Skip to content

Intune Policy Updates - #14

Merged
aaronparker merged 5 commits into
mainfrom
AutoPilot-Device-Preparation
Aug 18, 2026
Merged

aaronparker merged 5 commits into
mainfrom
AutoPilot-Device-Preparation

Conversation

@asalazar712

Copy link
Copy Markdown
Contributor

Update BitLocker OS recovery key choice value
Change the choiceSettingValue 'value' from 'OS Recovery Key usage set to allowed instead of required. It prevented Bitlocker from activating.

Update Intune Policies
macOS:

Updated the payload for macOS MDE 9.macOS MDE preference

Windows:

Compliance: Removed Defender Compliance settings from the physical PC Compliance Policy, and I separated them into a separate profile. I'm doing this because not everybody's leveraging Defender. In addition to that, I've added a medium risk score for the Defender for endpoint compliance settings.

Configuration: I updated Device Lock and Credential to reference user assignment. I've described it in the description to leverage filters to filter out any personal devices.

WHfB: Configures Windows Hello for Business device settings: enhanced anti-spoofing for facial recognition, PIN complexity (6-char minimum, upper/lowercase required, 24-cycle history), and security device (TPM) requirement. Gave guidance to disable global Windows Hello settings.

Change the choiceSettingValue 'value' from 'OS Recovery Key usage set to allowed instead of required. It prevented Bitlocker from activating.
This change adds new user-scoped Windows compliance and security policies, including Defender for Endpoint, device security, encryption, and Windows Hello for Business, while renaming the existing device-scoped Credential Guard and sign-in settings policies to user-scoped variants. It also updates the macOS MDE preference payload to align with the current Defender settings and documentation.
macOS:

Updated the payload for macOS MDE 9.macOS MDE preference

Windows:

Compliance: Removed Defender Compliance settings from the physical PC Compliance Policy, and I separated them into a separate profile. I'm doing this because not everybody's leveraging Defender. In addition to that, I've added a medium risk score for the Defender for endpoint compliance settings.

Configuration: I updated Device Lock and Credential to reference user assignment. I've described it in the description to leverage filters to filter out any personal devices.

WHfB: Configures Windows Hello for Business device settings: enhanced anti-spoofing for facial recognition, PIN complexity (6-char minimum, upper/lowercase required, 24-cycle history), and security device (TPM) requirement. Gave guidance to disable global Windows Hello settings.
Comment thread .gitignore Outdated

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Check the encoding for this file and update to UTF8 with BOM - I'm assuming this isn't readable due to UTF16 encoding.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Completed.

This commit stops ignoring markdown files in the repository and updates the Windows Hello for Business Device to UTF8 with BOM.
@aaronparker
aaronparker merged commit d79babe into main Aug 18, 2026
3 checks passed
@aaronparker
aaronparker deleted the AutoPilot-Device-Preparation branch August 18, 2026 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants