Do you need GPO for hybrid deployment of current on prem devices or will the user scope for mdm suffice?

Justin Lee 221 Reputation points
2023-03-28T01:05:11.7533333+00:00

Do you need GPO for hybrid deployment of current on prem devices or will the user scope for mdm suffice? Seeing conflicting articles. Whats the point of user scope for the mdm vs the GPO?

Microsoft Security Intune Enrollment
Microsoft Security Microsoft Entra Microsoft Entra ID
Microsoft Security Intune Other
{count} votes

Accepted answer
  1. Pavel yannara Mirochnitchenko 13,331 Reputation points MVP
    2023-03-28T09:14:45.84+00:00

    You can use GPO, MDM user or MDM device. By default, in conflict, MDM wins over GPO. Best way is to minimize GPO and maximize MDM ( Intune's Settings Catalog by default)

    And if you mean the GPO setting for MDM enrollment, use always User sub-selection there. Device selection is for co-mgnt or AVD multisession.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.