Skip to content

Latest commit

 

History

History
62 lines (50 loc) · 2.94 KB

advanced-hunting-devicebaselinecomplianceassessmentkb-table.md

File metadata and controls

62 lines (50 loc) · 2.94 KB
title description search.appverid ms.service ms.subservice f1.keywords ms.author author ms.localizationpriority manager audience ms.collection ms.custom ms.topic ms.date
DeviceBaselineComplianceAssessmentKB table in the advanced hunting schema
Learn about the various security configurations used by baseline compliance to assess devices in the DeviceBaselineComplianceAssessmentKB table in the advanced hunting schema.
met150
defender-xdr
adv-hunting
NOCSH
v-sgoyagoy
samanthagy
medium
dansimp
ITPro
m365-security
tier3
cx-ti
cx-ah
reference
11/20/2024

DeviceBaselineComplianceAssessmentKB (Preview)

[!INCLUDE Microsoft Defender XDR rebranding]

Applies to:

  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint

Important

Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.

The DeviceBaselineComplianceAssessmentKB table in the advanced hunting schema contains information about various security configurations used by baseline compliance to assess devices.

For information on other tables in the advanced hunting schema, see the advanced hunting reference.

Column name Data type Description
ConfigurationId string Unique identifier for a specific configuration
ConfigurationName string Display name of the configuration
ConfigurationDescription string Description of the configuration
ConfigurationRationale string Description of any associated risks and rationale behind the configuration
ConfigurationCategory string Category or grouping to which the configuration belongs
BenchmarkProfileLevels dynamic List of benchmark compliance levels for which the configuration is applicable
CCEReference string Unique Common Configuration Enumeration (CCE) identifier for the configuration
RemediationOptions string Recommended actions to reduce or address any associated risks
ConfigurationBenchmark string Industry benchmark recommending the configuration
Source dynamic The registry path or other location used to determine the current device setting
RecommendedValue dynamic Set of expected values for the current device setting to be compliant

Related topics

[!INCLUDE Microsoft Defender XDR rebranding]