MDM and GPO co-existance

Nikhil Sasikumar 0 Reputation points
2025-03-11T19:45:33.68+00:00

Hello there,

I have to move one policy to Intune which is currently configured in GPO. If I enable MDM Wins over GP, I believe other settings configured in GPO will be still be applied on the systems. Is it mandatory to remove the configuration from GPO before I apply it from Intune?

Thank you,

Nikhil

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
2,022 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,781 Reputation points MVP
    2025-03-11T21:51:30.8566667+00:00

    MDMWinsOverGpo policy CSP does not support Defender and Windows Update CSP. If the setting you want to move doesn’t fall under the above listed CSP, then you can leave the GPO on. If not, the. you will need to remove the assignment for the said setting in GPO.


  2. Crystal-MSFT 52,736 Reputation points Microsoft External Staff
    2025-03-12T01:17:35.1166667+00:00

    @Nikhil Sasikumar, Agree with Rahul, MDMWinsOverGP only applies to policies in Policy CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs.

    User's image

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-controlpolicyconflict#mdmwinsovergp

    If the same setting is configured in both GPO and Intune, it could lead to unpredictable behavior. To ensure a smooth transition, you might want to:

    1. Review and identify the policies in GPO that you plan to move to Intune. https://learn.microsoft.com/en-us/mem/intune-service/configuration/group-policy-analytics
    2. Disable or remove those specific policies from GPO after confirming they are successfully applied via Intune.
    3. Monitor the devices to ensure the Intune policies are being enforced correctly.

    This approach helps in avoiding conflicts and ensures that the intended policies are applied consistently across your devices.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.