With the help of Security Baseline, recommended security settings are applied to the end device. These offer an enhanced protection compared to the default settings, but should still not be considered as a definitive solution in production as some security aspects are not covered that are standard today in e.g. hospital or bank environments.
Learn about Windows security baselines you can deploy with Microsoft Intune | Microsoft Learn
My recommendations:
- Define a test group of IT & business users and apply Microsoft’s baselines
- Check conflicts – depending on the same settings have been defined via Windows profiles or policies in “Endpoint security”.
- Test the baseline for 2-3 weeks, as some restrictions may arise that affect the work of the user.
- Perform customizations.
- Implement & test further security settings using CIS Benchmark.
- Have the settings checked or validated by Endpoint Security experts.
CIS Benchmarks:
https://learn.cisecurity.org/benchmarks
Please note that for Windows devices managed via Intune a different benchmark document exists.