Intune deployment and Group Policy impact?

EnterpriseArchitect 4,846 Reputation points
2022-11-22T06:11:55.56+00:00

Hi Folks,

I need clarification and guidance if my current Hybrid Azure AD joined device still using Group Policy will not conflict with Intune when I enrol it en-masse.

Will there be any conflict or problem later on when the existing AD DS Group Policy is still applied to the workstation when managed by Intune?

In case there is a conflict or issue, which one takes precedence, the On-Premise AD DS group Policy or the Intune Policy?

Any help would be greatly appreciated.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,738 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,263 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,423 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 43,736 Reputation points Microsoft Vendor
    2022-11-22T08:23:14.44+00:00

    @EnterpriseArchitect , Thanks for posting in Q&A.

    In General, Intune uses policies that help you manage settings on Windows PCs. Many Intune settings are similar to settings that you might configure with Windows Group Policy. However, it is possible that, at times, the two methods might conflict with each another. When conflicts happen, domain-level Group Policy takes precedence over Intune policy.

    Starting with Windows 10 1803, there's a setting named MDMWinsOverGP can allow the IT admin to control which policy will be used whenever both the MDM policy and its equivalent Group Policy (GP) are set on the device. But it only applies to policies in Policy CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs. Here is a link with more details for the reference:
    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-controlpolicyconflict

    To avoid issue, it is recommended to migrate policies from Group policy to Intune. You can analyze your on-premises GPOs using Group Policy analytics in Microsoft Intune. And then do migration. Here are some articles for the reference:
    https://learn.microsoft.com/en-us/mem/intune/configuration/group-policy-analytics
    https://learn.microsoft.com/en-us/mem/intune/configuration/group-policy-analytics-migrate

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    4 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,171 Reputation points Microsoft Employee
    2022-11-22T19:28:03.17+00:00

    MDMWinsOverGP

    We strongly recommend that you avoid using this policy setting. It has many caveats that almost certainly will cause you issues. Control conflicts by not targeting the same settings from both authorities to the same devices. Definitely start your journey to using Intune for policy management ASAP and moving away from group policy is which more or less now legacy.

    2 people found this answer helpful.

  2. Jason Sandys 31,171 Reputation points Microsoft Employee
    2022-11-28T17:17:43.427+00:00

    is there any comparison or Pros and Cons between the Intune Policy vs. Group Policy

    Honestly, the only significant pro v con is that group policy is legacy as noted.

    I'm curious which settings cannot be done via Intune Policy.

    We don't have any comparison documentation as there are few significant differences when it comes to actual policies. Those that do exist either are not valid in a cloud native world or should generally be considered as not best for use in a cloud native world. The links posted by @Crystal-MSFT are a great starting point to begin your journey.

    1 person found this answer helpful.
    0 comments No comments