<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance-Baseline on Anything About IT</title><link>https://www.verboon.info/tags/compliance-baseline/</link><description>Recent content in Compliance-Baseline on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 12 Jul 2019 14:30:04 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/compliance-baseline/index.xml" rel="self" type="application/rss+xml"/><item><title>Monitoring Windows Defender Cloud Protection Service connectivity with ConfigMgr</title><link>https://www.verboon.info/2019/07/monitoring-windows-defender-cloud-protection-service-connectivity-with-configmgr/</link><pubDate>Fri, 12 Jul 2019 14:30:04 +0000</pubDate><guid>https://www.verboon.info/2019/07/monitoring-windows-defender-cloud-protection-service-connectivity-with-configmgr/</guid><description>&lt;p&gt;Hello everyone, earlier this week I wrote a blog post how to test Microsoft Defender Cloud Protection Service (MAPS) with PowerShell. Today I would like to share a possible approach how to actively monitor MAPS Connectivity across all your devices using ConfigMgr configuration baselines.&lt;/p&gt;
&lt;p&gt;As mentioned in my earlier blogpost in order to take full advantage of Microsoft Defender protection capabilities, it’s important that clients can communicate with MAPS, if the client cannot communicate with MAPS the client will be unable to provide near-instant, automated protection against new and emerging threats, meaning that Windows Defender will only be using the latest protection updates installed locally, depending on the strategy how you deploy these, these might be a couple of hours if not days old.&lt;/p&gt;</description></item><item><title>OMS Security and Audit Baseline Assessment</title><link>https://www.verboon.info/2018/02/oms-security-and-audit-baseline-assessment/</link><pubDate>Mon, 19 Feb 2018 20:53:31 +0000</pubDate><guid>https://www.verboon.info/2018/02/oms-security-and-audit-baseline-assessment/</guid><description>&lt;p&gt;The Microsoft Operations and Management Suite, Security and Audit Solution includes a Baseline Assessment component. The Baseline configuration definition includes a set of Registry, audit policy and security policy settings rules that are recommended to configure to achieve a secure operating environment.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/021918_2045_OMSSecurity1.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/021918_2045_OMSSecurity2.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;Within the Console we get an overview of &amp;ldquo;Rules&amp;rdquo; that have failed, because the servers don&amp;rsquo;t have the recommended configuration applied. While looking at this, I wondered where I can find the complete set of rules that are used when performing the baseline assessment.&lt;/p&gt;</description></item><item><title>ConfigMgr&amp;ndash;Compliance Baseline for BranchCache on Windows 8</title><link>https://www.verboon.info/2013/10/configmgrcompliance-baseline-for-branchcache-on-windows-8/</link><pubDate>Tue, 08 Oct 2013 14:14:03 +0000</pubDate><guid>https://www.verboon.info/2013/10/configmgrcompliance-baseline-for-branchcache-on-windows-8/</guid><description>&lt;p&gt;Here’s a ConfigMgr Compliance baseline that checks the BranchCache configuration on Windows 8 clients. With the release of Windows 8 and Server 2012 Microsoft also made available &lt;a href="http://technet.microsoft.com/en-us/library/hh848392.aspx"&gt;PowerShell cmdlets for BranchCache&lt;/a&gt;, so creating a script based configuration item in ConfigMgr becomes a pretty straight forward task.&lt;/p&gt;
&lt;p&gt;The below Compliance Baseline checks the following 3 things.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Is BranchCache Enabled&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Is the Service Running&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Is BranchCache operating in Distributed Cache mode&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/image_thumb.png" alt="image"&gt;

&lt;/p&gt;
&lt;p&gt;The following PowerShell commands are included within the configuration items.&lt;/p&gt;</description></item></channel></rss>