# SkipToTheEndpoint/OpenIntuneBaseline

Community-driven baseline to accelerate Intune adoption and learning.

Repository: https://github.com/SkipToTheEndpoint/OpenIntuneBaseline
Canonical: https://ross.abutalabs.com/products/openintunebaseline
Language: PowerShell
License: GPL-3.0
License Family: copyleft
Topics: device-config, intune, microsoft, security
Last push: 2026-05-08T12:33:27+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 81, release rhythm 59, longevity 100
- inputs: {"age_days": 1569, "days_push": 117, "days_rel": 117, "gap_med": 118.0, "n_releases_24m": 5}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1453, forks 270 (observed 2026-08-28T04:04:46.596898+00:00)

## What it is
A community-driven security baseline of configuration profiles and settings for Windows devices managed by Microsoft Intune. It provides a known-good starting point for endpoint security posture, informed by frameworks like CIS, NCSC, and ACSC Essential Eight.

## Use cases
- set up a security baseline for Windows devices in Intune
- harden Windows endpoints managed by Microsoft Intune
- learn Intune configuration best practices
- apply CIS and NCSC security recommendations via Intune
- bootstrap device configuration policies for a new Intune tenant
- compare my Intune settings against a community baseline

## When to choose
- you are adopting or learning Microsoft Intune and want a vetted starting point
- you want a baseline that balances security with admin manageability and user experience
- you prefer community-reviewed settings aligned to CIS, NCSC, and ACSC frameworks

## When to avoid
- you need a formally certified or vendor-supported compliance baseline
- you manage non-Windows or non-Intune environments
- you require production liability guarantees - the project explicitly assumes none

## Facets
- artifact type: infra-config
- maturity: active
- function: security, configuration-management, developer-tools
- domain: security, windows
- platform: windows, cloud, self-hosted
- tags: intune, microsoft-365, security-baseline, powershell, device-management, mdm, cis-benchmarks, endpoint-management, devops

## Member repositories
- SkipToTheEndpoint/OpenIntuneBaseline (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:46.596898+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:35:44.419958+00:00, confidence not recorded.
  - readme: https://github.com/SkipToTheEndpoint/OpenIntuneBaseline (fetched 2026-08-28T04:04:46.596898+00:00, sha 04c686dcf4db)
- Data as of 2026-08-30T08:39:29.467469+00:00.
