GuideInformationCybersecurityIT

Account for STIG checks excluded from Intune's audit report

How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

How should reviewers handle STIG rules that Intune's automated audit cannot evaluate?

Potentially affected

Consider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.

DSE recommendation

Maintain a coverage register alongside the automated results.

Source facts

Intune’s STIG audit baseline is read-only and does not configure device settings. Rules requiring physical inspection, administrative judgment, or conditions unavailable to the device’s configuration providers are excluded from its audit report and require separate manual assessment. The report also does not display the actual device configuration values behind its pass or fail results. The feature is limited to GCC High tenants. Microsoft Learn.

Applicability

Consider this report-boundary review only for an eligible GCC High deployment. Confirm the applicable benchmark and device population, and consult the current prerequisite list before treating the audit profile as an available service.

DSE recommendation

Maintain a coverage register alongside the automated results. Assign each excluded manual check an owner, an evidence requirement, and a review state. Keep missing manual evidence separate from a failed automated rule and from a rule that is not applicable. Do not count absence from the report as evidence that a requirement was met.

Verification

Compare the benchmark’s documented manual-check list with the review register and reconcile every omission. For a sampled automated result, inspect the underlying device setting through an approved read-only method rather than expecting the report to expose its value. Preserve assessment evidence and any approved remediation as separate records. Close the review only when the automated coverage and remaining manual work are both explicitly accounted for.

Official references

Microsoft Learn: Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune.

Primary reference

Review the official source

Use Security Technical Implementation Guide audit baselines to assess Windows device compliance in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE