OSDeploy | Sune Thomsen
TwitterLinkedInWindows 365 CommunityMVP ProfileGitHub
  • Home
  • Blog
    • Microsoft Intune
      • How to migrate BitLocker key(s) from all fixed drives to Microsoft Entra ID.
      • Migrate Bitlocker Recovery Key(s) to Azure AD with Proactive Remediation
      • Migrate imported GPOs to Intune with Group Policy analytics (preview)
      • Group Policy analytics (preview) made a bit easier with PowerShell
      • Analyze on-premises GPOs with MEM Group Policy Analytics (preview)
    • Virtual Machine
      • Fix the Hyper-V virtual switches after updating to Windows 11 (22H2)
    • 🆕Windows 365
      • 🆕Windows 365 Boot: Why User-Driven Mode?
      • 🆕Enhancing Security With Intune MAM (preview) for Windows 365
      • The Concept of Windows 365 Switch
      • The Concept of Windows 365 Boot
      • The Concept of Windows 365 Frontline
      • Move Cloud PCs to a new Azure Region or Azure Network Connection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 4. Windows 365 app and Cloud PC reporting
      • Windows 365 End-User Experience (Tips & Tricks) – Part 3. Multimedia Redirection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 2. Teams Optimization, SSO, and Localization
      • Windows 365 End-User Experience (Tips & Tricks) – Part 1. Connection experience
      • How to Configure Windows 365 Azure AD Join Single Sign-on (SSO)
      • Keep Windows 365 current and stay current with Windows Autopatch
      • Provide the end-users with a localized Windows 365 Cloud PC experience
      • How to configure Windows 365 Enterprise Azure AD join
      • How to secure Windows 365 using a FIDO2 security key
      • Prevent sensitive information from being captured on Windows 365 CPCs
      • Manage local administrator rights on Windows 365 Cloud PCs.
      • How to create a custom image for Windows 365 Enterprise Cloud PCs
      • How to reprovision existing Cloud PC (Windows 365) to Windows 11
      • How to configure Windows 365 Enterprise in Microsoft Endpoint Manager
  • Archive
    • Deployment
      • OSDCloud: The ZTI Way
      • OSDBuilder: WinPE Customization
    • Microsoft Configuration Manager
      • ConfigMgr: Run "All" Client Actions During OSD
      • ConfigMgr: WIM Your Applications Like a Boss
      • ConfigMgr: Deploy UWP Applications During OSD
      • ConfigMgr: Building a Basic LAB Environment
        • Part 1 - Installing Windows 10 (1909) on the Host
        • Part 2 - The Host and Hyper-V Configuration
        • Part 3 - Setting up the Domain Controller
          • Active Directory
          • DHCP
          • DNS
        • Part 4 - Setting up Microsoft Endpoint Configuration Manager
          • Prerequisites
          • SQL
        • Part 5 - Setting up Discovery Methods and Boundaries
        • Part 6 - Setting up Software Update Point
      • ConfigMgr: Splash Screen for Driver and BIOS Update
      • ConfigMgr: Global Conditions for Dell WD15 Dock Detection
    • Microsoft Intune
      • Block personally owned devices in Intune with enrollment restrictions
      • Remove Windows 10 built-in apps with Intune & Microsoft Store for Business Apps
    • Windows
      • Win10: Multi-Language Toast Notifications
        • Toast Notification: Low Disk Space
  • Links
    • Blogs
    • Microsoft
    • Scripts
Powered by GitBook
On this page
  • BEFORE YOU BEGIN
  • Introduction
  • Migrate GPOs to a Settings Catalog profile
  • Summary

Was this helpful?

  1. Blog
  2. Microsoft Intune

Migrate imported GPOs to Intune with Group Policy analytics (preview)

31-05-2023 9:01 PM

PreviousMigrate Bitlocker Recovery Key(s) to Azure AD with Proactive RemediationNextGroup Policy analytics (preview) made a bit easier with PowerShell

Last updated 9 months ago

Was this helpful?

BEFORE YOU BEGIN

Disclaimer: All information and content in this blog post is provided without any warranty whatsoever. The entire risk of using this information or executing the provided content remains with you. Under no circumstances should the mentioned persons or vendors, the author, or anyone else involved in creating these blog posts be held liable for any damage or data loss.

Migrate imported GPOs to Intune with Group Policy analytics (preview)

Introduction

Migrate GPOs to a Settings Catalog profile

In the list of your imported GPOs, select the Migrate checkbox next to the GPO you want to include in your Settings Catalog profile. Note. You can choose to select one GPO or multiple GPOs. Click Migrate.

From the Settings to migrate page, you can select all settings or search and manually select the settings to transition to Intune. – I chose four random settings for this article. Important note. As mentioned above, you can migrate multiple GPOs to the same Settings Catalog profile, but the list may include identical settings with different values! – If you choose identical settings with different values, a conflict will occur, and an error will show with the following message:

Conflicts are detected for the following settings: <setting name>. Select only one version with the value you prefer in order to continue.

Click Next.

On the Configuration page, you can review the selected settings and their values. Click Next.

On the Profile info page, fill in the required Name field. Although the Description field is optional, I would recommend filling it out. – It’s always a great idea to leave some breadcrumbs, so others know precisely why someone created the configuration profile. Click Next.

Choose either to assign the profile to "All devices/All users" or a group from the Assignments page. – I chose to assign this profile to "All devices", and then I’ve added a filter to only include corporate devices. Note. You do not have to configure the assignment at this point if your organization is not ready for it. Click Next.

The page will redirect you to an overview of your configuration profiles in Intune, and in the Notifications area, you should see that the migration was successful.

Select the newly created Settings Catalog profile from the overview and scroll down to the Configuration settings area. You will see the settings we chose during the profile creation. Shortly after creating and assigning the profile, the devices should start returning some data to the dashboard within the configuration profile.

Summary

In our previous blog post, where I wrote about , I promised you an article about the new migration option within Group Policy analytics (preview). Using this new feature, you can create a Settings Catalog profile based on your imported GPOs and assign the profile to "All devices/All users" or your groups directly from Group Policy analytics (preview) in Intune. Read about the prerequisites and requirements for Group Policy analytics (preview) and how to use the tool in our original blog post here –

Alright, let’s assume that you have imported all of your GPOs and analyzed the result, and you know precisely which on-prem policies you will transition to Intune. What are your options, then? Well, before the migration option became available, you would have to search for an equivalent setting in the Endpoint Security blade, Settings Catalog, Administrative Template, or create a Custom profile, which can be a very time-consuming task. So, as mentioned in the introduction, we can now migrate imported GPOs to a Settings Catalog profile and assign "All device/All users" or a group to this profile directly from the Group Policy analytics (preview), which eases the burden a lot compared to doing it manually. Now, let’s take a closer look at this new migration option. Go to Click Devices | Group Policy analytics (preview)

Please carefully review your configuration on the Review + deploy page and click Deploy. Important note. Some settings don’t migrate exactly and may use different settings or values. – Read more

In this article, you learned how to use the new migration option within Group Policy analytics (preview) in Microsoft Endpoint Manager. This new possibility will, without a doubt, ease the burden of migrating on-prem policies to Intune. However, it’s not perfect, and you need to carefully review the settings you selected during the creation of the Settings Catalog profile. Read more at Microsoft docs about That’s it, folks. Happy testing! If you have any questions regarding this topic, please feel free to reach out to me.

exporting GPOs from Group Policy management on-prem using PowerShell and doing a proper cleanup with Microsoft Graph
Analyze on-premises GPOs with MEM Group Policy analytics (preview).
https://intune.microsoft.com
here
what you need to know.