Cyber Essentials for Microsoft Intune: configuration guide
Use Microsoft Intune configuration, compliance, app protection and update policies to prepare Cyber Essentials evidence across supported platforms.

Section 01
Cyber Essentials for Microsoft Intune: configuration guide
Intune can be one of the cleanest ways to manage a suitable estate and can help configure devices and collect Cyber Essentials evidence across Windows, macOS, iOS and Android. Compliance policies evaluate supported status signals; configuration profiles, endpoint-security policies and update policies apply settings. Assignment, platform support and observed device state all matter. A baseline name or green compliance badge alone does not prove every scheme control.
Section 02
1. Enrolment scope first
Reconcile All devices with your asset register, identity records and actual sign-in activity. Users may have multiple devices, shared equipment or no assigned device, so inventory count does not simply equal active-user count. Include work BYOD accessing organisational data or services; devices used only for native voice, native text or MFA apps have explicit exceptions. Intune enrolment is a management choice, not a universal scheme requirement.
Section 03
2. Windows - configure and evaluate separately
Review the current Windows security baseline and each available setting before deployment. Use endpoint-security/configuration policies for required firewall, malware and authentication settings. BitLocker, Credential Guard, cloud-delivered protection and stronger password policies can be additional local hardening.
Create and assign compliance policies for supported OS status and relevant posture signals. Microsoft explains that compliance can feed Conditional Access; evaluation does not generally configure a missing control. Check exact Windows edition, release and qualifying extended support, including any Windows 10 ESU arrangement, rather than a blanket Windows 11 22H2 minimum.
Quality-update deferrals, deadlines, restart grace and offline devices together determine installation time. A seven-day deferral is an illustrative planning choice, not proof of meeting the release-based deadline.
Section 04
3. macOS
Use supported macOS configuration profiles for firewall, locking, authentication and software-update settings. Verify available settings for the actual OS and enrolment type; do not assume a built-in macOS Security Baseline exists. FileVault, recovery-key escrow and stealth mode can strengthen the estate but are not universal Cyber Essentials requirements. Use current Apple model/release support evidence rather than macOS 14 as a permanent minimum.
Section 05
4. iOS / iPadOS
Use supported passcode, lock and update settings appropriate to ownership and supervision. Short lock timers, non-simple passcodes and jailbreak blocking can be local hardening. Verify update-policy applicability and actual installation; a restrictions profile does not automatically prove every device patched on time. Support is model/release-specific, not a universal iOS N-1 rule.
Section 06
5. Android Enterprise
Choose fully managed for work-only corporate devices or a personally owned Work Profile where suitable. Verify Intune's current supported enrolment methods and OEM update support. Encryption, Play Protect, integrity checks and managed-app restrictions are useful platform protections; a generic Android 13 minimum does not establish vendor support.
Section 07
6. App Protection Policies (MAM)
App protection can protect supported app data with PIN, transfer restrictions and selective wipe. Platform, app and identity support vary. It does not automatically provide whole-device firewall, software support, patching or malware evidence. BYOD remains in scope when it accesses organisational data or services, including a virtual desktop; MAM-only is not a general device compliance exemption.
Section 08
Scheme baseline and local hardening
NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.
For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.
Section 09
7. Common failure points and evidence
- Unrecorded BYOD or offline devices: reconcile the complete scope rather than only reporting devices.
- Policies created but not assigned, conflicts or unsupported settings: compare assignment reports with observed state.
- Required fixes overdue despite an update ring: inspect installation and restart evidence.
- Password-only cloud access or legacy routes: check effective authentication, not enrolment alone.
Prepare the scoped device inventory, configuration and compliance exports, update settings and installation records, and app-protection coverage where relevant. Submit evidence appropriate to the assessor's request; no fixed export format guarantees acceptance.
Section 10
What Fig Group checks
Use the readiness check to support preparation. Share relevant device and policy evidence when requested. A read-only Graph integration, specific report ingestion or first-attempt success percentage should only be relied on where the actual service capability and operating records have been verified; no percentage establishes compliance.
Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | Book a CE Plus slot
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for Microsoft Azure: configuration guide
Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.
Read articleTechnical Guides
Cyber Essentials for Jamf Pro: Mac configuration guide
Prepare Jamf Pro Mac configuration and evidence for Cyber Essentials: scope coverage, firewall, supported software, malware protection and optional FileVault hardening.
Read articleTechnical Guides
Malware Protection for Cyber Essentials: What Qualifies and What Does Not
Malware protection looks simple - "we have antivirus" - but the question set asks specifically about configuration, coverage, and fallback approaches. This guide covers what qualifies under v3.3, including the application allow-listing alternative and the most common mistakes during assessment.
Read article

