In the policy we require code integrity, however a lot of our pcs are returning an error status of . My company has recently implemented intune and made a compliance policy. The windows baseline security has got.
A code integrity policy consists of a set of authorization indicators, either code signing certificates or sha256 file hashes, which the kernel matches before loading or. Windows defender application control (wdac) has evolved significantly, transitioning from device guard configurable code integrity to its current iteration as application control for. Code integrity is a security feature that ensures only trusted and verified code runs on a device.
For more information on supported versions, see device health attestation. Alternatively, you can configure these settings by using. These policies determine which code can run on windows. Enabling this feature in intune requires using the code integrity node in the virtualizationbasedtechnology csp.
For devices that don't support tpm 2.0 or later, the policy status in intune shows as not compliant. Code integrity is a feature that validates the integrity of drivers and system files each time they are loaded into memory. For memory integrity i used the following setting in my intune configuration profile: Code integrity policies shift endpoint security from reactive threat detection to proactive application control.