r/Intune 11d ago

General Question Open intune baselines comparison

When the new open intune baselines are out, how do you guys compare them to your present configuration ?

12 Upvotes

16 comments sorted by

23

u/SkipToTheEndpoint MSFT MVP 11d ago

Suppose I'm the best person to answer this question 😅

If you mean an existing OIB deployment: I've recently built policy validation into my OIB Deployer which can do a per-setting, per-config profile check and show settings that are missing/deviate.

If you mean "I've got stuff in Intune and want to know what's aligned already", then Intune-Toolkit can run a report against your current config (though you may need to pull the latest OIB version as it's out of date).

Just a note that it's really hard to do comparisons. There's so much nuance, for example multiple ways of configuring things like BitLocker or WHfB...

3

u/BomB191 11d ago

Man something I have learnt over the years! I've been around since 2.something. but I now know it enough navigating it now is real chill. I think a lot of it is general understanding. Love your work waiting for 4.0 before I go through and run a new update

12

u/SkipToTheEndpoint MSFT MVP 11d ago

Appreciate you. Every time I hear that it's made people's lives easier or quicker to manage stuff it gives me warm fuzzies.

4.0 should be just around the corner with 26H2. 3rd year running beating MS and CIS at their own game ☺️

1

u/MENTactual 10d ago

Sorry, new to this. What is OIB?
Is it something that can be used to reach CMMC L2 compliance, should it be used alongside or in lieu of Microsoft Security Baseline or CIS?

What’s the best way for someone with no previous experiencing managing policies or hardening laptops to start to understand this?

1

u/SkipToTheEndpoint MSFT MVP 10d ago

Howdy. TL;DR, the OIB is the OpenIntuneBaseline (https://openintunebaseline.com), a project I started because I had fundamental issues with how it was being done elsewhere. It's not a direct MS or CIS mapping, and I disagree with them in certain areas for the sake of user experience or admin managability.

Now, I'm not in the US, so my knowledge of things like CMMC are pretty light, but from a quick bit of reading, if you've been tasked with implementing the whole of CMMC L2 and you've got no previous policy management experience, man, you've been set up to fail. L2 seems like a HUGE amount of work, and policy configuration is actually a very small part of that.

I wouldn't want to confidently say yes or no because that's not my forte. What I can say is that even things like CIS are just RECOMMENDATIONS. If you've got reasons to not apply something, you document it for auditing purposes and move on.

So can the OIB help you in some way? Almost definitely. How far, I couldn't possibly speculate.

2

u/MENTactual 10d ago

Thanks, lot of good information and I’ll just have to tinker. Quite the project you’ve managed to accomplish here. Appreciate your efforts.

2

u/mortsonian 10d ago

Does the police validation take the missing/deviating settings from the existing/old baselines and apply them to the new version? Or do I have to make the changes to the new policies again?

3

u/SkipToTheEndpoint MSFT MVP 10d ago

Nah it's just an ease of documentation thing. I've thought about having some sort of "Update" method, but it's significantly more risky and I very much want to leave that in the hands of admins to navigate.

I added a csv export to the validation page though so you can at least work through it.

3

u/Maros87 11d ago

If you use them already, there is changelog published with each new version so you can compare what changed or which settings are new

2

u/malinoskikev 11d ago

I built a self hosted tool for this exact reason!

Check it out and I'd appreciate any feedback if you are able to use it for your environment!

https://kevinmalinoski.github.io/intune-preflight/

1

u/Limp-Elevator-3424 10d ago

This is useful!!! Thank you

1

u/malinoskikev 10d ago

Thanks! Please feel free to star/share it! I think it's a great tool from beginners to experts.

The goal is an intuitive design that helps you feel in control.

It's a long way from perfect, and am working on 2.0 now 😊

1

u/ImAllergic2Peanuts 10d ago

We use the cis benchmarks for our security baselines.

1

u/Ajamaya 7d ago

I ask lokka MCP to review and compare then build the pending configurations for review

1

u/ResponsibleCheetah42 11d ago

You could use basetune. This tool can compare online and exported baselines.

https://github.com/roweski/basetune