Intune Settings catalog¶
The kit's Intune route: the baseline in Settings catalog terms, with
no scripts on the endpoints. Settings catalog
settings are backed by Microsoft's
Policy CSPs;
each row names the CSP and links its Microsoft page. Find the setting in
the catalog by its name, or set it as a custom OMA-URI:
./Device/Vendor/MSFT/Policy/Config/<CSP>. For domain-joined hosts, the
same settings by Group Policy are on Group Policy paths.
Note
Built from Microsoft's CSP documentation, not yet field-tested in a
tenant (#46). Pilot
on a small device group and check the result with
Test-LoggingBaseline.ps1.
Things to know before you start:
- The catalog only covers part of the baseline. Audit policy,
command-line capture, Windows PowerShell logging, SMB auditing and three
log sizes have a CSP. The second table lists what doesn't, and why.
Test-LoggingBaseline.ps1reports those rows as FAIL on a device managed only through the catalog; that's expected, and runningEnable-LoggingBaseline.ps1once on the device covers them. - CSPs aren't role-aware. Rows marked (DC) only matter on domain controllers: a Settings catalog profile applies to every device it's assigned to, so leave those rows out of profiles for other devices.
- A policy sets a log size outright. The kit only ever raises sizes; a size policy also lowers a log that was bigger. Set the larger value if your hosts already have one.
- SMB auditing needs Windows 11 24H2 (build 26100.3613) or later, or Windows Server 2025, per Microsoft's LanmanServer and LanmanWorkstation CSP pages; older builds don't have those settings.
- Mind the Tier column. Leave HighVolume rows out unless you apply that tier (see Baselines).
Settings with a CSP¶
| Setting | Type | Tier | CSP | Value | Microsoft doc |
|---|---|---|---|---|---|
| Credential Validation | Audit | Core | Audit/AccountLogon_AuditCredentialValidation |
3 (Success+Failure) | Audit |
| Kerberos Authentication Service (DC) | Audit | Core | Audit/AccountLogon_AuditKerberosAuthenticationService |
3 (Success+Failure) | Audit |
| Kerberos Service Ticket Operations (DC) | Audit | Core | Audit/AccountLogon_AuditKerberosServiceTicketOperations |
3 (Success+Failure) | Audit |
| Computer Account Management (DC) | Audit | Core | Audit/AccountManagement_AuditComputerAccountManagement |
3 (Success+Failure) | Audit |
| Distribution Group Management (DC) | Audit | Core | Audit/AccountManagement_AuditDistributionGroupManagement |
3 (Success+Failure) | Audit |
| Other Account Management Events | Audit | Core | Audit/AccountManagement_AuditOtherAccountManagementEvents |
3 (Success+Failure) | Audit |
| Security Group Management | Audit | Core | Audit/AccountManagement_AuditSecurityGroupManagement |
3 (Success+Failure) | Audit |
| User Account Management | Audit | Core | Audit/AccountManagement_AuditUserAccountManagement |
3 (Success+Failure) | Audit |
| Plug and Play | Audit | Core | Audit/DetailedTracking_AuditPNPActivity |
3 (Success+Failure) | Audit |
| Process Creation | Audit | HighVolume | Audit/DetailedTracking_AuditProcessCreation |
3 (Success+Failure) | Audit |
| RPC Events | Audit | Core | Audit/DetailedTracking_AuditRPCEvents |
3 (Success+Failure) | Audit |
| Directory Service Access (DC) | Audit | Core | Audit/DSAccess_AuditDirectoryServiceAccess |
3 (Success+Failure) | Audit |
| Directory Service Changes (DC) | Audit | Core | Audit/DSAccess_AuditDirectoryServiceChanges |
3 (Success+Failure) | Audit |
| Account Lockout | Audit | Core | Audit/AccountLogonLogoff_AuditAccountLockout |
3 (Success+Failure) | Audit |
| Logoff | Audit | Core | Audit/AccountLogonLogoff_AuditLogoff |
3 (Success+Failure) | Audit |
| Logon | Audit | Core | Audit/AccountLogonLogoff_AuditLogon |
3 (Success+Failure) | Audit |
| Other Logon/Logoff Events | Audit | Core | Audit/AccountLogonLogoff_AuditOtherLogonLogoffEvents |
3 (Success+Failure) | Audit |
| Special Logon | Audit | Core | Audit/AccountLogonLogoff_AuditSpecialLogon |
3 (Success+Failure) | Audit |
| Certification Services | Audit | Core | Audit/ObjectAccess_AuditCertificationServices |
3 (Success+Failure) | Audit |
| File Share | Audit | Core | Audit/ObjectAccess_AuditFileShare |
3 (Success+Failure) | Audit |
| Filtering Platform Connection | Audit | HighVolume | Audit/ObjectAccess_AuditFilteringPlatformConnection |
3 (Success+Failure) | Audit |
| Other Object Access Events | Audit | Core | Audit/ObjectAccess_AuditOtherObjectAccessEvents |
3 (Success+Failure) | Audit |
| Removable Storage | Audit | Core | Audit/ObjectAccess_AuditRemovableStorage |
3 (Success+Failure) | Audit |
| SAM | Audit | Core | Audit/ObjectAccess_AuditSAM |
3 (Success+Failure) | Audit |
| Audit Policy Change | Audit | Core | Audit/PolicyChange_AuditPolicyChange |
3 (Success+Failure) | Audit |
| Authentication Policy Change | Audit | Core | Audit/PolicyChange_AuditAuthenticationPolicyChange |
3 (Success+Failure) | Audit |
| Other Policy Change Events | Audit | Core | Audit/PolicyChange_AuditOtherPolicyChangeEvents |
3 (Success+Failure) | Audit |
| Sensitive Privilege Use | Audit | HighVolume | Audit/PrivilegeUse_AuditSensitivePrivilegeUse |
3 (Success+Failure) | Audit |
| IPsec Driver | Audit | HighVolume | Audit/System_AuditIPsecDriver |
3 (Success+Failure) | Audit |
| Security State Change | Audit | Core | Audit/System_AuditSecurityStateChange |
3 (Success+Failure) | Audit |
| Security System Extension | Audit | Core | Audit/System_AuditSecuritySystemExtension |
3 (Success+Failure) | Audit |
| System Integrity | Audit | Core | Audit/System_AuditSystemIntegrity |
3 (Success+Failure) | Audit |
| Other System Events | Audit | Core | Audit/System_AuditOtherSystemEvents |
2 (Failure) | Audit |
| CmdLineAudit | Registry | HighVolume | ADMX_AuditSettings/IncludeCmdLine |
Enabled | ADMX_AuditSettings |
| ScriptBlock64 | Registry | HighVolume | WindowsPowerShell/TurnOnPowerShellScriptBlockLogging |
Enabled | WindowsPowerShell |
| ModuleLogging64 | Registry | HighVolume | ADMX_PowerShellExecutionPolicy/EnableModuleLogging |
Enabled | ADMX_PowerShellExecutionPolicy |
| ModuleNames64 | Registry | HighVolume | ADMX_PowerShellExecutionPolicy/EnableModuleLogging |
Module names: * | ADMX_PowerShellExecutionPolicy |
| NtlmInboundAudit | Registry | Core | LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic |
2 (enable auditing for all accounts) | LocalPoliciesSecurityOptions |
| ForceSubcategoryAudit | Registry | Core | LocalPoliciesSecurityOptions/Audit_ForceAuditPolicySubcategorySettingsToOverrideAuditPolicyCategorySettings |
1 (Enabled; Windows 11 22H2 with KB5053657, 24H2 and later) | LocalPoliciesSecurityOptions |
| AuditClientDoesNotSupportEncryption | SMB audit | Core | LanmanServer/AuditClientDoesNotSupportEncryption |
1 (Enabled) | LanmanServer |
| AuditClientDoesNotSupportSigning | SMB audit | Core | LanmanServer/AuditClientDoesNotSupportSigning |
1 (Enabled) | LanmanServer |
| AuditServerDoesNotSupportEncryption | SMB audit | Core | LanmanWorkstation/AuditServerDoesNotSupportEncryption |
1 (Enabled) | LanmanWorkstation |
| AuditServerDoesNotSupportSigning | SMB audit | Core | LanmanWorkstation/AuditServerDoesNotSupportSigning |
1 (Enabled) | LanmanWorkstation |
| AuditInsecureGuestLogon | SMB audit | Core | LanmanWorkstation/AuditInsecureGuestLogon |
1 (Enabled) | LanmanWorkstation |
| ServerAuditInsecureGuestLogon | SMB audit | Core | LanmanServer/AuditInsecureGuestLogon |
1 (Enabled) | LanmanServer |
| Security | Log size | Core | EventLogService/SpecifyMaximumFileSizeSecurityLog |
Enabled, 1048576 KB | EventLogService |
| System | Log size | Core | EventLogService/SpecifyMaximumFileSizeSystemLog |
Enabled, 131072 KB | EventLogService |
| Application | Log size | Core | EventLogService/SpecifyMaximumFileSizeApplicationLog |
Enabled, 131072 KB | EventLogService |
Settings without a CSP¶
Intune can't set these through the Settings catalog. Where they matter,
run Enable-LoggingBaseline.ps1 on the device (or use Group Policy on
domain-joined hosts, see Group Policy paths).
| Setting | Type | Why |
|---|---|---|
| ScriptBlock32 | Registry | The 32-bit (WOW64) copy of the script block policy has no CSP of its own. |
| ModuleLogging32 | Registry | The 32-bit (WOW64) copy of the module logging policy has no CSP of its own. |
| ModuleNames32 | Registry | The 32-bit (WOW64) copy of the module list has no CSP of its own. |
| PS7ScriptBlock64 | Registry | No built-in CSP for PowerShell 7 policy. Importing its ADMX as a custom template may be blocked by the registry locations Intune allows for imported ADMX. |
| PS7ScriptBlock32 | Registry | No built-in CSP for PowerShell 7 policy (32-bit copy). |
| PS7ModuleLogging64 | Registry | No built-in CSP for PowerShell 7 policy. Importing its ADMX as a custom template may be blocked by the registry locations Intune allows for imported ADMX. |
| PS7ModuleLogging32 | Registry | No built-in CSP for PowerShell 7 policy (32-bit copy). |
| NtlmOutboundAudit | Registry | A CSP exists (LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers), but Microsoft lists its value 1 as "Deny all domain accounts", not the registry's "Audit all". Setting 1 through the CSP could block NTLM, so don't set it in Intune; Group Policy or Enable-LoggingBaseline.ps1 sets it correctly. |
| NtlmDomainAudit (DC) | Registry | No CSP. Domain controllers only; set it by GPO on the DCs. |
| Microsoft-Windows-PowerShell/Operational | Log | No CSP for this log's size. |
| Windows PowerShell | Log | No CSP for this log's size. |
| PowerShellCore/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-Windows Defender/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-Bits-Client/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-Windows Firewall With Advanced Security/Firewall | Log | No CSP for this log's size. |
| Microsoft-Windows-NTLM/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-Security-Mitigations/KernelMode | Log | No CSP for this log's size. |
| Microsoft-Windows-Security-Mitigations/UserMode | Log | No CSP for this log's size. |
| Microsoft-Windows-PrintService/Admin | Log | No CSP for this log's size. |
| Microsoft-Windows-PrintService/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-SmbClient/Security | Log | No CSP for this log's size. |
| Microsoft-Windows-AppLocker/EXE and DLL | Log | No CSP for this log's size. |
| Microsoft-Windows-AppLocker/MSI and Script | Log | No CSP for this log's size. |
| Microsoft-Windows-AppLocker/Packaged app-Deployment | Log | No CSP for this log's size. |
| Microsoft-Windows-AppLocker/Packaged app-Execution | Log | No CSP for this log's size. |
| Microsoft-Windows-CodeIntegrity/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-Diagnosis-Scripted/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-DriverFrameworks-UserMode/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-WMI-Activity/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-TerminalServices-LocalSessionManager/Operational | Log | No CSP for this log's size. |
| Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-TaskScheduler/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-SMBServer/Audit | Log | No CSP for this log's size. |
| Microsoft-Windows-SmbClient/Audit | Log | No CSP for this log's size. |
| Microsoft-Windows-SMBServer/Security | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-SMBServer/Operational | Log | No CSP for this log's size or enablement. |
| Microsoft-Windows-Crypto-DPAPI/Debug | Log | No CSP for this log's size or enablement. |
| AdcsAuditFilter | Registry | No CSP, and it needs a CertSvc restart: set it on the CA in a change window (Enable-LoggingBaseline.ps1 there). |