Wes Ellis./ a personal notebook
Technology. Stories. Side projects.
A few things worth writing down.
← Back to Engineering

Engineering

Pushing Configuration Profiles to Devices That Are Already Deployed

Part 5 of the thread Getting devices into Intune

THE SHORT VERSION4 points
  • Build the profile once, assign it to a group, and every device picks it up at its next check-in. No reimage, no visit.
  • Start new profiles in the settings catalog, and keep BitLocker, Defender and firewall under Endpoint security.
  • Use device groups for machine-wide settings, and pilot on a handful of machines before widening.
  • In the status report, Conflict and Not applicable are the two results worth chasing.

Getting settings onto a brand-new device is the easy part. Autopilot runs, policies land, everybody's happy. The harder part is changing something on the few hundred laptops that are already out there, in bags and on kitchen tables, and being sure it arrived.

That's what configuration profiles are for. You build the profile once, assign it to a group, and each device picks it up the next time it checks in with Intune. No reimage, no visit.

Pick the right kind of profile

Before you click anything, decide what you're configuring, because Intune has more than one place for settings:

  • Settings catalog. This is where most new profiles should start. It's one searchable list of thousands of settings, and it's where Microsoft adds new ones first.
  • Templates. Pre-built profiles for things like Wi-Fi, VPN, certificates and custom OMA-URI settings. Use these when the catalog doesn't cover what you need.
  • Endpoint security. BitLocker, Defender Antivirus, firewall and attack surface reduction have their own policies under Endpoint security. You can configure some of these in a regular profile, but keeping security settings in one place makes conflicts much easier to spot later.

Create the profile

  1. Sign in to the Intune admin center. (It used to be the Microsoft Endpoint Manager admin center at endpoint.microsoft.com. Same service, new name.)
  2. Go to Devices > Configuration, then Create > New policy.
  3. Choose the platform, for example Windows 10 and later, and the profile type, usually Settings catalog.
  4. Give it a name you'll understand in two years. Something like Win - Edge - Homepage and Startup beats Test policy 3.
  5. Add your settings. In the catalog, use Add settings and search. Every setting has an info icon that explains what it really does, and it's worth reading.
  6. On Scope tags, add any you use to divide admin rights. If you don't use them, leave the default.
  7. On Assignments, add the groups it should apply to, plus any groups to exclude.
  8. Review and Create.

Get the assignment right

This is the step that decides whether the profile does what you meant.

User groups or device groups? A profile assigned to a user group follows that user to every device they sign in to. A device group sticks to the hardware no matter who's using it. For machine-wide settings, device groups are usually the safer choice.

Tip

Start small. Assign to a pilot group of a handful of devices first, ideally including your own. Wait a day, then widen it. Somebody's line-of-business app always has an opinion about your new setting.

Filters help. Assignment filters let you narrow a big group without building a new one, like "all users, but only on devices where the model starts with Surface".

When will it apply?

Devices check in with Intune roughly every eight hours, and more often right after enrollment. A new or changed policy also sends a notification that prompts devices to check in sooner. So most online devices pick up changes fairly quickly, and anything asleep or offline catches up next time it's on the network.

Try this

To hurry one along, open the device in Intune and click Sync. Or on the device itself, go to Settings > Accounts > Access work or school, select the account, then Info > Sync.

Make sure it landed

Open the profile and check its Device and user check-in status. You'll see counts for succeeded, failed, conflict, not applicable and pending. Click through to see individual devices, then per-setting status for the ones that failed.

Two results deserve extra attention, plus one that's really a different problem:

Status What it usually means
Conflict Another profile sets the same thing to a different value. Intune won't pick a winner for you. Find the other profile and decide which one owns the setting.
Not applicable The setting doesn't apply to that Windows edition or version. A setting that requires Enterprise does nothing on Pro, quietly.
Pending for days The device isn't checking in at all. That's an enrollment or connectivity problem, not a profile problem.