{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
        "slug": "dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/"
        },
        "title": "Plan the assignment handoff when updating an Intune baseline",
        "summary": "What remains on the old profile when a current-format Intune security baseline is updated?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:24+00:00",
        "modified_at": "2026-09-10T00:55:35+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 233,
        "potentially_affected": "Apply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.",
        "dse_recommendation": "Treat the new profile as a separate deployment object.",
        "primary_source": {
            "name": "Configure security baseline policies in Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For baseline profiles created in May 2023 or later, an Intune version update creates a separate latest-version profile rather than replacing the original. Existing setting customizations can be retained or discarded. Assignments and scope tags are not carried into the new profile automatically. The original retains its settings, tags, and assignments, so the deployment handoff must account for both instances. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.</p>\n<h2>DSE recommendation</h2>\n<p>Treat the new profile as a separate deployment object. Record which customizations should survive, then explicitly review administrative visibility and target groups. Plan the old-to-new assignment transition with the policy owner so a name suggesting an upgrade does not obscure the still-assigned original. Preserve the original record until the handoff has been verified.</p>\n<h2>Verification</h2>\n<p>Inspect both profiles after creating the updated instance. Compare the intended retained or discarded settings and confirm the new tags and assignments deliberately. Pilot the new profile with the approved population, then reconcile old assignments before expanding. Verify the effective device configuration and check for overlapping policy ownership. Record both profile identifiers in the change record so later troubleshooting can distinguish the original deployment from its replacement.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure security baseline policies in Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nFor baseline profiles created in May 2023 or later, an Intune version update creates a separate latest-version profile rather than replacing the original. Existing setting customizations can be retained or discarded. Assignments and scope tags are not carried into the new profile automatically. The original retains its settings, tags, and assignments, so the deployment handoff must account for both instances. Microsoft Learn.\nApplicability\nApply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.\nDSE recommendation\nTreat the new profile as a separate deployment object. Record which customizations should survive, then explicitly review administrative visibility and target groups. Plan the old-to-new assignment transition with the policy owner so a name suggesting an upgrade does not obscure the still-assigned original. Preserve the original record until the handoff has been verified.\nVerification\nInspect both profiles after creating the updated instance. Compare the intended retained or discarded settings and confirm the new tags and assignments deliberately. Pilot the new profile with the approved population, then reconcile old assignments before expanding. Verify the effective device configuration and check for overlapping policy ownership. Record both profile identifiers in the change record so later troubleshooting can distinguish the original deployment from its replacement.\nOfficial references\nMicrosoft Learn: Configure security baseline policies in Microsoft Intune.",
        "content_markdown": "## Source facts\n\nFor baseline profiles created in May 2023 or later, an Intune version update creates a separate latest-version profile rather than replacing the original. Existing setting customizations can be retained or discarded. Assignments and scope tags are not carried into the new profile automatically. The original retains its settings, tags, and assignments, so the deployment handoff must account for both instances. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines).\n\n## Applicability\n\nApply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.\n\n## DSE recommendation\n\nTreat the new profile as a separate deployment object. Record which customizations should survive, then explicitly review administrative visibility and target groups. Plan the old-to-new assignment transition with the policy owner so a name suggesting an upgrade does not obscure the still-assigned original. Preserve the original record until the handoff has been verified.\n\n## Verification\n\nInspect both profiles after creating the updated instance. Compare the intended retained or discarded settings and confirm the new tags and assignments deliberately. Pilot the new profile with the approved population, then reconcile old assignments before expanding. Verify the effective device configuration and check for overlapping policy ownership. Record both profile identifiers in the change record so later troubleshooting can distinguish the original deployment from its replacement.\n\n## Official references\n\n[Microsoft Learn: Configure security baseline policies in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Plan the assignment handoff when updating an Intune baseline",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/",
                "headline": "Plan the assignment handoff when updating an Intune baseline",
                "description": "What remains on the old profile when a current-format Intune security baseline is updated?",
                "abstract": "What remains on the old profile when a current-format Intune security baseline is updated?",
                "articleBody": "Source facts\nFor baseline profiles created in May 2023 or later, an Intune version update creates a separate latest-version profile rather than replacing the original. Existing setting customizations can be retained or discarded. Assignments and scope tags are not carried into the new profile automatically. The original retains its settings, tags, and assignments, so the deployment handoff must account for both instances. Microsoft Learn.\nApplicability\nApply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.\nDSE recommendation\nTreat the new profile as a separate deployment object. Record which customizations should survive, then explicitly review administrative visibility and target groups. Plan the old-to-new assignment transition with the policy owner so a name suggesting an upgrade does not obscure the still-assigned original. Preserve the original record until the handoff has been verified.\nVerification\nInspect both profiles after creating the updated instance. Compare the intended retained or discarded settings and confirm the new tags and assignments deliberately. Pilot the new profile with the approved population, then reconcile old assignments before expanding. Verify the effective device configuration and check for overlapping policy ownership. Record both profile identifiers in the change record so later troubleshooting can distinguish the original deployment from its replacement.\nOfficial references\nMicrosoft Learn: Configure security baseline policies in Microsoft Intune.",
                "datePublished": "2026-09-10T00:29:24+00:00",
                "dateModified": "2026-09-10T00:55:35+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Plan the assignment handoff when updating an Intune baseline"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 233,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure security baseline policies in Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines"
                }
            }
        ]
    }
}