# Plan the assignment handoff when updating an Intune baseline

> What remains on the old profile when a current-format Intune security baseline is updated?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:24+00:00
- Modified: 2026-09-10T00:55:35+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What remains on the old profile when a current-format Intune security baseline is updated?

## Potentially affected

Apply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.

## DSE recommendation

Treat the new profile as a separate deployment object.

## Article

## Source facts

For baseline profiles created in May 2023 or later, an Intune version update creates a separate latest-version profile rather than replacing the original. Existing setting customizations can be retained or discarded. Assignments and scope tags are not carried into the new profile automatically. The original retains its settings, tags, and assignments, so the deployment handoff must account for both instances. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines).

## Applicability

Apply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.

## DSE recommendation

Treat the new profile as a separate deployment object. Record which customizations should survive, then explicitly review administrative visibility and target groups. Plan the old-to-new assignment transition with the policy owner so a name suggesting an upgrade does not obscure the still-assigned original. Preserve the original record until the handoff has been verified.

## Verification

Inspect both profiles after creating the updated instance. Compare the intended retained or discarded settings and confirm the new tags and assignments deliberately. Pilot the new profile with the approved population, then reconcile old assignments before expanding. Verify the effective device configuration and check for overlapping policy ownership. Record both profile identifiers in the change record so later troubleshooting can distinguish the original deployment from its replacement.

## Official references

[Microsoft Learn: Configure security baseline policies in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines).

## Primary reference

- Name: Configure security baseline policies in Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/security-baselines/configure-baselines
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan the assignment handoff when updating an Intune baseline,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-152-plan-the-assignment-handoff-when-updating-an-intune-baseline/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
