Do you need GPO for hybrid deployment of current on prem devices or will the user scope for mdm suffice?

Justin Lee 221 Reputation points
2023-03-28T01:05:11.7533333+00:00

Do you need GPO for hybrid deployment of current on prem devices or will the user scope for mdm suffice? Seeing conflicting articles. Whats the point of user scope for the mdm vs the GPO?

Microsoft Security | Intune | Enrollment
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
{count} votes

Answer accepted by question author
  1. Pavel yannara Mirochnitchenko 13,426 Reputation points MVP
    2023-03-28T09:14:45.84+00:00

    You can use GPO, MDM user or MDM device. By default, in conflict, MDM wins over GPO. Best way is to minimize GPO and maximize MDM ( Intune's Settings Catalog by default)

    And if you mean the GPO setting for MDM enrollment, use always User sub-selection there. Device selection is for co-mgnt or AVD multisession.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.