Skillplan M365 Checklist
2026-07-20 00:24
M365
Microsoft 365 Security Checkliste
de
en
fr
it
System Online
← Zurück zu den Bereichen
Mitigationsmaßnahmen · Bereich 14 von 17
Intune — Endpoint Management
Bewertungsfortschritt
0
/ 136 Elemente
0%
Bisherige Erfüllung
0
/ 0 Kontrollen
0%
Diese Kontrolle erklären
Enforce a device compliance policy that requires BitLocker, Secure Boot, antivirus, and a current OS build.
Nicht erfüllt
Erfüllt
Akzeptiert
Require Conditional Access to consume Intune device compliance signals (no access for non-compliant devices).
Nicht erfüllt
Erfüllt
Akzeptiert
Enroll all Windows devices via Autopilot; eliminate manual on-the-box administrator provisioning.
Nicht erfüllt
Erfüllt
Akzeptiert
Apply App Protection Policies (MAM) requiring a PIN, blocking copy/paste to unmanaged apps, and wiping on jailbreak.
Nicht erfüllt
Erfüllt
Akzeptiert
Deploy Defender for Endpoint via Intune; do not rely on user-driven onboarding.
Nicht erfüllt
Erfüllt
Akzeptiert
Enable Endpoint Privilege Management to grant just-in-time local-admin elevation for approved actions.
Nicht erfüllt
Erfüllt
Akzeptiert
Apply ASR rules and Controlled Folder Access via the Intune Endpoint Security blade.
Nicht erfüllt
Erfüllt
Akzeptiert
Maintain a corporate-device wipe policy for retired or lost devices and exercise it quarterly.
Nicht erfüllt
Erfüllt
Akzeptiert
Speichern und Weiter →