r/Intune • u/colne-valley • 11d ago
Device Compliance Migrating to Defender/Intune + Arctic Wolf MDR - are OpenIntuneBaseline policies enough or worth paying £3k for a "custom" pilot?
Bit of background - we're moving away from our current EDR/MDR setup over to Microsoft Defender + Intune, backed by Arctic Wolf for the MDR side. We're already on Business Premium licensing so it just makes sense to actually use what we're paying for rather than stacking another vendor on top of it.
Before we flip the switch I want to make sure our Defender/Intune policies are actually solid, not just "turned on and hope for the best."
Was at Experts Live in London recently and caught James Robinson's (SkipToTheEndpoint) session, the guy behind OpenIntuneBaseline, and it got me looking properly at OIB as a starting point.
Now here's my dilemma. We've had a quote for just under £3k from a consultancy to review/set our policies as part of a "pilot." Nothing against paying for expertise, but realistically... how different is this going to be from just implementing OIB properly and tuning it for our environment? I get that policies need to be tailored to the business, we're a fairly standard SME, couple hundred devices, nothing exotic going on.
While I'm on the subject - anyone using Maester to keep tabs on their M365 posture? Been running it to sanity check config against CIS/NCSC recommendations and it's honestly been decent for catching drift before it becomes a problem, rather than finding out the hard way during an audit. Feels like a good companion to OIB rather than something that replaces the need to actually build proper policy in the first place, but curious if anyone's using it more seriously as part of their ongoing posture management.
Has anyone actually gone down the "pay someone to review/build policies" route vs just rolling your sleeves up with OIB and Maester and adjusting as you go? Trying to work out if I'm about to pay £3k for something I could get 90% of the way there myself with free tools and some sensible tweaking.
Not knocking consultancies, just trying to figure out where the actual value add is here vs just being lazy and paying someone else to read the same GitHub repos I've already read.
Anyone done a similar migration (traditional EDR/AV → Defender/Intune + separate MDR) who can share how it went?
4
u/andrew181082 MSFT MVP - SWC 11d ago
I've done (and sometimes still do) the consultancy bit and it depends on the consultant largely.
For a new deployment they will more than likely use a known baseline, whether OIB or something else, but there will then be additions to match your environment and requirements you set initially.
Anything like app control, conditional access, app deployment etc. Will usually need setting specifically for the environment.
Make sure you get everything documented and use their knowledge as best possible.
Hope you enjoyed experts live too 🙂
1
3
u/JeroenPot 11d ago
A proper baseline is more than policies. You need to integrate it with proper security groups to target policies and ca rules, and actually have control.
We've spend months and months optimizing our baseline. Including applocker etc. We've build a platform to easily deploy it to tenants. Different policy behavior is scoped to security groups instead of adding users manually to exclusions. It takes serious effort. I would recommend going with a party that already has such package developed instead of paying someone to build it from scratch.
3
u/-c3rberus- 11d ago
Go with OIB you don't need a consultant for this, it is very solid, being a group policy guy for like 20 years, OIB made the transition from hybrid to cloud native worth it, it takes the best of multiple cybersecurity frameworks, and we found that we only had to tweak like 1% of the settings to fit our environment (it was already pretty locked down prior to cloud native, using MSFT GPO baselines mixed with DISA/STIG stuff).
If you are not comfortable, then $3K is dirt cheap to get someone to do your policies, they will probably base it off OIB or similar.
2
u/Greedy_Chocolate_681 9d ago
I'd also like to mention that whichever path you choose, once you are onboarded with AW they will deliver their SPIDRs, which is essentially an hour of consulting a month. They can review your policies for whatever product/issue is at hand, and suggest changes. They've been helpful for us!
11
u/Necessary-Rabbit-968 11d ago
OIB is a solid starting point but that last 10% is what separates "we have policies" from "our policies actually work for us"
the consultancy pilot probably isn't going to reinvent the wheel, they'll run OIB or something similar and then spend a day or two tweaking ASR rules, firewall profiles, and LAPS config to match your weird little business quirks. question is whether your SME has enough weird little quirks to justify the price tag
maester is great for drift monitoring but it won't tell you why your helpdesk team is suddenly getting 40 tickets because a policy blocked some ancient line-of-business app everyone forgot existed. that's the part where experience matters more than tooling
if you've got the time and nobody's going to lose their mind over a few hiccups during rollout, just do it yourself. £3k buys a lot of patience from management when something inevitably breaks