Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is a review of the MDM/Intune overdue? #27

Open
TechsUK opened this issue Mar 28, 2023 · 9 comments
Open

Is a review of the MDM/Intune overdue? #27

TechsUK opened this issue Mar 28, 2023 · 9 comments
Labels
documentation Improvements or additions to documentation

Comments

@TechsUK
Copy link

TechsUK commented Mar 28, 2023

Windows 11
Do NCSC up to date recommendations align with these 2 year old ones? If yea/nay can you state on readme?
My problem is that I don't know if after apply 2 year old JSON if there are new settings in Endpoint that are unutilised

@TechsUK TechsUK added the documentation Improvements or additions to documentation label Mar 28, 2023
@steve-prentice
Copy link

I'd second this. All the Windows templates are based on Intune "Templates" rather than Intune "Settings Catalog"... a review and migration would be much appreciated so that we know we're implementing something that's up to date and still shown some love.

@petecog
Copy link

petecog commented Apr 26, 2023

another idea might be to liase with MS and publish an NCSC "Security Baselines" (under the endpoint security section). But agreed, a refresh is probably needed.

@doug-fitzmaurice-rowden

This would be great. We've tried to apply some of the Intune templates to Azure VMs and they stick in a "Not applicable" state.

From trying to create a Settings Catalog alternative I can see that lots of the settings have moved or been renamed, but once you find the equivalent the policies will apply successfully.

@steve-prentice
Copy link

I emailed NCSC to ask for some comments and had a one line reply back...

"This guidance is currently being reviewed/updated and a new version will be issued shortly. "

Which, if I'm honest, I felt was a brush off considering these Issue threads in GitHub appear to be abandoned by NCSC at the moment.

@Ironised
Copy link

Ironised commented May 11, 2023

NCSC also need to be aware that while they may publish guidance, other UK gov agencies then treat them as standards.

Leaving these configs to drift for two years is a burden on UK gov suppliers (and presumably much of the public sector too.)

For example, Crown Commerical Service Call Off Schedule 9 Part B - Annex 1 clause 2.2 includes the following text "all Supplier devices are expected to meet the set of security requirements set out in the End User Devices Security Guidance (https://www.ncsc.gov.uk/guidance/enduser-device-security)" which includes links to these config files.

Given CCS are turning guidance into "requirements" and contractual obligations, NCSC need to either actively manage their EUD guidance, or perhaps CCS' expectations of NCSC guidance.

@aps-gilberts
Copy link

aps-gilberts commented May 11, 2023 via email

@koff75
Copy link

koff75 commented Dec 15, 2023

Any scheduled update about this Windows 10/11 configuration file for InTune ?

@steve-prentice
Copy link

Well. in May they said "shortly", so don't hold your breath it seems.

We've given up waiting, the world moves on and NCSC in this space has become less relevant due to their lack of involvement. We've gone with the MS baselines and will work from those.

@humphreysl
Copy link

We're now not far from 2025 and still no update. My organisation is trying to implement some of the baselines stated here but the installation instructions alone are way out of date (a load of DLL errors in PS so can't import them - can't even import them via the Azure Portal). Can we get an update on these so they are fit for purpose in 2024/2025?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

8 participants