Azure / Azure/securedworkstation

Device Compliance policy for ATP seems incredibly permissive

Open
#29 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
PowerShell
Stars
260
Forks
62
PR merge metrics
No merged PRs in 30d

Description

The readme states:

[Privileged Compliance ATP](https://github.com/Azure/securedworkstation/blob/master/PAW/JSON/DeviceCompliance/PAW-Compliance-ATP.json) policy is used to feed the Threat Intelligence data from Microsoft Defender for Endpoint into the devices compliance state so its signals can be used as part of the Conditional Access evaluation process.

However it looks like the policy has very loose parameters i.e. all of these are `false`: `passwordMinimumLength`, `defenderEnabled`, `activeFirewallRequired`

Can anyone explain this?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.