/4.7/4.8 secure configuration and firewall/session controls; 5.2 unique/rotated administrator credentials; 7.3 automated OS patching; 9.2/9.3 browser hardening; 10.1/10.4/10.5/10.7 anti-malware, ASR, and SmartScreen protections).
* **CIS Microsoft Intune for Windows 11 Benchmark** (2025 edition) and the underlying **NIST National Checklist Program entry 1161** — satisfied wholesale by deploying the "CIS Microsoft Intune for Windows 11 Benchmark - 2025" template, with the documented exceptions noted in the table above.

If you need a Device Configuration setting that maps to an Augmentt Secure Score / Compliance Audit check specifically (for example, the Intune-enrollment sign-in frequency control), see [Device Compliance](/modules/secure/intune/device-compliance.md) and [Conditional Access](/modules/secure/conditional-access.md) — that particular check is enforced through a Conditional Access policy, not a Device Configuration profile.

## Related pages

* [Intune](/modules/secure/intune.md) — the parent page covering Templates/Baselines/Policies and the general Intune workflow.
* [Device Compliance](/modules/secure/intune/device-compliance.md)
* [Conditional Access](/modules/secure/conditional-access.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/secure/intune/device-configuration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
