Repository navigation
Intune Policy Updates - #14
Merged
Merged
Conversation
Change the choiceSettingValue 'value' from 'OS Recovery Key usage set to allowed instead of required. It prevented Bitlocker from activating.
This change adds new user-scoped Windows compliance and security policies, including Defender for Endpoint, device security, encryption, and Windows Hello for Business, while renaming the existing device-scoped Credential Guard and sign-in settings policies to user-scoped variants. It also updates the macOS MDE preference payload to align with the current Defender settings and documentation.
This reverts commit 2769a62.
macOS: Updated the payload for macOS MDE 9.macOS MDE preference Windows: Compliance: Removed Defender Compliance settings from the physical PC Compliance Policy, and I separated them into a separate profile. I'm doing this because not everybody's leveraging Defender. In addition to that, I've added a medium risk score for the Defender for endpoint compliance settings. Configuration: I updated Device Lock and Credential to reference user assignment. I've described it in the description to leverage filters to filter out any personal devices. WHfB: Configures Windows Hello for Business device settings: enhanced anti-spoofing for facial recognition, PIN complexity (6-char minimum, upper/lowercase required, 24-cycle history), and security device (TPM) requirement. Gave guidance to disable global Windows Hello settings.
aaronparker
requested changes
Aug 14, 2026
Collaborator
There was a problem hiding this comment.
Check the encoding for this file and update to UTF8 with BOM - I'm assuming this isn't readable due to UTF16 encoding.
This commit stops ignoring markdown files in the repository and updates the Windows Hello for Business Device to UTF8 with BOM.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update BitLocker OS recovery key choice value
Change the choiceSettingValue 'value' from 'OS Recovery Key usage set to allowed instead of required. It prevented Bitlocker from activating.
Update Intune Policies
macOS:
Updated the payload for macOS MDE 9.macOS MDE preference
Windows:
Compliance: Removed Defender Compliance settings from the physical PC Compliance Policy, and I separated them into a separate profile. I'm doing this because not everybody's leveraging Defender. In addition to that, I've added a medium risk score for the Defender for endpoint compliance settings.
Configuration: I updated Device Lock and Credential to reference user assignment. I've described it in the description to leverage filters to filter out any personal devices.
WHfB: Configures Windows Hello for Business device settings: enhanced anti-spoofing for facial recognition, PIN complexity (6-char minimum, upper/lowercase required, 24-cycle history), and security device (TPM) requirement. Gave guidance to disable global Windows Hello settings.