{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
        "slug": "dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/"
        },
        "title": "Do not transplant GPO precedence into Intune catalog assignments",
        "summary": "Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:16+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 221,
        "potentially_affected": "Apply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.",
        "dse_recommendation": "Build a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles.",
        "primary_source": {
            "name": "Walkthrough-Create a settings catalog policy - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s comparison walkthrough explains that Intune assignments do not use the on-premises Group Policy hierarchy. Overlapping Intune policies can therefore produce a setting conflict rather than an organizational-unit override. The walkthrough distinguishes conflicting configuration profiles, whose setting is not applied, from conflicting compliance policies, where the stricter policy applies. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.</p>\n<h2>DSE recommendation</h2>\n<p>Build a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles. Ask the owner of each old exception to choose an explicit target design instead of relying on an inherited precedence assumption. Keep compliance-policy decisions separate from configuration-profile conflict handling. Use an isolated test group while the mapping is incomplete.</p>\n<h2>Verification</h2>\n<p>Compare the intended setting with the corresponding catalog entry and review every assignment reaching the test identity or device. Exercise a representative exception as well as the ordinary population, then inspect the effective setting and conflict status. Record any unmapped setting rather than inventing an equivalent. Accept the migration only when the chosen assignment design explains both test results without depending on the former OU hierarchy.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Walkthrough-Create a settings catalog policy</a>.</p>",
        "content_text": "Source facts\nMicrosoft’s comparison walkthrough explains that Intune assignments do not use the on-premises Group Policy hierarchy. Overlapping Intune policies can therefore produce a setting conflict rather than an organizational-unit override. The walkthrough distinguishes conflicting configuration profiles, whose setting is not applied, from conflicting compliance policies, where the stricter policy applies. Microsoft Learn.\nApplicability\nApply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.\nDSE recommendation\nBuild a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles. Ask the owner of each old exception to choose an explicit target design instead of relying on an inherited precedence assumption. Keep compliance-policy decisions separate from configuration-profile conflict handling. Use an isolated test group while the mapping is incomplete.\nVerification\nCompare the intended setting with the corresponding catalog entry and review every assignment reaching the test identity or device. Exercise a representative exception as well as the ordinary population, then inspect the effective setting and conflict status. Record any unmapped setting rather than inventing an equivalent. Accept the migration only when the chosen assignment design explains both test results without depending on the former OU hierarchy.\nOfficial references\nMicrosoft Learn: Walkthrough-Create a settings catalog policy.",
        "content_markdown": "## Source facts\n\nMicrosoft’s comparison walkthrough explains that Intune assignments do not use the on-premises Group Policy hierarchy. Overlapping Intune policies can therefore produce a setting conflict rather than an organizational-unit override. The walkthrough distinguishes conflicting configuration profiles, whose setting is not applied, from conflicting compliance policies, where the stricter policy applies. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration).\n\n## Applicability\n\nApply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.\n\n## DSE recommendation\n\nBuild a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles. Ask the owner of each old exception to choose an explicit target design instead of relying on an inherited precedence assumption. Keep compliance-policy decisions separate from configuration-profile conflict handling. Use an isolated test group while the mapping is incomplete.\n\n## Verification\n\nCompare the intended setting with the corresponding catalog entry and review every assignment reaching the test identity or device. Exercise a representative exception as well as the ordinary population, then inspect the effective setting and conflict status. Record any unmapped setting rather than inventing an equivalent. Accept the migration only when the chosen assignment design explains both test results without depending on the former OU hierarchy.\n\n## Official references\n\n[Microsoft Learn: Walkthrough-Create a settings catalog policy](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not transplant GPO precedence into Intune catalog assignments",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/",
                "headline": "Do not transplant GPO precedence into Intune catalog assignments",
                "description": "Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?",
                "abstract": "Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?",
                "articleBody": "Source facts\nMicrosoft’s comparison walkthrough explains that Intune assignments do not use the on-premises Group Policy hierarchy. Overlapping Intune policies can therefore produce a setting conflict rather than an organizational-unit override. The walkthrough distinguishes conflicting configuration profiles, whose setting is not applied, from conflicting compliance policies, where the stricter policy applies. Microsoft Learn.\nApplicability\nApply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.\nDSE recommendation\nBuild a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles. Ask the owner of each old exception to choose an explicit target design instead of relying on an inherited precedence assumption. Keep compliance-policy decisions separate from configuration-profile conflict handling. Use an isolated test group while the mapping is incomplete.\nVerification\nCompare the intended setting with the corresponding catalog entry and review every assignment reaching the test identity or device. Exercise a representative exception as well as the ordinary population, then inspect the effective setting and conflict status. Record any unmapped setting rather than inventing an equivalent. Accept the migration only when the chosen assignment design explains both test results without depending on the former OU hierarchy.\nOfficial references\nMicrosoft Learn: Walkthrough-Create a settings catalog policy.",
                "datePublished": "2026-09-10T00:26:16+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not transplant GPO precedence into Intune catalog assignments"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 221,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Walkthrough-Create a settings catalog policy - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration"
                }
            }
        ]
    }
}