Skip to content

Framework coverage

Compare your Settings Catalog policies with a baseline, review the gaps, and create the missing settings as unassigned policies.

Frameworks compares your tenant’s Settings Catalog policies with a versioned baseline, setting by setting. It shows which recommended settings are present, missing or different, lets you inspect the evidence, and can create the missing settings as new, unassigned policies.

The results are configuration findings, not a compliance score or a certification.

Open Frameworks in the sidebar. All frameworks lists the catalog, and Find a framework… filters it. The catalog includes:

FrameworkPublisherTypePolicy content
OpenIntuneBaselineSkipToTheEndpointBaselineWindows v3.8 and macOS v1.0 Settings Catalog packs load directly
Microsoft Security BaselinesMicrosoftBaselineImport your own policy JSON
CIS BenchmarksCenter for Internet SecurityBenchmarkImport your own licensed mappings
CIS ControlsCenter for Internet SecurityControl frameworkImport your own mappings
NIST CSFNISTControl frameworkImport your own mappings
NIST SP 800-53NISTControl frameworkImport your own mappings
NIST SP 800-171NISTControl frameworkImport your own mappings
DISA STIGDISABenchmarkImport your own mappings
ASD Essential EightAustralian Signals DirectorateControl frameworkImport your own mappings
BSI IT-GrundschutzBSIControl frameworkImport your own mappings
Custom BaselinesYour organizationCustomImport your own policy JSON

Only OpenIntuneBaseline ships automatic policy content. For every other entry you supply reviewed Settings Catalog policy exports that map the framework to Intune. TenuVault does not bundle CIS benchmark text, CIS Build Kits or any other restricted content. Selecting a framework does not certify your mappings as official.

Each framework page describes its source and coverage, and links to the publisher with Source.

CommunityProMSP
Compare with the OIB Windows Settings Catalog packYesYesYes
Compare with the OIB macOS pack, imported packs and other frameworksNoYesYes
Create missing settings from a comparisonYesYesYes

On Community, a comparison is allowed when every loaded policy is an OIB Windows Settings Catalog policy. Other comparisons return an upgrade message for “Baselines beyond the Windows Quick Start”.

Select the tenant in the sidebar, then open a framework.

“Import one or more Settings Catalog JSON exports. Review the source, version and intended profile before comparison. Loading a pack does not change your tenant.”

  • On OpenIntuneBaseline, click Load OIB Windows v3.8 or Load OIB macOS v1.0. TenuVault downloads the pack from the upstream repository at a pinned commit. Loading fails as a whole if any policy cannot be downloaded or parsed.
  • On any framework, use Import policy JSON to select one or more .json files. Each file holds one policy or an array of policies.

The header shows how many policies are loaded. Then:

  1. Enter Source version / profile, for example “approved workstation baseline, revision 3, standard profile”. It is required before you can compare, and is limited to 200 characters. OIB packs fill it in for you.
  2. Expand Review N loaded policies and remove alternative profiles. OIB includes alternative profiles for some settings; click Remove next to the ones you do not use. Alternatives left in the pack produce Review findings.
  3. Optional: click Export coverage and source mappings to save a JSON inventory of every policy and setting mapping, its provenance, and the areas outside automated coverage.
  • Between 1 and 200 policies, 8 MB in total.
  • Each policy needs name, platforms, technologies and a non-empty settings array.
  • Each setting needs a settingInstance with a settingDefinitionId and its @odata.type.
  • Tenant-specific IDs, assignments, scope tags and export annotations are removed from what TenuVault would create.

Errors such as “Policy 3: expected a Settings Catalog export with name, platforms, technologies and settings.” tell you which policy to fix.

Click Run comparison (Compare again for later runs). TenuVault reads all Settings Catalog policies in the tenant, every page of each policy’s settings, and each policy’s assignments. If any read fails or is incomplete, the comparison stops instead of reporting settings as missing.

The result shows how many tenant policies were read and when. Filter the findings with All, Present, Missing, Different and Review:

ResultMeaning
PresentEvery occurrence of the setting in your tenant matches the recommended configuration.
MissingNo policy of the same family and platform configures the setting.
DifferentAt least one occurrence differs from the recommendation, even if another policy matches.
ReviewThe pack contains alternative values for this setting. Remove the alternative profiles, or resolve the recommendation yourself.

How matching works:

  • Settings are matched by their setting definition, never by policy name.
  • Nested values are compared. Extra nested values in your policy produce Different.
  • Collections are compared in order, so a reordered collection may show Different and need manual review.
  • An unassigned policy can still be Present.

Expand a finding to see Recommended configuration next to Observed policies and configuration. The observed side lists each matching policy with its value and its assignment evidence: all devices, all users, groups, exclusions and filter references. Targeting is reported as unassigned, configured, review or unavailable. A denied or incomplete assignment read is shown as unavailable, never as unassigned.

Findings are shown 50 per page. Click Export report to save the assessment as JSON.

You can create the Missing settings as new policies:

  1. Tick the Missing findings you want. Only Missing findings can be selected. The footer shows how many settings and new policies your selection makes, for example “4 missing root settings selected · 2 new policies”.
  2. Click Preview recommended policies.
  3. Expand Inspect the exact policy payloads to see what will be sent.
  4. Tick “I reviewed these recommendations and want to create unassigned policies in tenant.”
  5. Click Create N unassigned policies.

What TenuVault creates:

  • One new policy per source policy you selected settings from, named [Baseline] followed by the source policy name. Its description records the source version and that it was created unassigned.
  • Only the selected settings, with their nested dependent settings.
  • No assignments. Existing policies are never changed or deleted.

Before writing, TenuVault reads the tenant again. If your policies changed since the comparison, it stops with “The tenant policy landscape changed. Compare again before creating policies.” A comparison can be used for creation once, within 15 minutes.

The result lists each policy with its new ID or its error, followed by “Unassigned policies created. Assignment and device verification are still required.” Review the new policies and their conflicts in Intune before you assign them. Run the comparison again to confirm the settings now show as Present.

Loaded packs, source versions and assessment results are saved per tenant and framework in encrypted storage on this device. Under Saved workspace and history you can:

  • Export workspace to save the whole workspace as JSON.
  • Delete workspace to remove the packs and all history for this framework and tenant.
  • View read-only to open a saved assessment. Historical assessments cannot be used to create policies; run a fresh comparison first.
  • Export or Delete a single saved assessment. Deleting an assessment also cancels its pending creation.

A workspace keeps up to 50 assessments and 32 MB. When it is full, TenuVault shows “Workspace history is full. Export and delete older assessments before continuing.”

Automated comparison covers Settings Catalog policies only. These areas are outside its scope:

  • Compliance policies
  • Update rings
  • Legacy security baseline templates
  • Application deployment
  • Device enforcement and applicability
  • Organizational controls and manual audit evidence

Conflicts with other policy families are not evaluated. Profile selection and approval, organizational safeguards and device-side validation remain manual.

MessageCause and fix
Request failed (403) at … Check Intune permissions for this tenant.Your account or the app registration cannot read Settings Catalog policies. Check your Intune role.
Policy settings changed during the read. Compare again.A policy changed while TenuVault read it. Run the comparison again.
This assessment has expired or was already used. Run comparison again.More than 15 minutes passed, or policies were already created from it. Compare again.
Another baseline creation is in progress for this tenant.Wait for the current creation to finish.
The selection repeats a setting across multiple policies. Select it from one policy only.Deselect the duplicate setting in one of the policies.
Provide a source version and profile (up to 200 characters).Fill in Source version / profile.
The policy pack exceeds 8 MB.Import fewer or smaller files.

OpenIntuneBaseline content is by SkipToTheEndpoint and contributors, licensed under GPL-3.0.