GuideInformationBusiness ContinuityIT

Plan the assignment handoff when updating an Intune baseline

What remains on the old profile when a current-format Intune security baseline is updated?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

What remains on the old profile when a current-format Intune security baseline is updated?

Potentially affected

Apply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.

DSE recommendation

Treat the new profile as a separate deployment object.

Source facts

For baseline profiles created in May 2023 or later, an Intune version update creates a separate latest-version profile rather than replacing the original. Existing setting customizations can be retained or discarded. Assignments and scope tags are not carried into the new profile automatically. The original retains its settings, tags, and assignments, so the deployment handoff must account for both instances. Microsoft Learn.

Applicability

Apply this workflow to current-format baseline updates, not the separate conversion procedure for profiles created before May 2023. Identify the original profile, desired new version, assignment groups, tags, and approved customizations before selecting the update option.

DSE recommendation

Treat the new profile as a separate deployment object. Record which customizations should survive, then explicitly review administrative visibility and target groups. Plan the old-to-new assignment transition with the policy owner so a name suggesting an upgrade does not obscure the still-assigned original. Preserve the original record until the handoff has been verified.

Verification

Inspect both profiles after creating the updated instance. Compare the intended retained or discarded settings and confirm the new tags and assignments deliberately. Pilot the new profile with the approved population, then reconcile old assignments before expanding. Verify the effective device configuration and check for overlapping policy ownership. Record both profile identifiers in the change record so later troubleshooting can distinguish the original deployment from its replacement.

Official references

Microsoft Learn: Configure security baseline policies in Microsoft Intune.

Primary reference

Review the official source

Configure security baseline policies in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE