Do you need GPO for hybrid deployment of current on prem devices or will the user scope for mdm suffice?

Justin Lee 221 Reputation points
2023-03-28T01:05:11.7533333+00:00

Do you need GPO for hybrid deployment of current on prem devices or will the user scope for mdm suffice? Seeing conflicting articles. Whats the point of user scope for the mdm vs the GPO?

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,346 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,959 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,346 questions
{count} votes

Accepted answer
  1. Pavel yannara Mirochnitchenko 12,496 Reputation points MVP
    2023-03-28T09:14:45.84+00:00

    You can use GPO, MDM user or MDM device. By default, in conflict, MDM wins over GPO. Best way is to minimize GPO and maximize MDM ( Intune's Settings Catalog by default)

    And if you mean the GPO setting for MDM enrollment, use always User sub-selection there. Device selection is for co-mgnt or AVD multisession.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.