Skip to content
Technical Guides

Cyber Essentials for Microsoft Intune: configuration guide

Use Microsoft Intune configuration, compliance, app protection and update policies to prepare Cyber Essentials evidence across supported platforms.

black and silver asus laptop computer

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

7 min read

Share

Section 01

Cyber Essentials for Microsoft Intune: configuration guide

Intune can be one of the cleanest ways to manage a suitable estate and can help configure devices and collect Cyber Essentials evidence across Windows, macOS, iOS and Android. Compliance policies evaluate supported status signals; configuration profiles, endpoint-security policies and update policies apply settings. Assignment, platform support and observed device state all matter. A baseline name or green compliance badge alone does not prove every scheme control.

Section 02

1. Enrolment scope first

Reconcile All devices with your asset register, identity records and actual sign-in activity. Users may have multiple devices, shared equipment or no assigned device, so inventory count does not simply equal active-user count. Include work BYOD accessing organisational data or services; devices used only for native voice, native text or MFA apps have explicit exceptions. Intune enrolment is a management choice, not a universal scheme requirement.

Section 03

2. Windows - configure and evaluate separately

Review the current Windows security baseline and each available setting before deployment. Use endpoint-security/configuration policies for required firewall, malware and authentication settings. BitLocker, Credential Guard, cloud-delivered protection and stronger password policies can be additional local hardening.

Create and assign compliance policies for supported OS status and relevant posture signals. Microsoft explains that compliance can feed Conditional Access; evaluation does not generally configure a missing control. Check exact Windows edition, release and qualifying extended support, including any Windows 10 ESU arrangement, rather than a blanket Windows 11 22H2 minimum.

Quality-update deferrals, deadlines, restart grace and offline devices together determine installation time. A seven-day deferral is an illustrative planning choice, not proof of meeting the release-based deadline.

Section 04

3. macOS

Use supported macOS configuration profiles for firewall, locking, authentication and software-update settings. Verify available settings for the actual OS and enrolment type; do not assume a built-in macOS Security Baseline exists. FileVault, recovery-key escrow and stealth mode can strengthen the estate but are not universal Cyber Essentials requirements. Use current Apple model/release support evidence rather than macOS 14 as a permanent minimum.

Section 05

4. iOS / iPadOS

Use supported passcode, lock and update settings appropriate to ownership and supervision. Short lock timers, non-simple passcodes and jailbreak blocking can be local hardening. Verify update-policy applicability and actual installation; a restrictions profile does not automatically prove every device patched on time. Support is model/release-specific, not a universal iOS N-1 rule.

Section 06

5. Android Enterprise

Choose fully managed for work-only corporate devices or a personally owned Work Profile where suitable. Verify Intune's current supported enrolment methods and OEM update support. Encryption, Play Protect, integrity checks and managed-app restrictions are useful platform protections; a generic Android 13 minimum does not establish vendor support.

Section 07

6. App Protection Policies (MAM)

App protection can protect supported app data with PIN, transfer restrictions and selective wipe. Platform, app and identity support vary. It does not automatically provide whole-device firewall, software support, patching or malware evidence. BYOD remains in scope when it accesses organisational data or services, including a virtual desktop; MAM-only is not a general device compliance exemption.

Section 08

Scheme baseline and local hardening

NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.

For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.

Section 09

7. Common failure points and evidence

  • Unrecorded BYOD or offline devices: reconcile the complete scope rather than only reporting devices.
  • Policies created but not assigned, conflicts or unsupported settings: compare assignment reports with observed state.
  • Required fixes overdue despite an update ring: inspect installation and restart evidence.
  • Password-only cloud access or legacy routes: check effective authentication, not enrolment alone.

Prepare the scoped device inventory, configuration and compliance exports, update settings and installation records, and app-protection coverage where relevant. Submit evidence appropriate to the assessor's request; no fixed export format guarantees acceptance.

Section 10

What Fig Group checks

Use the readiness check to support preparation. Share relevant device and policy evidence when requested. A read-only Graph integration, specific report ingestion or first-attempt success percentage should only be relied on where the actual service capability and operating records have been verified; no percentage establishes compliance.

Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | Book a CE Plus slot

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group