GuideInformationBusiness ContinuityIT

Do not transplant GPO precedence into Intune catalog assignments

Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

Will recreating an ADMX setting in Intune also recreate its old Group Policy precedence?

Potentially affected

Apply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.

DSE recommendation

Build a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles.

Source facts

Microsoft’s comparison walkthrough explains that Intune assignments do not use the on-premises Group Policy hierarchy. Overlapping Intune policies can therefore produce a setting conflict rather than an organizational-unit override. The walkthrough distinguishes conflicting configuration profiles, whose setting is not applied, from conflicting compliance policies, where the stricter policy applies. Microsoft Learn.

Applicability

Apply this check when translating a Windows ADMX-based configuration into settings-catalog assignments. Treat the walkthrough as a comparison exercise, not authorization to copy its example groups or settings into production.

DSE recommendation

Build a setting-by-setting migration map that records the intended value, user or device scope, target population, and overlapping Intune profiles. Ask the owner of each old exception to choose an explicit target design instead of relying on an inherited precedence assumption. Keep compliance-policy decisions separate from configuration-profile conflict handling. Use an isolated test group while the mapping is incomplete.

Verification

Compare the intended setting with the corresponding catalog entry and review every assignment reaching the test identity or device. Exercise a representative exception as well as the ordinary population, then inspect the effective setting and conflict status. Record any unmapped setting rather than inventing an equivalent. Accept the migration only when the chosen assignment design explains both test results without depending on the former OU hierarchy.

Official references

Microsoft Learn: Walkthrough-Create a settings catalog policy.

Primary reference

Review the official source

Walkthrough-Create a settings catalog policy - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE