Endpoint management

Endpoint security policy

Microsoft Intune endpoint security policy

Endpoint security policies are a distinct, security-team-focused set of policy types within Intune, found under the Endpoint Security node of the admin console rather than alongside general configuration profiles.

Why Endpoint security policy matters in a Microsoft estate

Endpoint security policy matters for endpoint teams because device, app, compliance, update, and troubleshooting signals often sit across several Microsoft admin areas. Linking these terms back to Intune and device-reporting routes helps readers move from definition to action.

How Endpoint security policy shows up in practice

They cover disk encryption (BitLocker and FileVault), firewall rules, antivirus and Microsoft Defender configuration, endpoint detection and response (EDR) onboarding to Microsoft Defender for Endpoint, attack surface reduction rules, and account protection settings such as local administrator password management through Windows LAPS. Functionally, most endpoint security policies configure the same underlying CSPs that a general configuration profile could also set, and the split exists primarily for organisational and role-based reasons: it lets a dedicated security team own and manage security-specific configuration, with its own assignment and reporting surface, separately from a broader device management team's Wi-Fi, VPN, and general restriction profiles. That matters in larger organisations where those two functions sit in genuinely different teams with different change control processes.

This separation is also exactly where duplicate or conflicting settings creep in: it is entirely possible for a general configuration profile and an endpoint security policy to both target the same CSP, for instance firewall state, with different values, producing the same kind of unresolved conflict that affects overlapping configuration profiles generally. It is a common oversight for organisations to build out endpoint security policies without checking whether an existing configuration profile already sets the same underlying settings. Microsoft Defender for Endpoint integration is one of the more operationally significant pieces here: onboarding devices for EDR through an endpoint security policy is what actually connects Intune-managed devices into Defender's detection and response capability.

A device that's compliant and encrypted but never received its Defender onboarding policy is fully patched and locked down on paper while remaining invisible to the organisation's actual threat detection tooling, a gap that's easy to miss because it doesn't show up as a compliance failure the way a missing BitLocker or password policy would. Attack surface reduction rules and account protection policies, including Windows LAPS for rotating local administrator passwords automatically, are newer additions to this policy family and are commonly under-deployed relative to the more established encryption and antivirus policies.

Partly this is because they require a slightly different mental model, reducing the practical impact of a compromise rather than checking a static compliance state, and partly because retrofitting them into an estate with existing local admin practices or software that assumes predictable local admin credentials takes more careful rollout planning than most other Intune policy types. Because these policies sit at the sharpest end of an organisation's actual security posture rather than just its reported compliance percentage, gaps here are disproportionately consequential relative to their visibility. Reviewing endpoint security policy coverage against the full device estate, not just against what's assigned versus what compliance policy reports as passing, is a worthwhile distinct exercise from general Intune policy auditing.

Glossary