1 min read

Intune – Use the Group Policy Analytics report to prepare the migration of your GPO to Endpoint Configuration Manager MDM

For years, IT administrators have been using group policy objects (GPO) – and still continue today – to manage/configure devices, both clients and servers.

With the move to a cloud-based devices management, the need to replicate as much as possible settings set using GPO is more and more relevant.

To help you prepare moving from GPO based to MDM policies based, you can use the Group Policy Analytics report available from the Intune/Endpoint Configuration Manager portal.

To start analyzing your GPO settings to find which settings can be implemented using Endpoint Configuration Manager MDM start by logging on on a device with the Group Policy Management console to export the GPO report and save it as XML file

image_thumb

Then connect to your Endpoint Configuration Manager portal (https://endpoint.microsoft.com/) and access the DevicesGroup Policy Analytics blade to import the XML file generated above

NOTE the XML file to be imported can not be bigger than 1 Mb

image_thumb[1]  image_thumb[2]  image_thumb[3]  image_thumb[4]

You can import more than one XML file by repeating the above steps as many times as you need.

Once the import is completed, refresh the blade to view the list of imported GPO, showing the name of the GPO, percentage of coverage with MDM

image_thumb[5]

Then by hitting the MDM percentage support you will get details about what is supported or not by Endpoint Configuration Manager MDM, when supported you will get the minimum OS version and the Configuration Service Provider (CSP) mapping (either policy, Bitlocker, Passport for Works (aka Windows Hello), Firewall or AppLocker CSP)

image_thumb[6]

If you have imported more than one GPO report, you can have a global report by accessing the ReportsGroup Policy Analytics blade

image_thumb[7]

Intune – You can now monitor your Windows Defender devices from the portal

As you know, you can manage Windows Defender settings by creating device configuration profiles using Intune/Endpoint Configuration Manager,...

Read More

Intune – Deploy printers used with Universal Print with Intune/Endpoint Configuration Manager

As you may know, a new service called Universal Print has been released in preview allowing you replacing your on-premises print servers (see ...

Read More

Intune – New security focused policies available in preview

As you know, Intune/Endpoint Configuration Manager allows you to define policies to managed devices configuration and security settings.

Read More