Resource Categories
Configuration Policies
Device settings and configurations
Compliance Policies
Device compliance requirements
Windows Updates
Update rings and driver updates
Device Enrollment
Enrollment policies and configurations
Platform Support
| Platform | Configuration | Compliance | Updates | Enrollment |
|---|---|---|---|---|
| Windows | ✓ | ✓ | ✓ | ✓ |
| macOS | ✓ | ✓ | ✓ | ✓ |
| iOS/iPadOS | ✓ | ✓ | - | ✓ |
| Android | ✓ | ✓ | - | ✓ |
| Linux | ✓ | ✓ | - | - |
Quick Start
Windows Compliance Policy
Settings Catalog Configuration
Common Scenarios
Enforce device compliance
Enforce device compliance
Create compliance policies to ensure devices meet your security requirements before accessing corporate resources.
- Minimum OS versions
- Encryption requirements
- Password policies
- Security features (firewall, antivirus)
Deploy configuration profiles
Deploy configuration profiles
Use configuration policies to standardize device settings:
- Wi-Fi and VPN configurations
- Email profiles
- Certificate deployment
- Security baselines
Manage Windows Updates
Manage Windows Updates
Control update deployment timing and behavior:
- Update rings for different user groups
- Deferral periods for testing
- Maintenance windows
- Feature update controls
Configure device enrollment
Configure device enrollment
Customize the enrollment experience:
- Enrollment restrictions
- Auto-enrollment settings
- Terms and conditions
- Branding and customization
Policy Assignment
Most device management policies support flexible assignment:Advanced Features
Endpoint Privilege Management
Control elevation of privileges on Windows devices:App Control for Business
Manage application control policies:Remediation Scripts
Deploy PowerShell scripts for device remediation:Role-Based Access Control
Manage Intune RBAC permissions:Best Practices
Start with compliance policies
Define compliance requirements before deploying configuration policies to ensure devices meet minimum standards.
Use pilot groups for testing
Test new policies with pilot groups before broad deployment to identify issues early.
Monitor compliance status
Regularly review compliance reports to identify non-compliant devices and take corrective action.
Document your policies
Maintain documentation of policy intent, settings, and assignment targets for operational clarity.
Next Steps
Configuration Policies
Create device configuration policies
Compliance Policies
Define compliance requirements
Windows Updates
Manage Windows Update deployment
Enrollment
Configure device enrollment
