# Do not transplant GPO precedence into Intune catalog assignments

> Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:16+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?

## Potentially affected

Apply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.

## DSE recommendation

Build a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles.

## Article

## Source facts

Microsoft’s comparison walkthrough explains that Intune assignments do not use the on-premises Group Policy hierarchy. Overlapping Intune policies can therefore produce a setting conflict rather than an organizational-unit override. The walkthrough distinguishes conflicting configuration profiles, whose setting is not applied, from conflicting compliance policies, where the stricter policy applies. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration).

## Applicability

Apply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.

## DSE recommendation

Build a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles. Ask the owner of each old exception to choose an explicit target design instead of relying on an inherited precedence assumption. Keep compliance-policy decisions separate from configuration-profile conflict handling. Use an isolated test group while the mapping is incomplete.

## Verification

Compare the intended setting with the corresponding catalog entry and review every assignment reaching the test identity or device. Exercise a representative exception as well as the ordinary population, then inspect the effective setting and conflict status. Record any unmapped setting rather than inventing an equivalent. Accept the migration only when the chosen assignment design explains both test results without depending on the former OU hierarchy.

## Official references

[Microsoft Learn: Walkthrough-Create a settings catalog policy](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration).

## Primary reference

- Name: Walkthrough-Create a settings catalog policy - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/tutorial-group-policy-migration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not transplant GPO precedence into Intune catalog assignments,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-340-do-not-transplant-gpo-precedence-into-intune-catalog-assignments/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
