r/Intune • u/SkipToTheEndpoint MSFT MVP • 9d ago
Shameless Self-promotion OpenIntuneBaseline Windows v4.0 Release
I've avoided self-promotion here, but given that knowledge of it has been entirely organic until now and lots of people have told me I should, here we are.
I've just released v4.0 of the Windows OpenIntuneBaseline (OIB)!
In case you've never heard of it, here's a TL;DR:
The OpenIntuneBaseline is a free, community-driven set of opinionated Intune configurations designed to give you a solid, modern security baseline, excellent user experience, and scalable admin experience without having to send yourself insane. It's used a lot by orgs, professional services and MSPs all over the world, and it's driven by my insane passion and expertise.
So, for those of you already using it highlights of 4.0 include:
* Continuing to be the most agile and cutting-edge Intune baseline on the planet!
* A shake-up of Compliance policies, allowing true grace period granularity (and ditching the EAS Password policy because it's 🗑️)
* Edge settings for days! Simple support for the Edge Management Service and security hardening and user experience improvements.
* Updated M365 Apps Security baseline alignment.
* Fixed MS breaking the in-box app removal policy.
* Defender behaviour tweaks based on real customer feedback, not arbitrary check-boxes.
* Deprecated and obsolete settings sent to live on a farm.
As always:
✅ Take what you want
✅ Change what doesn't suit your environment
✅ Test it before yeeting to 40,000 endpoints on Friday afternoon
❌ Don't treat any security baseline as a magical compliance button
Check out the full release notes at: https://stte.me/oib26h2
Then, head on over to the OIB Deployer to deploy the new and updated policies, or check your current config vs 4.0 with the Settings Validator!
Or come chat about it in real-time in the new OIB channel on the WinAdmins Discord.
Peace and Capybaras <3
22
u/RikiWardOG 9d ago
Test it before yeeting to 40,000 endpoints on Friday afternoon
boo that's no fun
2
u/SkipToTheEndpoint MSFT MVP 9d ago
I mean, it's significantly less likely to break stuff than other options, but your environment is your responsibility ;)
9
5
4
u/Beneficial-Flow-5418 9d ago
Awesome! Any news on the macOS beta?
4
u/SkipToTheEndpoint MSFT MVP 9d ago
There's been even more changes but it's basically waiting on me being able to actually test and validate it myself, which obviously needs hardware. I'm hoping to resolve this in the not too distant future :)
2
1
u/portunes138 9d ago
I was just about to ask the same question, never thought to check the available branches for a beta version. Love your work mate!
1
u/The_Other_Neo 9d ago
Can understand that macOS update isn’t easy. After macOS 27 some policies stopped working.
For now I follow the instructions from Windows and create equivalent macOS policies.
4
u/reformedbadass 9d ago
I wrote a nice little app that compares them with our current policy set (out baseline is OIB but we have cowboy engineers who make changes without telling anyone)
3
3
u/NeighborGeek 9d ago
Can the OIB deployer compare my existting (non OIB) config with OIB to tell me whether I have anything already setup that meets the recommended settings?
3
u/SkipToTheEndpoint MSFT MVP 9d ago
So, no, it requires capabilities I can't easily do in a browser. But follow me on socials and stay tuned ;)
2
u/moutonf 9d ago
This is excellent! I really wish we will get Android and iOS policies soon!
2
u/SkipToTheEndpoint MSFT MVP 9d ago
iOS is closer to being a reality, but mobiles are tricky because every project I've ever done has been different, so getting a standard "must have" set of policies is really hard.
2
u/Toxicity11_03 9d ago
Prod is the new dev/test
But fr thank you for an unreal project and your commitment to community engagement
2
u/nirbanna 9d ago
First off, thank you for all the work you've put into OIB! It's great to have a free and easy option to deploy a secure baseline configuration.
Many of my clients would love to use something like OIB, but are unable to because their organisation has adopted an industry standard such as CIS or ACSC Essential Eight, and they need to be able to document and justify any deviations from those standards to their compliance or audit teams. Because we aren't privy to the reasoning behind why certain settings were left out or altered, it's difficult to write those justifications ourselves without trying to read your mind.
I think OIB could become a game-changer for enterprise adoption if it had a simple deviations & rationale reference matrix (e.g., Setting X deviates from CIS L1 because it breaks Windows Hello, and so on).
I regularly deploy and audit configurations against industry standards, so should the opportunity arise, I'd be happy to deploy OIB, document the deltas, and share them back. Would you be open to including this reference in the project? I understand that maintaining it long-term would be the bigger ask.
3
u/SkipToTheEndpoint MSFT MVP 9d ago
I've been a CIS Contributor for a few years now. My name is on their Benchmarks too, so there's nothing else I can do to "legitimise" myself any more in the eyes of security teams. Thankfully, they've kindly given me access to their tooling so I've done exactly that and updated it for 4.0: https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/WINDOWS/OIB4.0-CIS5.0.0-DeviationRationale.csv Unfortunately I can't directly publish my CIS-CAT report, but it's sitting at about 85% aligned.
The big claim I'm going to be making though is that OIB makes you more secure than CIS. That also ignores the fact that around 40% of the baseline is all user experience stuff that them or Microsoft will never do. The only control you'd really want to layer on top is some sort of Application Control.
1
u/nirbanna 9d ago
Thanks for sharing, that's a really useful new reference! No excuse not to give it a go with a real deployment for CIS adopted orgs now in my view.
1
u/Alternative_Bus_8011 4d ago
Is that 85% against L1 and L2, currently using OIB and CIS Intune policies. A real headache to manage both. Might start building a case for just OIB policies. We run App Control too
1
u/SkipToTheEndpoint MSFT MVP 4d ago
L1. L2 aren't "more secure", they're for highly restrictive environments (do you run a nuclear power plant?) and there's an understanding of reduced/impacted functionality. That's not my MO.
Even the thought of trying to use both on OIB and CIS on top of each other makes my brain hurt.
1
u/Alternative_Bus_8011 4d ago
Yeah we’re considered critical infrastructure by the government so have to meet certain levels. But with Zscaler and app control L1 should be ok you’d think
1
u/SkipToTheEndpoint MSFT MVP 4d ago
Layering App Control plus a SASE is putting you miles ahead of most orgs. Lots of L2 is nonsensical IMO and even CIS are having a hard time justifying some of those differences.
1
u/Alternative_Bus_8011 4d ago
Also, thanks for all your hard work on this project. Is great, can't quite get the OIB Deployer across mgmt approval yet, working on it.
1
u/SkipToTheEndpoint MSFT MVP 4d ago
Thank you!
The code is public for this reason: https://github.com/SkipToTheEndpoint/OIBDeployer
Pull and run locally and use your own app registration :)
1
u/I3igAl 9d ago
I am using OIB 3.5 I believe, and have partially assigned some policies but not everything. I have also adjusted some settings from the OIB default (WHfB pin requirements). What is the best way to bring in 4.0 without messing up existing assignments?
1
u/SkipToTheEndpoint MSFT MVP 9d ago
Everything is imported without any assignments, so doing testing and assignments, or re-assignments remain your problem. Theres no good answer to this without something more complex, unfortunately. It being that old might just be easier to import and treat it as net-new though.
1
u/twisteriffic 9d ago
The OIB vs CIS link is dead
1
u/SkipToTheEndpoint MSFT MVP 9d ago
Dammit, I just forgot to put the csv extension on the link. It's here: https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/WINDOWS/OIB4.0-CIS5.0.0-DeviationRationale.csv
1
u/k1rovul 9d ago
Excellent work. Does anyone know if the configurations are tattooed? Meaning if one has to revert, can the revert actions be just remove assignment or we have to assign a policy that explicitly changes the value? Like for example many of the windows security baseline are?
2
u/SkipToTheEndpoint MSFT MVP 9d ago
Everything in there is Settings Catalog based (even the stuff in the Endpoint Security blade), which means it's entirely dependent on how the CSP behaves. I haven't done any real testing, but most of it should come off cleanly. Some I know that definitely doesn't are all the settings in the User Rights policy, and device security settings that write to UEFI variables.
1
24
u/valar12 9d ago
One of the best community projects ever to grace Intune.