Skip to content

Intune Settings catalog

The kit's Intune route: the baseline in Settings catalog terms, with no scripts on the endpoints. Settings catalog settings are backed by Microsoft's Policy CSPs; each row names the CSP and links its Microsoft page. Find the setting in the catalog by its name, or set it as a custom OMA-URI: ./Device/Vendor/MSFT/Policy/Config/<CSP>. For domain-joined hosts, the same settings by Group Policy are on Group Policy paths.

Note

Built from Microsoft's CSP documentation, not yet field-tested in a tenant (#46). Pilot on a small device group and check the result with Test-LoggingBaseline.ps1.

Things to know before you start:

  • The catalog only covers part of the baseline. Audit policy, command-line capture, Windows PowerShell logging, SMB auditing and three log sizes have a CSP. The second table lists what doesn't, and why. Test-LoggingBaseline.ps1 reports those rows as FAIL on a device managed only through the catalog; that's expected, and running Enable-LoggingBaseline.ps1 once on the device covers them.
  • CSPs aren't role-aware. Rows marked (DC) only matter on domain controllers: a Settings catalog profile applies to every device it's assigned to, so leave those rows out of profiles for other devices.
  • A policy sets a log size outright. The kit only ever raises sizes; a size policy also lowers a log that was bigger. Set the larger value if your hosts already have one.
  • SMB auditing needs Windows 11 24H2 (build 26100.3613) or later, or Windows Server 2025, per Microsoft's LanmanServer and LanmanWorkstation CSP pages; older builds don't have those settings.
  • Mind the Tier column. Leave HighVolume rows out unless you apply that tier (see Baselines).

Settings with a CSP

Setting Type Tier CSP Value Microsoft doc
Credential Validation Audit Core Audit/AccountLogon_AuditCredentialValidation 3 (Success+Failure) Audit
Kerberos Authentication Service (DC) Audit Core Audit/AccountLogon_AuditKerberosAuthenticationService 3 (Success+Failure) Audit
Kerberos Service Ticket Operations (DC) Audit Core Audit/AccountLogon_AuditKerberosServiceTicketOperations 3 (Success+Failure) Audit
Computer Account Management (DC) Audit Core Audit/AccountManagement_AuditComputerAccountManagement 3 (Success+Failure) Audit
Distribution Group Management (DC) Audit Core Audit/AccountManagement_AuditDistributionGroupManagement 3 (Success+Failure) Audit
Other Account Management Events Audit Core Audit/AccountManagement_AuditOtherAccountManagementEvents 3 (Success+Failure) Audit
Security Group Management Audit Core Audit/AccountManagement_AuditSecurityGroupManagement 3 (Success+Failure) Audit
User Account Management Audit Core Audit/AccountManagement_AuditUserAccountManagement 3 (Success+Failure) Audit
Plug and Play Audit Core Audit/DetailedTracking_AuditPNPActivity 3 (Success+Failure) Audit
Process Creation Audit HighVolume Audit/DetailedTracking_AuditProcessCreation 3 (Success+Failure) Audit
RPC Events Audit Core Audit/DetailedTracking_AuditRPCEvents 3 (Success+Failure) Audit
Directory Service Access (DC) Audit Core Audit/DSAccess_AuditDirectoryServiceAccess 3 (Success+Failure) Audit
Directory Service Changes (DC) Audit Core Audit/DSAccess_AuditDirectoryServiceChanges 3 (Success+Failure) Audit
Account Lockout Audit Core Audit/AccountLogonLogoff_AuditAccountLockout 3 (Success+Failure) Audit
Logoff Audit Core Audit/AccountLogonLogoff_AuditLogoff 3 (Success+Failure) Audit
Logon Audit Core Audit/AccountLogonLogoff_AuditLogon 3 (Success+Failure) Audit
Other Logon/Logoff Events Audit Core Audit/AccountLogonLogoff_AuditOtherLogonLogoffEvents 3 (Success+Failure) Audit
Special Logon Audit Core Audit/AccountLogonLogoff_AuditSpecialLogon 3 (Success+Failure) Audit
Certification Services Audit Core Audit/ObjectAccess_AuditCertificationServices 3 (Success+Failure) Audit
File Share Audit Core Audit/ObjectAccess_AuditFileShare 3 (Success+Failure) Audit
Filtering Platform Connection Audit HighVolume Audit/ObjectAccess_AuditFilteringPlatformConnection 3 (Success+Failure) Audit
Other Object Access Events Audit Core Audit/ObjectAccess_AuditOtherObjectAccessEvents 3 (Success+Failure) Audit
Removable Storage Audit Core Audit/ObjectAccess_AuditRemovableStorage 3 (Success+Failure) Audit
SAM Audit Core Audit/ObjectAccess_AuditSAM 3 (Success+Failure) Audit
Audit Policy Change Audit Core Audit/PolicyChange_AuditPolicyChange 3 (Success+Failure) Audit
Authentication Policy Change Audit Core Audit/PolicyChange_AuditAuthenticationPolicyChange 3 (Success+Failure) Audit
Other Policy Change Events Audit Core Audit/PolicyChange_AuditOtherPolicyChangeEvents 3 (Success+Failure) Audit
Sensitive Privilege Use Audit HighVolume Audit/PrivilegeUse_AuditSensitivePrivilegeUse 3 (Success+Failure) Audit
IPsec Driver Audit HighVolume Audit/System_AuditIPsecDriver 3 (Success+Failure) Audit
Security State Change Audit Core Audit/System_AuditSecurityStateChange 3 (Success+Failure) Audit
Security System Extension Audit Core Audit/System_AuditSecuritySystemExtension 3 (Success+Failure) Audit
System Integrity Audit Core Audit/System_AuditSystemIntegrity 3 (Success+Failure) Audit
Other System Events Audit Core Audit/System_AuditOtherSystemEvents 2 (Failure) Audit
CmdLineAudit Registry HighVolume ADMX_AuditSettings/IncludeCmdLine Enabled ADMX_AuditSettings
ScriptBlock64 Registry HighVolume WindowsPowerShell/TurnOnPowerShellScriptBlockLogging Enabled WindowsPowerShell
ModuleLogging64 Registry HighVolume ADMX_PowerShellExecutionPolicy/EnableModuleLogging Enabled ADMX_PowerShellExecutionPolicy
ModuleNames64 Registry HighVolume ADMX_PowerShellExecutionPolicy/EnableModuleLogging Module names: * ADMX_PowerShellExecutionPolicy
NtlmInboundAudit Registry Core LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic 2 (enable auditing for all accounts) LocalPoliciesSecurityOptions
ForceSubcategoryAudit Registry Core LocalPoliciesSecurityOptions/Audit_ForceAuditPolicySubcategorySettingsToOverrideAuditPolicyCategorySettings 1 (Enabled; Windows 11 22H2 with KB5053657, 24H2 and later) LocalPoliciesSecurityOptions
AuditClientDoesNotSupportEncryption SMB audit Core LanmanServer/AuditClientDoesNotSupportEncryption 1 (Enabled) LanmanServer
AuditClientDoesNotSupportSigning SMB audit Core LanmanServer/AuditClientDoesNotSupportSigning 1 (Enabled) LanmanServer
AuditServerDoesNotSupportEncryption SMB audit Core LanmanWorkstation/AuditServerDoesNotSupportEncryption 1 (Enabled) LanmanWorkstation
AuditServerDoesNotSupportSigning SMB audit Core LanmanWorkstation/AuditServerDoesNotSupportSigning 1 (Enabled) LanmanWorkstation
AuditInsecureGuestLogon SMB audit Core LanmanWorkstation/AuditInsecureGuestLogon 1 (Enabled) LanmanWorkstation
ServerAuditInsecureGuestLogon SMB audit Core LanmanServer/AuditInsecureGuestLogon 1 (Enabled) LanmanServer
Security Log size Core EventLogService/SpecifyMaximumFileSizeSecurityLog Enabled, 1048576 KB EventLogService
System Log size Core EventLogService/SpecifyMaximumFileSizeSystemLog Enabled, 131072 KB EventLogService
Application Log size Core EventLogService/SpecifyMaximumFileSizeApplicationLog Enabled, 131072 KB EventLogService

Settings without a CSP

Intune can't set these through the Settings catalog. Where they matter, run Enable-LoggingBaseline.ps1 on the device (or use Group Policy on domain-joined hosts, see Group Policy paths).

Setting Type Why
ScriptBlock32 Registry The 32-bit (WOW64) copy of the script block policy has no CSP of its own.
ModuleLogging32 Registry The 32-bit (WOW64) copy of the module logging policy has no CSP of its own.
ModuleNames32 Registry The 32-bit (WOW64) copy of the module list has no CSP of its own.
PS7ScriptBlock64 Registry No built-in CSP for PowerShell 7 policy. Importing its ADMX as a custom template may be blocked by the registry locations Intune allows for imported ADMX.
PS7ScriptBlock32 Registry No built-in CSP for PowerShell 7 policy (32-bit copy).
PS7ModuleLogging64 Registry No built-in CSP for PowerShell 7 policy. Importing its ADMX as a custom template may be blocked by the registry locations Intune allows for imported ADMX.
PS7ModuleLogging32 Registry No built-in CSP for PowerShell 7 policy (32-bit copy).
NtlmOutboundAudit Registry A CSP exists (LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers), but Microsoft lists its value 1 as "Deny all domain accounts", not the registry's "Audit all". Setting 1 through the CSP could block NTLM, so don't set it in Intune; Group Policy or Enable-LoggingBaseline.ps1 sets it correctly.
NtlmDomainAudit (DC) Registry No CSP. Domain controllers only; set it by GPO on the DCs.
Microsoft-Windows-PowerShell/Operational Log No CSP for this log's size.
Windows PowerShell Log No CSP for this log's size.
PowerShellCore/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-Windows Defender/Operational Log No CSP for this log's size.
Microsoft-Windows-Bits-Client/Operational Log No CSP for this log's size.
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall Log No CSP for this log's size.
Microsoft-Windows-NTLM/Operational Log No CSP for this log's size.
Microsoft-Windows-Security-Mitigations/KernelMode Log No CSP for this log's size.
Microsoft-Windows-Security-Mitigations/UserMode Log No CSP for this log's size.
Microsoft-Windows-PrintService/Admin Log No CSP for this log's size.
Microsoft-Windows-PrintService/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-SmbClient/Security Log No CSP for this log's size.
Microsoft-Windows-AppLocker/EXE and DLL Log No CSP for this log's size.
Microsoft-Windows-AppLocker/MSI and Script Log No CSP for this log's size.
Microsoft-Windows-AppLocker/Packaged app-Deployment Log No CSP for this log's size.
Microsoft-Windows-AppLocker/Packaged app-Execution Log No CSP for this log's size.
Microsoft-Windows-CodeIntegrity/Operational Log No CSP for this log's size.
Microsoft-Windows-Diagnosis-Scripted/Operational Log No CSP for this log's size.
Microsoft-Windows-DriverFrameworks-UserMode/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-WMI-Activity/Operational Log No CSP for this log's size.
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational Log No CSP for this log's size.
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-TaskScheduler/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-SMBServer/Audit Log No CSP for this log's size.
Microsoft-Windows-SmbClient/Audit Log No CSP for this log's size.
Microsoft-Windows-SMBServer/Security Log No CSP for this log's size or enablement.
Microsoft-Windows-SMBServer/Operational Log No CSP for this log's size or enablement.
Microsoft-Windows-Crypto-DPAPI/Debug Log No CSP for this log's size or enablement.
AdcsAuditFilter Registry No CSP, and it needs a CertSvc restart: set it on the CA in a change window (Enable-LoggingBaseline.ps1 there).