# Intune

![](https://2434432314-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCTly3knsVr9zUXbWG1eo%2Fuploads%2FKbbnmy5yz1urajmthyff%2FIntune%20Logo.jfif?alt=media\&token=d83e40b5-cea2-4696-bf86-f1cdf5811289)

**Section Purpose:** The security section shows recommend security controls for Teams based on the CIS Controls. Each control contains the following subsections:

* Description
* Policy Definition
* Licensing Considerations&#x20;
* Set Up Instructions
* End-User Impact
* PowerShell Scripts
* Video Tutorials

| Policy                                                                                                                                                                                                                                                            | End-User Impact                                   | License     |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- | ----------- |
| [personal-devices-should-be-restricted-from-enrolling-into-the-mdm-solution](https://docs.tminus365.com/security/intune/personal-devices-should-be-restricted-from-enrolling-into-the-mdm-solution "mention")                                                     | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [devices-shall-be-deleted-that-havent-checked-in-for-over-30-days](https://docs.tminus365.com/security/intune/devices-shall-be-deleted-that-havent-checked-in-for-over-30-days "mention")                                                                         | <mark style="background-color:green;">Low</mark>  | Standard    |
| [devices-compliance-policies-shall-be-configured-for-every-supported-device-platform](https://docs.tminus365.com/security/intune/devices-compliance-policies-shall-be-configured-for-every-supported-device-platform "mention")                                   | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [noncompliant-devices-shall-be-blocked-from-accessing-corporate-resources](https://docs.tminus365.com/security/intune/noncompliant-devices-shall-be-blocked-from-accessing-corporate-resources "mention")                                                         | <mark style="background-color:red;">High</mark>   | Azure AD P1 |
| [mfa-shall-be-required-for-intune-enrollment](https://docs.tminus365.com/security/intune/mfa-shall-be-required-for-intune-enrollment "mention")                                                                                                                   | <mark style="color:yellow;">Medium</mark>         | Azure AD P1 |
| [security-baselines-should-be-configured-for-windows-devices](https://docs.tminus365.com/security/intune/security-baselines-should-be-configured-for-windows-devices "mention")                                                                                   | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [windows-update-rings-shall-be-configured-for-windows-devices](https://docs.tminus365.com/security/intune/windows-update-rings-shall-be-configured-for-windows-devices "mention")                                                                                 | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [update-policies-shall-be-configured-for-apple-devices](https://docs.tminus365.com/security/intune/update-policies-shall-be-configured-for-apple-devices "mention")                                                                                               | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [app-protection-policies-should-be-created-for-mobile-devices](https://docs.tminus365.com/security/intune/app-protection-policies-should-be-created-for-mobile-devices "mention")                                                                                 | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [mobile-devices-shall-only-be-able-to-access-corporate-data-through-approved-client-apps](https://docs.tminus365.com/security/intune/mobile-devices-shall-only-be-able-to-access-corporate-data-through-approved-client-apps "mention")                           | <mark style="color:yellow;">Medium</mark>         | Azure AD P1 |
| [lockout-screen-and-password-settings-shall-be-configured-for-each-device](https://docs.tminus365.com/security/intune/lockout-screen-and-password-settings-shall-be-configured-for-each-device "mention")                                                         | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [encryption-shall-be-required-on-all-devices](https://docs.tminus365.com/security/intune/encryption-shall-be-required-on-all-devices "mention")                                                                                                                   | <mark style="background-color:green;">Low</mark>  | Standard    |
| [windows-hello-for-business-should-be-configured-where-applicable](https://docs.tminus365.com/security/intune/windows-hello-for-business-should-be-configured-where-applicable "mention")                                                                         | <mark style="background-color:green;">Low</mark>  | Standard    |
| [authorized-applications-shall-be-configured-for-single-sign-on](https://docs.tminus365.com/security/azure-ad-entra/authorized-applications-shall-be-configured-for-single-sign-on "mention")                                                                     | <mark style="background-color:green;">Low</mark>  | Standard    |
| [device-use-shall-be-restricted-until-required-applications-are-installed](https://docs.tminus365.com/security/intune/device-use-shall-be-restricted-until-required-applications-are-installed "mention")                                                         | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [devices-and-applications-shall-be-wiped-when-a-user-leaves-the-organization-or-reports-a-lost-stolen](https://docs.tminus365.com/security/intune/devices-and-applications-shall-be-wiped-when-a-user-leaves-the-organization-or-reports-a-lost-stolen "mention") | <mark style="background-color:green;">None</mark> | Standard    |
