§ Baselines · what's included
Every artifact created in your tenant when you run Baselines, by section. Profiles ship unassigned by default so you can review before rolling out — or flip the optional toggle to activate everything tenant-wide on deploy.
§ ships with audit reference
$3,000
One-time · no ongoing costs
§ required licensing
M365 Business Premium M365 Enterprise (E3 / E5) Intune Standalone Need licensing →Optional auto-assign features (dynamic AutoPilot group, MDM auto-enrollment) require Entra ID Premium P1, which is bundled with all M365 SKUs above.
These artifacts are created in your tenant on every Baselines purchase, regardless of whether you toggle the optional auto-activate.
Devices › Windows › Enrollment
Entra ID › Protection › Conditional Access
Devices › Compliance
To be compliant, devices must:
If non-compliant:
Devices › Configuration
Apps › Windows
Devices › Windows › Update rings
Devices › Configuration › IOC - Windows LAPS
Devices › Configuration › IOC - ASR Rules (Audit)
Devices › Configuration › IOC - Firewall Profile
A single opt-in checkbox on the deploy page. Off by default. Flip it on and the deployment also wires up these tenant-wide settings before redeeming the order.
Profile assignment
Tenant-wide auto-enroll
Auto-assign requires Entra ID Premium P1 (bundled with M365 Business Premium and all M365 Enterprise SKUs).
After deployment, your confirmation page links to a guided handoff for every major OEM. Set up each vendor once and every future order ships pre-registered with AutoPilot.
Walkthroughs included for
Each vendor has multiple paths (self-service, account rep, reseller, troubleshooting) so you can route around portal changes and account quirks.
Saveable, vendor-agnostic
Vendor calls rarely happen the same day. The page is designed to be revisited.
Profiles deploy unassigned by default
Designed so you can review every policy before applying it. Auto-assign is one explicit checkbox away.
Built for cloud-only Windows fleets
Entra-joined / cloud-only environments. Hybrid Azure AD join and non-Windows platforms are out of scope.
Retry-safe redemption
Your order is only marked redeemed after a fully-successful deploy. Failures don't burn the order.
Complete-build guarantee
You always end up with the full environment. If our automated deploy doesn't land every configuration, we'll manually build out the rest ourselves at no extra cost.
Need every detail for an audit?
This brochure is the customer-friendly view. For a full compliance reference with every setting, framework mapping (CIS / NIST CSF / SOC 2), and verification procedures, open the Audit Reference Document.
§ ready to deploy
Deployed, documented, and connected to your hardware vendors in one afternoon. Ships with the audit reference your reviewer will sign off on.
Get Baselines → Back to home