Microsoft Intune Bug Prevents Saving of Security Baseline Policy Changes During Updates

Microsoft recently disclosed a significant issue affecting the security baseline policy update flow in Intune, the cloud-based endpoint management service widely used for device and policy management.

The problem involves customizations made by administrators to security baselines not being saved when updating to newer baseline versions, such as moving from version 23H2 to 24H2.

This issue impacts organizations that rely on tailored security configurations to meet their specific compliance and operational needs.

Understanding the Security Baseline Update Problem

Security baselines in Microsoft Intune are sets of preconfigured Windows device configuration settings designed to enforce recommended security policies.

These baselines are templates consisting of multiple device configuration profiles, leveraging the Configuration Service Provider (CSP) framework to apply granular settings like BitLocker enforcement, password requirements, and authentication controls on Windows 10 and 11 devices.

Administrators often customize these baselines to deviate from Microsoft’s recommended defaults to better suit organizational policies.

However, the newly identified issue causes these customized settings to be overwritten and reset to default values during the baseline update process.

This means that when an admin updates a security baseline profile to a newer version (e.g., 23H2 to 24H2), any deviations from the default settings are lost, forcing admins to manually reapply their customizations post-update.

Technical Details and Workaround

The problem arises during the baseline update flow, where the update mechanism fails to retain settings that differ from the recommended baseline values.

This issue specifically affects profiles updated to versions released after May 2023, when Microsoft introduced a new security baseline format aligned more directly with CSP names and configurations.

Currently, Microsoft recommends the following temporary workaround:

  • After updating the baseline to the latest version, administrators should manually reapply any customizations that were previously configured.
  • Admins are encouraged to consult the Microsoft Learn documentation on “Update a profile to the latest version”, which explains the baseline update process and how to export settings for easier reapplication.

Microsoft is actively working on a fix and has committed to providing updates via their official support channels and blog posts.

Best Practices for Managing Security Baseline Updates

To minimize disruption and maintain security posture during baseline updates, organizations should adopt the following best practices:

  • Test updates on duplicate profiles: Before applying updates to production groups, create copies of existing baseline profiles and test updates on a controlled group to validate changes and customizations.
  • Use Intune’s CSV export feature: Export existing baseline configurations to CSV files to track current customizations and facilitate manual reapplication if necessary.
  • Plan for phased rollouts: Deploy updated baselines incrementally to user/device groups to monitor impact and rollback if needed.
  • Stay informed on baseline versions: Regularly review Microsoft’s baseline version releases and update notes to anticipate changes and plan accordingly.
  • Leverage PowerShell and Microsoft Graph API: For advanced management, scripts such as those available on GitHub can help compare and manage baseline profiles programmatically.

This issue highlights the importance of careful change management in endpoint security configurations.

While Microsoft Intune continues to evolve its security baseline framework, administrators must remain vigilant in applying updates and preserving critical customizations to safeguard their environments effectively.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories