Your organization wants a Microsoft-recommended security configuration that can be pinned to a specific version and upgraded in a controlled manner for Azure AD-joined Windows 11 Enterprise multi-session session hosts managed by Intune. What should you deploy?
Choose an answer
Tap an option to check your answer.
Correct answer: A Windows 11 Security Baseline profile in Intune and pin it to the desired baseline version..
Why this is the answer
The correct option is a Windows 11 Security Baseline profile in Intune, pinned to a specific version. Microsoft Security Baselines are pre-configured groups of settings recommended by Microsoft for securing Windows devices. They can be pinned to a specific version, allowing for controlled upgrades and consistent security posture across Azure AD-joined Windows 11 multi-session hosts managed by Intune. A Settings catalog profile with 'Baseline mode' enabled is not a standard Intune feature. While the Settings Catalog allows granular configuration, there isn't a specific 'Baseline mode' that directly maps to Microsoft's security baselines. An Administrative Templates profile for Windows relies on ADMX ingestion and doesn't offer the version pinning and comprehensive security recommendations of a Microsoft Security Baseline. Relying on automatic versioning might introduce unexpected changes. A custom OMA-URI profile that imports the CIS benchmark is a valid method for applying custom settings but is more complex to manage, doesn't offer native version pinning like Microsoft Baselines, and isn't Microsoft's recommended out-of-the-box solution for this scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed