github SkipToTheEndpoint/OpenIntuneBaseline windows-v3.5

2 days ago

Windows v3.5 - 2025-02-20 - 24H2 Baseline Edition (Mostly)

Added

Settings Catalog

Win - OIB - SC - Device Security - D - Windows Package Manager - v3.5

  • Added configuration that will be being added to the CIS Benchmark, as well as some additional, non-impacting restrictions to the Desktop App Installer (winget):
    • Enable App Installer Experimental Features - Disabled
    • Enable App Installer Hash Override - Disabled
    • Enable App Installer Local Manifest Files - Disabled
    • Enable App Installer ms-appinstaller protocol - Disabled
    • Enable App Installer Settings - Disabled

Note

If you disable the App Installer completely by setting either "Enable App Installer" or "Enable App Installer Microsoft Store Source" to "Disabled", it will break delivery of Store apps from Intune!
So don't do that :)

Changed/Updated

Settings Catalog

Win - OIB - SC - Defender Antivirus - D - Additional Configuration

Win - OIB - SC - Device Security - D - Security Hardening

Win - OIB - SC - Device Security - D - User Rights

  • Removed S-1-2-0 (Local) from "Deny Remote Desktop Services Log On" as this breaks Windows 365 access. Resolves #69

Win - OIB - SC - Device Security - U - Device Guard, Credential Guard and HVCI

  • Added the following setting from the 24H2 Baseline:

Win - OIB - SC - Microsoft Office - U - Config and Experience

  • Added a recently added setting to make files clicked in Teams open in the desktop apps rather than in SPO:
    • File links open preference default selection as Desktop App (User) - Enabled
  • Added a setting to remove some options from the save locations available. The tooltip is confusing but 137 restricts OneDrive Personal, SharePoint OnPrem and (most importantly) Third-party Services (e.g Box, Dropbox, Egnyte, ShareFile) from the "Add a place" in the Save As menu.
    • Hide Microsoft cloud-based file locations in the Backstage view (User) - 137

Win - OIB - SC - Windows Hello for Business - D - Cloud Kerberos Trust - v3.5

  • Added "Cloud Kerberos Ticket Retrieval Enabled" set to Enabled.

Don't miss a new OpenIntuneBaseline release

NewReleases is sending notifications on new releases.