Operations
Baseline
Configuration baseline
A configuration baseline is a known-good snapshot of a system or tenant's settings, captured and formally designated as the trusted reference point that all future comparisons are measured against, whether that system is a Microsoft 365 tenant's Conditional Access and compliance policies, an Intune device configuration profile, or a broader security posture assessment.
Why Baseline matters in a Microsoft estate
Baseline matters when teams need repeatable day-two work rather than one-off fixes. Definitions in this area should help readers connect reporting, review, remediation, backup, drift, and evidence capture to a controlled operating model.
How Baseline shows up in practice
The defining property of a baseline is not simply that it was captured, but that it was deliberately chosen and pinned as correct. A scheduled tenant backup produces many historical snapshots over time, but only one of them, typically reviewed and approved, becomes the baseline that drift detection actually compares live state against. This is what turns a passive archive of past states into an active reference for judging whether current configuration is still correct. Establishing a baseline is itself a governance decision, not a purely technical one, since it usually follows a security review, a compliance audit, or a deliberate hardening exercise. This means the baseline represents not just what the tenant looked like at a point in time but what the organisation agreed it should look like.
That is why re-baselining after a legitimate, reviewed change is appropriate, while re-baselining simply because the current state has quietly drifted away from the old baseline is not, since that would encode uncontrolled drift as the new normal rather than flagging it as something to review. Baselines are the direct input to drift detection: every subsequent comparison walks forward from the pinned baseline. Anything that differs, a loosened Conditional Access rule, a compliance policy that no longer matches, a security control that got disabled, surfaces as drift that needs a decision, either restore the setting to match the baseline or accept the change and update the baseline to reflect it as the new intended state.
For Intune specifically, Microsoft's own security baselines, pre-built templates of recommended settings for Windows, Microsoft Defender, and related workloads, serve the same conceptual purpose at a broader, vendor-published level. They give organisations a starting reference point they can adopt and then customise into their own tenant-specific baseline rather than building one from a blank slate. Baselines also carry direct audit and compliance value: being able to show an assessor a specific, dated, approved baseline, evidence of ongoing comparison against it, and a record of remediation whenever drift was found and corrected, is concrete, demonstrable proof of the kind of configuration management and change control that frameworks like ISO 27001, Cyber Essentials, and SOC 2 expect. This turns what could be an abstract policy statement into something backed by a verifiable trail of actual comparisons and actions taken.