Configuration Profiles Best Practise

Anonymous
2022-12-18T10:33:34.007+00:00

Simple question, when setting up device configuration profiles, is it good practise to differentiate between Corporate and BYOD devices at the assignment stage?

Reason I ask, if I have a BYOD AAD registered device on Home Windows 10, I don’t want it to be picking up Bitlocker configuration policies, or Compliance/Conditional Access Policies on the same theme, as I would for BYOD AAD Registered/Joined devices Windows 10 Pro.

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
143 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,609 questions
0 comments No comments
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,366 Reputation points
    2022-12-19T07:24:52.97+00:00

    @Anonymous Thanks for posting in our Q&A.

    Of course. If you don't want some devices apply some policies, please don't add these devices in these policies' assignment. Create a device group for home windows devices and create another device group for windows 10 pro devices.

    However, it is needed to apply Conditional Access Policies to users, not devices. So, the target user signing in the home windows device will still be limited by the conditional access policy.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


2 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-12-23T17:22:56.3+00:00

    @Lu Dai-MSFT-0289
    Couple of things:

    1. When differentiating between Corporate/BYOD is it best to use a filter in the assignment.
    2. Can you expand on para 2, not quite sure what you are saying to me, are you saying Conditional Access is tied to identity, hence it's only tied to User Assignment when assigning conditional access policy?

  2. Anonymous
    2023-01-03T13:35:07.173+00:00

    @Lu Dai-MSFT
    Firstly, hope you had a merry Xmas and a happy new year.

    Many thanks for the clarification, Intune is a great product, but not easy to understand sometimes, due to it’s granularity (many moving parts).