6.1 Endpoint Security Policies and Security Baselines
Key Takeaways
- Endpoint security policies are purpose-built Intune policy types for security workloads such as antivirus, disk encryption, firewall, attack surface reduction, and endpoint detection and response.
- Security baselines are Microsoft-recommended collections of settings; targeted endpoint security policies are better when the requirement names one specific control such as BitLocker, Defender Antivirus, or firewall rules.
- MD-102 scenarios often test policy selection: use antivirus for Defender AV behavior, disk encryption for BitLocker or FileVault, firewall for network profile rules, and attack surface reduction for exploit and risky-behavior blocking.
- Configuration conflicts can occur when baselines, endpoint security policies, and device configuration profiles set the same setting differently on the same device.
- A secure design must include monitoring and remediation, not just assignment; verify deployment status, conflicts, device compliance, and security posture after policy rollout.
Why this matters for MD-102
The current Microsoft MD-102 study guide lists Protect devices at 15-20% of the exam and specifically calls out antivirus policies, disk encryption policies, firewall policies, attack surface reduction policies, security baselines, Microsoft Defender for Endpoint integration, onboarding, and update management. Expect scenario questions that ask which Intune control solves a precise protection requirement.
Endpoint protection in Intune is not one generic profile. The exam wants you to recognize the management surface, the platform, and the downstream effect. A requirement to configure Microsoft Defender Antivirus exclusions is different from a requirement to rotate a BitLocker recovery key, enforce firewall behavior across the domain, private, and public profiles, or deploy a Microsoft-recommended hardening package. Each endpoint security policy lives under Endpoint security in the Intune admin center and uses a focused, security-specific UI rather than the broad settings catalog.
Policy families you must distinguish
| Requirement cue | Best Intune area | What it controls | Common distractor |
|---|---|---|---|
| Real-time protection, scan behavior, Defender AV exclusions, security intelligence | Endpoint security > Antivirus | Microsoft Defender Antivirus and related AV settings | Feature updates or app configuration |
| BitLocker on Windows, FileVault on macOS, recovery behavior, encryption settings | Endpoint security > Disk encryption | Data-at-rest protection and recovery key escrow | Compliance policy alone |
| Domain/private/public firewall profiles or specific firewall rules | Endpoint security > Firewall | Built-in firewall behavior and network access controls | Delivery Optimization |
| Block risky behaviors such as malicious Office child processes, script abuse, credential theft paths, or device control rules | Endpoint security > Attack surface reduction | Hardening and exploit-path reduction | Antivirus only |
| Broad Microsoft-recommended hardening starting point | Endpoint security > Security baselines | Curated sets of settings for products such as Windows, Microsoft Defender for Endpoint, Microsoft Edge, and Windows 365 | Hand-built settings catalog profile for every setting |
| Onboard devices to Defender for Endpoint and configure EDR settings | Endpoint security > Endpoint detection and response | Security telemetry, onboarding, and EDR settings | Compliance policy only |
Baseline versus targeted setting
A security baseline is the fastest way to deploy a broad, opinionated set of Microsoft-recommended settings. Use it when the scenario says the organization wants Microsoft-recommended hardening quickly, wants a known starting posture, or is migrating security configuration from older Group Policy thinking into Intune. Baselines are versioned: Microsoft publishes new baseline versions, and you should plan to review and move policies to newer versions rather than leaving them on a superseded one.
A targeted endpoint security policy is the better answer when the scenario names a specific workload. If the stem says BitLocker, choose disk encryption. If it says Microsoft Defender Firewall, choose firewall. If it says ASR rules, choose attack surface reduction. If it says real-time protection, Defender AV scan settings, or exclusions, choose antivirus. The noun in the requirement points directly to the policy family.
Conflict and rollout discipline
Intune treats different policy types as configuration sources. If a baseline sets a firewall option and a separate firewall profile sets a different value for the same device, the result can be a conflict, and the conflicting setting may not apply at all. The exam will not always say "conflict" directly; it may describe settings that fail to apply, inconsistent device state, or two admins deploying duplicate controls. When a setting shows an error or "conflict" status in reporting, look for the same setting configured in more than one policy.
Use this rollout sequence for real-world and exam thinking:
- Start with a pilot device group and one clear policy intent.
- Deploy a baseline only after reviewing its defaults and the settings you intend to override.
- Use targeted endpoint security policies for settings that need ownership, tuning, or a separate lifecycle.
- Avoid setting the same value in a baseline, a settings catalog profile, and an endpoint security policy at the same time.
- Monitor assignment, device status, per-setting errors, and conflicts before broad deployment.
Exam decision pattern
When a question asks for a policy, identify the noun in the requirement first. "Encrypt" points to disk encryption, "network profiles/firewall rules" point to firewall, "malicious macros and exploit techniques" point to attack surface reduction, and "recommended set of settings" points to a security baseline. Compliance policies can evaluate whether a device meets a requirement, but they do not configure the security control; they read state, they do not enable BitLocker, firewall rules, or ASR rules.
Antivirus, ASR, and account protection in more depth
The antivirus family is broader than a single profile. On Windows it includes Microsoft Defender Antivirus settings (real-time protection, cloud-delivered protection, scan schedules, exclusions), a separate Windows Security experience profile that controls the end-user Windows Security app, and a Defender Update controls profile for managing security intelligence and platform update behavior. A scenario about hiding or customizing the user-facing Windows Security interface points to the Windows Security experience profile, not the core antivirus profile.
Attack surface reduction (ASR) policy is itself a family. It covers ASR rules (blocking behaviors such as Office apps creating child processes, credential theft from LSASS, or executable content from email), but also exploit protection, web protection / network protection, controlled folder access (an anti-ransomware control), and device control for removable storage.
When a stem describes blocking USB mass storage, choose device control; when it describes protecting specific folders from ransomware, choose controlled folder access; when it describes blocking macro and script abuse, choose ASR rules. These distinctions are common MD-102 traps because they all live under attack surface reduction.
Account protection rounds out the endpoint security policy types and overlaps with the Prepare-infrastructure domain. It includes Windows Hello for Business, credential and Credential Guard settings, Local Administrator Password Solution (Windows LAPS), and local user group membership. Knowing that LAPS and local group membership are reachable under Endpoint security > Account protection helps when a question frames them as security hardening rather than identity setup.
Reporting that proves the policy worked
Deploying a policy is not the same as the policy applying. Use the per-policy device status and per-setting status views to confirm success, error, or conflict, and check the Endpoint security dashboards (such as antivirus device status and the firewall/EDR summaries) to see fleet-wide posture. When a setting shows a conflict, the resolution is to remove the duplicate definition from the competing policy so a single source of truth controls that setting. This monitoring discipline is part of the exam's definition of a complete, secure design, not an optional extra.
A company wants to centrally configure Microsoft Defender Antivirus real-time protection, scan options, and exclusions on Windows devices. Which Intune policy family is the best fit?
Security leadership wants a quick Microsoft-recommended hardening starting point for Windows devices, with later tuning for exceptions. What should the administrator deploy first?
Which statements correctly describe endpoint security policies and baselines in Intune? Select all that apply.
Select all that apply