Engineering
Pushing Configuration Profiles to Devices That Are Already Deployed
Getting settings onto a brand-new device is the easy part. Autopilot runs, policies land, everybody's happy. The harder part is changing something on the few hundred laptops that are already out there, in bags and on kitchen tables, and being sure it arrived.
That's what configuration profiles are for. You build the profile once, assign it to a group, and each device picks it up the next time it checks in with Intune. No reimage, no visit.
Pick the right kind of profile
Before you click anything, decide what you're configuring, because Intune has more than one place for settings:
- Settings catalog. This is where most new profiles should start. It's one searchable list of thousands of settings, and it's where Microsoft adds new ones first.
- Templates. Pre-built profiles for things like Wi-Fi, VPN, certificates and custom OMA-URI settings. Use these when the catalog doesn't cover what you need.
- Endpoint security. BitLocker, Defender Antivirus, firewall and attack surface reduction have their own policies under Endpoint security. You can configure some of these in a regular profile, but keeping security settings in one place makes conflicts much easier to spot later.
Create the profile
- Sign in to the Intune admin center. (It used to be the Microsoft Endpoint Manager admin center at endpoint.microsoft.com. Same service, new name.)
- Go to Devices > Configuration, then Create > New policy.
- Choose the platform, for example Windows 10 and later, and the profile type, usually Settings catalog.
- Give it a name you'll understand in two years. Something like
Win - Edge - Homepage and StartupbeatsTest policy 3. - Add your settings. In the catalog, use Add settings and search. Every setting has an info icon that explains what it really does, and it's worth reading.
- On Scope tags, add any you use to divide admin rights. If you don't use them, leave the default.
- On Assignments, add the groups it should apply to, plus any groups to exclude.
- Review and Create.
Get the assignment right
This is the step that decides whether the profile does what you meant.
User groups or device groups? A profile assigned to a user group follows that user to every device they sign in to. A device group sticks to the hardware no matter who's using it. For machine-wide settings, device groups are usually the safer choice.
Start small. Assign to a pilot group of a handful of devices first, ideally including your own. Wait a day, then widen it. Somebody's line-of-business app always has an opinion about your new setting.
Filters help. Assignment filters let you narrow a big group without building a new one, like "all users, but only on devices where the model starts with Surface".
When will it apply?
Devices check in with Intune roughly every eight hours, and more often right after enrollment. A new or changed policy also sends a notification that prompts devices to check in sooner. So most online devices pick up changes fairly quickly, and anything asleep or offline catches up next time it's on the network.
To hurry one along, open the device in Intune and click Sync. Or on the device itself, go to Settings > Accounts > Access work or school, select the account, then Info > Sync.
Make sure it landed
Open the profile and check its Device and user check-in status. You'll see counts for succeeded, failed, conflict, not applicable and pending. Click through to see individual devices, then per-setting status for the ones that failed.
Two results deserve extra attention:
- Conflict means another profile sets the same thing to a different value. Intune won't pick a winner for you. Find the other profile and decide which one owns the setting.
- Not applicable usually means the setting doesn't apply to that Windows edition or version. A setting that requires Enterprise does nothing on Pro, quietly.
Pending that stays pending for days usually means the device isn't checking in at all. That's an enrollment or connectivity problem, not a profile problem.