Considerations:
There are three options available offering different levels of security in the form of bundled, ready to use policy groups:
Light Security Policy Groups:
The Light Security Policy Group is for Admins looking to provide users with a minimally restrictive experience while enforcing critical security against everyday threats with targeted security policies like firewall controls, sign-on requirements, disk encryption, device storage, and configuring account statuses.
For the list of policies included, please refer to this page
Standard Security Policy Groups:
The Standard Security Policy Group is for Admins looking to provide users with a moderately restrictive experience while enforcing critical security measures. This group contains everything in the Light security tier plus extra features like file and app-sharing restrictions, secure startup settings, SSH access and security, file ownership, permissions, and storage management.
For the list of policies included, please refer to this page
Enhanced Security Policy Groups:
The Enhanced Security Policy Group is for Admins looking to provide significant device protections with maximum restrictions on the end user. The group contains everything in the Light and Standard tiers, plus features like system hardening, app and app store/software restrictions, remote assistance, blocked profile installation, control panel access, and notification settings.
For the list of policies included, please refer to this page
For more details about the policies, please see below: