{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
        "slug": "dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/"
        },
        "title": "Account for STIG checks excluded from Intune's audit report",
        "summary": "How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:59+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 241,
        "potentially_affected": "Consider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.",
        "dse_recommendation": "Maintain a coverage register alongside the automated results.",
        "primary_source": {
            "name": "Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune&#8217;s STIG audit baseline is read-only and does not configure device settings. Rules requiring physical inspection, administrative judgment, or conditions unavailable to the device&#8217;s configuration providers are excluded from its audit report and require separate manual assessment. The report also does not display the actual device configuration values behind its pass or fail results. The feature is limited to GCC High tenants. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Consider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.</p>\n<h2>DSE recommendation</h2>\n<p>Maintain a coverage register alongside the automated results. Assign each excluded manual check an owner, an evidence requirement, and a review state. Keep missing manual evidence separate from a failed automated rule and from a rule that is not applicable. Do not count absence from the report as evidence that a requirement was met.</p>\n<h2>Verification</h2>\n<p>Compare the benchmark&#8217;s documented manual-check list with the review register and reconcile every omission. For a sampled automated result, inspect the underlying device setting through an approved read-only method rather than expecting the report to expose its value. Preserve assessment evidence and any approved remediation as separate records. Close the review only when the automated coverage and remaining manual work are both explicitly accounted for.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nIntune’s STIG audit baseline is read-only and does not configure device settings. Rules requiring physical inspection, administrative judgment, or conditions unavailable to the device’s configuration providers are excluded from its audit report and require separate manual assessment. The report also does not display the actual device configuration values behind its pass or fail results. The feature is limited to GCC High tenants. Microsoft Learn.\nApplicability\nConsider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.\nDSE recommendation\nMaintain a coverage register alongside the automated results. Assign each excluded manual check an owner, an evidence requirement, and a review state. Keep missing manual evidence separate from a failed automated rule and from a rule that is not applicable. Do not count absence from the report as evidence that a requirement was met.\nVerification\nCompare the benchmark’s documented manual-check list with the review register and reconcile every omission. For a sampled automated result, inspect the underlying device setting through an approved read-only method rather than expecting the report to expose its value. Preserve assessment evidence and any approved remediation as separate records. Close the review only when the automated coverage and remaining manual work are both explicitly accounted for.\nOfficial references\nMicrosoft Learn: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune.",
        "content_markdown": "## Source facts\n\nIntune’s STIG audit baseline is read-only and does not configure device settings. Rules requiring physical inspection, administrative judgment, or conditions unavailable to the device’s configuration providers are excluded from its audit report and require separate manual assessment. The report also does not display the actual device configuration values behind its pass or fail results. The feature is limited to GCC High tenants. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline).\n\n## Applicability\n\nConsider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.\n\n## DSE recommendation\n\nMaintain a coverage register alongside the automated results. Assign each excluded manual check an owner, an evidence requirement, and a review state. Keep missing manual evidence separate from a failed automated rule and from a rule that is not applicable. Do not count absence from the report as evidence that a requirement was met.\n\n## Verification\n\nCompare the benchmark’s documented manual-check list with the review register and reconcile every omission. For a sampled automated result, inspect the underlying device setting through an approved read-only method rather than expecting the report to expose its value. Preserve assessment evidence and any approved remediation as separate records. Close the review only when the automated coverage and remaining manual work are both explicitly accounted for.\n\n## Official references\n\n[Microsoft Learn: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Account for STIG checks excluded from Intune's audit report",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/",
                "headline": "Account for STIG checks excluded from Intune's audit report",
                "description": "How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?",
                "abstract": "How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?",
                "articleBody": "Source facts\nIntune’s STIG audit baseline is read-only and does not configure device settings. Rules requiring physical inspection, administrative judgment, or conditions unavailable to the device’s configuration providers are excluded from its audit report and require separate manual assessment. The report also does not display the actual device configuration values behind its pass or fail results. The feature is limited to GCC High tenants. Microsoft Learn.\nApplicability\nConsider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.\nDSE recommendation\nMaintain a coverage register alongside the automated results. Assign each excluded manual check an owner, an evidence requirement, and a review state. Keep missing manual evidence separate from a failed automated rule and from a rule that is not applicable. Do not count absence from the report as evidence that a requirement was met.\nVerification\nCompare the benchmark’s documented manual-check list with the review register and reconcile every omission. For a sampled automated result, inspect the underlying device setting through an approved read-only method rather than expecting the report to expose its value. Preserve assessment evidence and any approved remediation as separate records. Close the review only when the automated coverage and remaining manual work are both explicitly accounted for.\nOfficial references\nMicrosoft Learn: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune.",
                "datePublished": "2026-09-10T00:24:59+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Account for STIG checks excluded from Intune's audit report"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 241,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline"
                }
            }
        ]
    }
}