Microsoft Defender for Endpoint
Endpoint protection

Increase compliance with the Microsoft Defender for Endpoint security baseline

In brief

The page date and custom metadata were updated, and wording around the Intune security baselines FAQ link was refined.

What Defender admins need to know

No administrator action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Increase compliance with the Microsoft Defender for Endpoint security baseline

Security baselines ensure that security features are configured according to guidance from both security experts and expert Windows system administrators. When deployed, the Defender for Endpoint security baseline sets Defender for Endpoint security controls to provide optimal protection.

To understand security baselines and how they're assigned onin Intune using configuration profiles, see Security baselines FAQ.

Before you can deploy and track compliance to security baselines:

Compare the Microsoft Defender for Endpoint and the Windows Intune security baselines

The Windows Intune security baseline provides a comprehensive set of recommended settings needed to securely configure devices running Windows, including browser settings, PowerShell settings, and settings for some security features like Microsoft Defender Antivirus. In contrast, the Defender for Endpoint baseline provides settings that optimize all the security controls in the Defender for Endpoint stack, including settings for endpoint detection and response (EDR) and settings also found in the Windows Intune security baseline. For more information about eachthe Windows Intune security baseline and the Defender for Endpoint baseline, see: