{"product_id":11298,"v_id":11298,"product_name":"Microsoft Intune","certification_status":"Certified","certification_date":"2024-12-31T00:00:00Z","tech_type":"Mobility","vendor_id":{"name":"Microsoft Corporation","website":"https://www.microsoft.com"},"vendor_poc":"Michael Grimm","vendor_phone":"425-703-5683","vendor_email":"mgrimm@microsoft.com","assigned_lab":{"cctl_name":"Lightship Security USA, Inc."},"product_description":"<p><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif; color: black;\">Microsoft Intune is a mobile device management system that includes MDM Server and Mobile Application Store (MAS) functionality. The Microsoft Company Portal app provides the MDM agent for Android devices.</span></p>","evaluation_configuration":"<p style=\"margin: 6pt 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\">Microsoft Intune is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM). Administrators can control how their organization&rsquo;s mobile devices are used and also configure specific policies to control applications installed on the devices.&nbsp;There is only one Intune service (version) that is continuously offered with rolling feature enhancements which is located at the URL described in section 1.2 of the Security Target. Intune is part of Microsoft's Enterprise Mobility + Security (EMS) suite.</p>\r\n<p><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">The Microsoft Intune Company Portal is a mobile device management agent.</span></p>","security_evaluation_summary":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which Microsoft Intune was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Rev. 5. The product, when configured as identified in the <em><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">Operational and Administrative Guidance Microsoft Intune</span></em>, satisfies all of the security functional requirements stated in the <em>Microsoft Intune Security Target</em>. The project underwent CCEVS Validator review. The evaluation was completed in December 2024. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span></p>","environmental_strengths":"<h3 style=\"margin: 12pt 0in 3pt 0.55in; text-indent: -0.3in; break-after: avoid; font-size: 12pt; font-family: 'Times New Roman Bold', serif;\"><a name=\"_Toc522003816\"></a><a name=\"_Toc522783575\"></a><a name=\"_Toc523296995\"></a>Security Audit</h3>\r\n<p style=\"margin: 6pt 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\">Microsoft Intune has the ability to generate, review, protect, and restrict access to audit and event logs as required by the MDM PP and MDM Agent PP-Module.&nbsp; Audit information generated by the system includes the date and time of the event, the user identity that caused the event to be generated, and other event specific data.&nbsp; Authorized administrators can review audit logs and have the ability to search and sort audit records securely via the Microsoft Intune Admin Center console or via the Graph API. In the context of this evaluation, the protection profile requirements cover generating audit events, which events should be audited, and providing secure storage for audit event entries. <a name=\"_Toc211918531\"></a><a name=\"_Toc522003817\"></a><a name=\"_Toc522783576\"></a><a name=\"_Toc523296996\"></a><a name=\"_Toc173855412\"></a></p>\r\n<h3 style=\"margin: 12pt 0in 3pt 0.55in; text-indent: -0.3in; break-after: avoid; font-size: 12pt; font-family: 'Times New Roman Bold', serif;\">Cryptographic Support</h3>\r\n<p style=\"margin: 6pt 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\">Microsoft Intune provides cryptographic functions that support encryption/decryption, cryptographic signatures, cryptographic hashing, cryptographic key agreement, and random number generation. The TOE additionally provides support for X.509 certificates including validation functions. Certificates are issued during device enrollment and are used for authentication and protection of both user and system data while in transit.</p>\r\n<h3 style=\"margin: 12pt 0in 3pt 0.55in; text-indent: -0.3in; break-after: avoid; font-size: 12pt; font-family: 'Times New Roman Bold', serif;\"><a name=\"_Toc201998726\"></a><a name=\"_Toc522003818\"></a><a name=\"_Toc522783577\"></a><a name=\"_Toc523296997\"></a><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;</span>Identification and authentication</h3>\r\n<p style=\"margin: 6pt 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\">Each Microsoft Intune administrator must be identified and authenticated based on administrator-defined policy prior to performing any TSF-mediated functions.&nbsp; An interactive user invokes a trusted path to protect their identity and credentials.&nbsp; Microsoft Intune maintains databases of accounts including their identities, authentication information, group associations, and administrative privileges. Microsoft Intune provides the ability to use, store, and protect X.509 certificates that are used for mobile devices. Communications between the Mobile device and Intune are facilitated with authenticated TLS sessions.</p>\r\n<h3 style=\"margin: 12pt 0in 3pt 0.55in; text-indent: -0.3in; break-after: avoid; font-size: 12pt; font-family: 'Times New Roman Bold', serif;\"><a name=\"_Toc201998727\"></a><a name=\"_Toc522003819\"></a><a name=\"_Toc522783578\"></a><a name=\"_Toc523296998\"></a><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;</span>Security Management</h3>\r\n<p style=\"margin: 6pt 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\">Microsoft Intune includes several functions to manage security policies on registered devices.&nbsp; Microsoft Intune MDM policy functions include the ability to define the minimum password length, the number of failed logon attempts, the duration of lockout, and password age. MDM Policy management is available to Intune administrators that have sufficient permissions or are members of an applicable role-based group as described in FMT_SMR.1. Successfully enrolled devices are issued an X.509 certificate that is used for identification and authentication.</p>\r\n<h3 style=\"margin: 12pt 0in 3pt 0.55in; text-indent: -0.3in; break-after: avoid; font-size: 12pt; font-family: 'Times New Roman Bold', serif;\"><a name=\"_Toc201998728\"></a><a name=\"_Toc522003820\"></a><a name=\"_Toc522783579\"></a><a name=\"_Toc523296999\"></a><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;</span>Protection of the TOE Security Functions</h3>\r\n<p style=\"margin: 6pt 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><a name=\"_Toc201998729\"></a>Microsoft Intune provides several features to ensure the protection of TOE security functions. Intune protects against unauthorized data disclosure and modification by requiring authenticated TLS sessions between registered devices and Intune. All Intune components employ self-testing features on start-up that ensure the integrity of executable code and any cryptographic functions.</p>\r\n<h3 style=\"margin: 12pt 0in 3pt 0.55in; text-indent: -0.3in; break-after: avoid; font-size: 12pt; font-family: 'Times New Roman Bold', serif;\"><a name=\"_Toc200530868\"></a><a name=\"_Toc522003823\"></a><a name=\"_Toc522783581\"></a><a name=\"_Toc523297001\"></a>Trusted path/Channels<a name=\"_Toc219289137\"></a><a name=\"_Toc219289139\"></a><a name=\"_Toc219289141\"></a><a name=\"_Toc219289143\"></a><a name=\"_Toc219289145\"></a><a name=\"_Toc219289146\"></a><a name=\"_Toc199065774\"></a><a name=\"_Toc199656154\"></a><a name=\"_Toc199757990\"></a><a name=\"_Toc199762456\"></a><a name=\"_Toc199762609\"></a><a name=\"_Toc199065776\"></a><a name=\"_Toc199656156\"></a><a name=\"_Toc199757992\"></a><a name=\"_Toc199762458\"></a><a name=\"_Toc199762611\"></a><a name=\"_Toc199065777\"></a><a name=\"_Toc199656157\"></a><a name=\"_Toc199757993\"></a><a name=\"_Toc199762459\"></a><a name=\"_Toc199762612\"></a><a name=\"_Toc199065778\"></a><a name=\"_Toc199656158\"></a><a name=\"_Toc199757994\"></a><a name=\"_Toc199762460\"></a><a name=\"_Toc199762613\"></a><a name=\"_Toc199065780\"></a><a name=\"_Toc199656160\"></a><a name=\"_Toc199757996\"></a><a name=\"_Toc199762462\"></a><a name=\"_Toc199762615\"></a><a name=\"_Toc199065781\"></a><a name=\"_Toc199656161\"></a><a name=\"_Toc199757997\"></a><a name=\"_Toc199762463\"></a><a name=\"_Toc199762616\"></a><a name=\"_Toc199065782\"></a><a name=\"_Toc199656162\"></a><a name=\"_Toc199757998\"></a><a name=\"_Toc199762464\"></a><a name=\"_Toc199762617\"></a><a name=\"_Toc199065783\"></a><a name=\"_Toc199656163\"></a><a name=\"_Toc199757999\"></a><a name=\"_Toc199762465\"></a><a name=\"_Toc199762618\"></a> for Communications</h3>\r\n<p><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">Microsoft Intune uses TLS and HTTPS to provide a trusted path for communications between Intune and remote administrators as well as registered devices. Trusted channels provided by Intune include the Microsoft Intune Admin Center for Administrator use via HTTPS, and a X.509 authenticated TLS channel for device enrollment and continual policy updates.</span></p>","features":[{"id":2007,"feature_name":"Asymmetric Key Generation"},{"id":2003,"feature_name":"Auditing"},{"id":2000,"feature_name":"Certificate Authentication"},{"id":1999,"feature_name":"Certificate Validation"},{"id":2009,"feature_name":"Cryptographic Hashing"},{"id":2008,"feature_name":"Cryptographic Key Establishment"},{"id":2010,"feature_name":"Cryptographic Signature Generation"},{"id":4001,"feature_name":"Cryptographic Signature Verification"},{"id":1998,"feature_name":"DRBG"},{"id":2006,"feature_name":"HTTPS Client"},{"id":2004,"feature_name":"Key Destruction"},{"id":2011,"feature_name":"Keyed-hash message authentication"},{"id":2005,"feature_name":"MDM-Agent"},{"id":1989,"feature_name":"Mobile Application Management"},{"id":1988,"feature_name":"Mobile Content Management"},{"id":1984,"feature_name":"Mobile Device Management"}]}