> For the complete documentation index, see [llms.txt](https://docs.tminus365.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tminus365.com/security/intune.md).

# Intune

![](/files/97PqX1HJz1XM27qEg5qT)

**Section Purpose:** The security section shows recommend security controls for Teams based on the CIS Controls. Each control contains the following subsections:

* Description
* Policy Definition
* Licensing Considerations&#x20;
* Set Up Instructions
* End-User Impact
* PowerShell Scripts
* Video Tutorials

| Policy                                                                                                                                                                                                                           | End-User Impact                                   | License     |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- | ----------- |
| [Personal Devices should be restricted from enrolling into the MDM solution](/security/intune/personal-devices-should-be-restricted-from-enrolling-into-the-mdm-solution.md)                                                     | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Devices shall be deleted that haven’t checked in for over 30 days](/security/intune/devices-shall-be-deleted-that-havent-checked-in-for-over-30-days.md)                                                                        | <mark style="background-color:green;">Low</mark>  | Standard    |
| [Devices compliance policies shall be configured for every supported device platform](/security/intune/devices-compliance-policies-shall-be-configured-for-every-supported-device-platform.md)                                   | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Noncompliant devices shall be blocked from accessing corporate resources](/security/intune/noncompliant-devices-shall-be-blocked-from-accessing-corporate-resources.md)                                                         | <mark style="background-color:red;">High</mark>   | Azure AD P1 |
| [MFA Shall be required for Intune Enrollment](/security/intune/mfa-shall-be-required-for-intune-enrollment.md)                                                                                                                   | <mark style="color:yellow;">Medium</mark>         | Azure AD P1 |
| [Security Baselines should be configured for Windows Devices](/security/intune/security-baselines-should-be-configured-for-windows-devices.md)                                                                                   | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Windows Update Rings shall be configured for Windows Devices](/security/intune/windows-update-rings-shall-be-configured-for-windows-devices.md)                                                                                 | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Update Policies shall be configured for Apple Devices](/security/intune/update-policies-shall-be-configured-for-apple-devices.md)                                                                                               | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [App Protection policies should be created for mobile devices](/security/intune/app-protection-policies-should-be-created-for-mobile-devices.md)                                                                                 | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Mobile devices shall only be able to access corporate data through approved client apps](/security/intune/mobile-devices-shall-only-be-able-to-access-corporate-data-through-approved-client-apps.md)                           | <mark style="color:yellow;">Medium</mark>         | Azure AD P1 |
| [Lockout screen and password settings shall be configured for each device](/security/intune/lockout-screen-and-password-settings-shall-be-configured-for-each-device.md)                                                         | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Encryption shall be required on all devices](/security/intune/encryption-shall-be-required-on-all-devices.md)                                                                                                                   | <mark style="background-color:green;">Low</mark>  | Standard    |
| [Windows Hello for Business should be configured where applicable](/security/intune/windows-hello-for-business-should-be-configured-where-applicable.md)                                                                         | <mark style="background-color:green;">Low</mark>  | Standard    |
| [Authorized Applications shall be configured for Single Sign-On](/security/azure-ad-entra/authorized-applications-shall-be-configured-for-single-sign-on.md)                                                                     | <mark style="background-color:green;">Low</mark>  | Standard    |
| [Device Use Shall be restricted until required applications are installed](/security/intune/device-use-shall-be-restricted-until-required-applications-are-installed.md)                                                         | <mark style="color:yellow;">Medium</mark>         | Standard    |
| [Devices and Applications shall be wiped when a user leaves the organization or reports a lost/stolen](/security/intune/devices-and-applications-shall-be-wiped-when-a-user-leaves-the-organization-or-reports-a-lost-stolen.md) | <mark style="background-color:green;">None</mark> | Standard    |
