Event details
Our organization is trying to transition from ConfigManager/SCCM to Intune. We are currently using Hybrid with a large (many domain) ADFS AAD setup. We currently harden via GPO on each domain. My goal is to be able to deploy policy via Intune instead of domain GPO, but it seems Intune is still in Preview and lacking policy support in MDM. As an example, CIS is our Organizations security standard, 70-90 policies are not supported in Intune MDM when importing a CIS benchmark. Word is you can setup OMA-URI custom, manual settings. Is there a way to confirm the accuracy of these strings? Is Intune still being expanded for MDM to cover all of the unsupported/missing policies? Thanks!
- Joe_LurieOct 24, 2022
Microsoft
Without knowing what the 70-90 settings are, I can't give a recommendation on using OMA-URI to set them. But Settings Catalog is in GA (no Preview), and we are constantly adding settings to it. But again, without know what settings you're looking for, I can't really give more advice. Note that some of those settings may never be translated to Intune - settings that include the word "Domain" or "Kerberos" as these are on-prem domain terms, and cloud-only devices are managed differently. Or some may be in a different spot in Intune - Firewall settings are not in Settings Catalog, but are in the Security node; Password policies are in Azure, since that's where user accounts live. So, it's possible that at least some of these settings are there but in a different spot than you'd expect, or aren't necessary on a cloud-first device. - RickClark2Oct 24, 2022Copper Contributor
This is our biggest blocker to moving to AADJ. Would be great if MSFT has an official response. Joe_Lurie or Matthew_Palko , any help?
- UniverseCitiz3nOct 24, 2022Copper ContributorI've heard from Customer Success Team that we can provide list of settings from GPO that are not yet supported via MDM and it should be covered in some unknown future. On the other hand, when I've raised support ticket I end-up with recommendation to deploy PowerShell script that will implement that part of CIS which had issue. The last thing is reporting of CIS implementation on the endpoint. In GPO recommendation document there are reg keys for polices from GPO, and Intune MDM caches settings in PolicyManager key so if there is an automated/ semi-automated audit that will check for reg keys based on GPO doc you will probably fail
- gatewood502Oct 24, 2022Brass Contributor
Intune has Group Policy Analytics that lets you upload your GPO, compare it to Intune policy, and even convert it to an Intune policy