A CIS baseline scanner/comparison would be great, and would show the intune / ad «policy holes» vs CIS preferred baseline.
Today we try to comply with CIS policy baselines, but there are always some holes left open, either intentionally or unintentionally.
Also, a report could tag devices as % of CIS compliance. Maybe with the possibility to exclude the parts of cis per organization to show proof of control.