What's changed: Created MD-102 Chapter 2 (domain: Manage and maintain devices). Deploy Windows clients (Windows Autopilot deployment profiles/device preparation policies, modes user-driven/pre-provisioning/self-deploying, Enrollment Status Page, Windows 11 upgrades, Windows 365 Cloud PC, Windows Backup), configuration profiles (device configuration profiles, ADMX import, Group Policy analytics, specialty devices, assignment filters, enrollment time grouping), and Intune Suite/remote actions (EPM, Remote Help, Cloud PKI, Microsoft Tunnel, Advanced Analytics, remote actions retire vs wipe, rotate BitLocker keys, device query KQL).
2.2Configuration profiles
Understand device configuration profiles, ADMX import and Group Policy analytics, each platform (Windows/Android/iOS/macOS) and specialty devices, and assignment filters and enrollment time grouping.
Distribute device settings centrally via device configuration profiles. Different in purpose from compliance policies (which evaluate compliance).
2.2.1Profiles and GPO migration
Apply settings via device configuration profiles to Windows, Android, iOS/iPadOS, macOS, and specialty devices (Teams Rooms, HoloLens 2, Zebra). On Windows, import ADMX templates to use administrative-template settings, and Group Policy analytics analyzes existing on-prem GPOs to migrate them to Intune settings. Distinguish "distribute settings" = configuration profile from "evaluate compliance" = compliance policy.
2.2.2Targeting
Target profiles using assignment filters to narrow scope by attributes (OS version, ownership, model). Layered on group assignment, this gives finer control over where a profile applies. Use enrollment time grouping to group at enrollment for efficient first-time configuration.
Cues: "distribute settings to devices" = device configuration profile. "analyze on-prem GPOs to migrate to Intune" = Group Policy analytics. "ingest administrative-template settings" = ADMX import. "narrow assignment by attributes" = assignment filters. "evaluate compliance" = compliance policy (different). Teams Rooms/HoloLens are specialty devices.
Watch the mix-ups: (1) Configuration profile (distribute settings) vs compliance policy (evaluate compliance). (2) Group Policy analytics (GPO migration analysis) vs ADMX import (template ingestion). (3) Assignment filters (narrow by attributes) layer on top of group assignment for scope control.
2.2.3Section summary
- Device configuration profiles distribute settings to each platform/specialty devices
- Group Policy analytics migrates existing GPOs to Intune; ADMX import for template settings
- Assignment filters narrow assignment by attributes
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to analyze existing on-prem Group Policy (GPOs) to assess migration to Intune settings. Best?
Q2. You want to centrally distribute language/security settings to Windows devices from Intune. Best?
Q3. Within the same group, you want a profile to apply only to devices matching a specific OS version. Best?
Q4. You want to apply dedicated configuration to special devices like Teams Rooms and HoloLens 2. What are these called?
Q5. What correctly distinguishes a device configuration profile from a compliance policy?

