215 settings currently Unconfirmed. These candidates are not counted as verified.
Intune Baseline
Comparison
See the coverage first. Inspect the evidence when needed.
How much of Microsoft’s baseline does OIB cover?
The verified figure requires both a reliable setting identity and comparable value semantics. Unconfirmed candidates are shown separately instead of inflating coverage.
335 of 482 if all current Unconfirmed candidates are verified.
147 Microsoft settings have no current OIB candidate.
Microsoft baseline composition
482 settings- 115 Same
- 5 Different
- 215 Unconfirmed
- 147 No established OIB match
Among the 120 verified comparisons, 115 use equivalent values and 5 differ.
Where do OIB and Microsoft differ?
5 verified configuration differences found.
- Submit Samples Consent
- Privilege Use Audit Sensitive Privilege Use
- User Account Control Behavior Of The Elevation Prompt For Standard Users
- PK Init Hash Algorithm SHA256
- Require Platform Security Features
No established Microsoft baseline match
1015OIB settings for which the current matcher has not established a Microsoft counterpart. This group may include genuine OIB additions and false negatives caused by differing source representations or incomplete metadata.
Explore these OIB settings →v3.8
1350 normalized settings · 1445 occurrences
View pinned OIB source ↗25H2
482 reference entries · Intune
View pinned Microsoft source ↗15 Sept 2026, 05:48
Europe/Stockholm
Comparison generated 17 Sept 2026, 16:12
Coverage by area
Start with the part of the baseline you care about, then inspect individual settings if needed.
Defender & attack surface
17 of 56 Microsoft settings
BitLocker & data protection
4 of 11 Microsoft settings
Identity & authentication
31 of 63 Microsoft settings
Device & platform security
10 of 12 Microsoft settings
Firewall & networking
17 of 44 Microsoft settings
Audit & privileges
16 of 36 Microsoft settings
Applications & browser
5 of 189 Microsoft settings
Windows system & experience
18 of 58 Microsoft settings
Other
2 of 13 Microsoft settings
DETAILED VIEWExplore individual settings
Search, filter and inspect source evidence when you need the granular view.
Open explorer ↓
Explore individual settings
Search, filter and inspect source evidence when you need the granular view.
The default view contains the 482 Microsoft baseline settings. OIB settings without an established Microsoft baseline match are available as a separate dataset.
Open the explorer to load settings.
Loading comparison data…
No settings match these filters. Try another search or reset the filters.
Evidence before coverage.
Produced by JNL Group AB. This is an independent tool, not an official Microsoft or OpenIntuneBaseline product. Verify results before making security decisions.
- Deterministic setting IDs and documented CSP paths establish identity first.
- Uncertain mappings remain Unconfirmed and do not increase verified coverage.
- No established Microsoft baseline match means that the matcher found no counterpart; it does not prove that the setting is absent from Microsoft’s baseline.
- “Not Configured” is not automatically assigned an effective Windows value.
- Different describes a configuration difference, not a security ranking.
How this comparison works
The comparison uses saved public configuration data. Stable setting IDs and documented CSP paths establish identity. Unconfirmed means that the available source evidence is insufficient for the tool to classify a comparison as Same or Different. Verified OIB coverage is 24.9% of the Microsoft baseline.
OIB settings without an established Microsoft baseline match are reported separately and never enter the Microsoft coverage denominator. This group may contain both genuine OIB additions and false negatives caused by source representation differences or incomplete metadata.
Configured values are separate from effective Windows defaults. “Not Configured” is never assumed to mean Disabled. v1 does not use effective-default mappings.
Downloads include the entire current dataset, regardless of filters. No tenant access is required. Source snapshots are versioned, and upstream changes require validation and review before promotion.