# Account for STIG checks excluded from Intune's audit report

> How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:59+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?

## Potentially affected

Consider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.

## DSE recommendation

Maintain a coverage register alongside the automated results.

## Article

## Source facts

Intune’s STIG audit baseline is read-only and does not configure device settings. Rules requiring physical inspection, administrative judgment, or conditions unavailable to the device’s configuration providers are excluded from its audit report and require separate manual assessment. The report also does not display the actual device configuration values behind its pass or fail results. The feature is limited to GCC High tenants. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline).

## Applicability

Consider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.

## DSE recommendation

Maintain a coverage register alongside the automated results. Assign each excluded manual check an owner, an evidence requirement, and a review state. Keep missing manual evidence separate from a failed automated rule and from a rule that is not applicable. Do not count absence from the report as evidence that a requirement was met.

## Verification

Compare the benchmark’s documented manual-check list with the review register and reconcile every omission. For a sampled automated result, inspect the underlying device setting through an approved read-only method rather than expecting the report to expose its value. Preserve assessment evidence and any approved remediation as separate records. Close the review only when the automated coverage and remaining manual work are both explicitly accounted for.

## Official references

[Microsoft Learn: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline).

## Primary reference

- Name: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/security-baselines/stig-audit-baseline
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Account for STIG checks excluded from Intune's audit report,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-417-account-for-stig-checks-excluded-from-intune-s-audit-report/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
