Prevent Users from Changing Important Windows Device Settings using Intune

Key Takeaways

  • Turn On to show a simple Quick Settings layout.
  • Only basic controls will be available.
  • Turn Off or leave it Not Configured to use the normal layout.
  • The normal layout shows all Quick Settings options.

Hey, let’s discuss about how to Prevent Users from Changing Important Windows Device Settings using Intune. If you enable this policy, Quick Settings will show only the WiFi, Bluetooth, Accessibility, and VPN buttons, the brightness and volume sliders, the battery level, and a link to the Settings app. This provides a simpler Quick Settings panel with only the essential controls.

Table of Contents

Prevent Users from Changing Important Windows Device Settings using Intune

If you disable this policy or leave it unconfigured, Quick Settings will display its default layout whenever it is opened. Users will have access to the full set of Quick Settings tiles and controls instead of the simplified view.

How to Create a Policy

To configure this policy, first sign in to the Microsoft Intune Admin Center. Once you are signed in, navigate to Devices, then open the Configuration section. Click Create, and from the available options, select New policy to start creating and configuring the policy.

Configure Automatic Remediation for Windows Hotpatch Devices using Intune - Fig.1
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.1

Create a Profile

The next step in creating the policy is to create a profile. Select Windows 10 and later as the platform and choose Settings catalog as the profile type. After selecting these options, click Create to continue.

Patch My PC
Configure Automatic Remediation for Windows Hotpatch Devices using Intune - Fig.2
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.2

Basic Tab of Simplify Quick Settings Policy

To begin configuring the policy in Intune, start with the Basics step. Enter the policy name as Simplify Quick Settings and add a brief description(Load regular or simplify quick settings layout). The platform is already set to Windows. Click Next to continue.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.3
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.3

Configure Simplify Quick Settings

On the Configuration settings tab, click Add settings to open the Settings picker. From the available settings, select the start category or search Simplify Quick Settings on the search bar and choose the Simplify Quick Settings policy.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.4
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.4

Regular Quick Settings

After closing the Settings picker, the selected setting appears on the Configuration settings page. Here, the Simplify Quick Settings option is displayed with the default value set to Load regular Quick Settings layout. Keep the default value or select the required option, then click Next to continue.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.5
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.5

Simplified Quick Settings

You can change the Simplify Quick Settings option by clicking the drop-down menu. From the available options, select Load simplified Quick Settings layout . After selecting the option, verify the setting and click Next to continue with the policy configuration.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.6
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.6

What is Scope Tag

A Scope Tag in Intune is used to control the visibility and access of Intune resources based on administrative roles. Scope tags are optional. You can add a scope tag by clicking the Select scope tags button. Click Next to continue.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.7
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.7

Assignment Tab of Simplify Quick Settings Policy

On the Assignments tab, you can select the users or devices that will receive the policy. Under Include groups, click Add groups and choose the group from the list, such as HTMD – Test Policy. After selecting the group, click Next to continue.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.8
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.8

Final Step of Simplify Quick Settings Policy

At the final Review + Create step, review all the configured settings. If any changes are needed, click Previous to update them. Once everything is correct, click Create to finish. A notification will confirm that the Simplify Quick Settings created successfully.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.9
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.9

Device and User Check-in Status

We can check a policy’s status in the Intune Portal. Generally, it takes about 8 hours for policies to be created. Use the manual sync option to reduce the configuration delay in the Company Portal app on the device, then check the status again. Navigate to Devices> Configuration. Click on the Simplify Quick Settings policy to see its details.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.10
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.10

Client Side Verification

To confirm if a policy has been applied, use the Event Viewer on the client device. Go to Applications and Services Logs > Microsoft > Windows > Device Management > Enterprise Diagnostic Provider > Admin. Use the Filter Current Log option and search for Intune event 813.

MDM PolicyManager: Set policy int, Policy(SimplifyQuickSettings)Area: (Start), EnrollmentID
requesting merge: (EB427D85-802F-46D9-A3E2-D5B41458/F63), Current User: (Device), Int: (0x1),
Enrollment Type: (0x6), Scope: (0x0).

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.11
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.11

Windows Configuration Service Provider (CSP)

The policy Configuration Service Provider (CSP) is a tool for businesses to manage settings on Windows 10 and 11 devices. It details each policy’s function (Description Framework Properties) and how it relates to older Group Policy settings (Group Policy Mapping details) and allowed values.

Description Framework Properties

  • Format – Int
  • Access Type – Add, Delete, Get, Replace
  • Default Value – 0

Allowed Values

ValueDescription
0(Default)Load regular Quick Settings layout.
1Load simplified Quick Settings layout.
Prevent Users from Changing Important Windows Device Settings using Intune – Table.1

Group Policy Mapping Details

NameValue
NameSimplifyQuickSettings
Friendly NameSimplify Quick Settings Layout
LocationComputer Configuration
PathStart Menu and Taskbar
Registry Key NameSoftware\Policies\Microsoft\Windows\Explorer
Registry Value NameSimplifyQuickSettings
ADMX File NameStartMenu.admx
Allow or Block Search Engine Customization using Intune Policy – Table.2
Prevent Users from Changing Important Windows Device Settings using Intune - Fig.12
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.12

How to Remove Assigned Group from Simplify Quick Settings Policy

To remove a group from Simplify Quick Setting policy assignment for security updates, open the policy from the Configuration tab. Click Edit in the Assignment tab, select Remove to delete the group, and then click Review + Save to apply the changes.

For detailed information, you can refer to our previous post – Learn How to Delete or Remove App Assignment from Intune using by Step-by-Step Guide.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.13
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.13

How to Delete Simplify Quick Settings Policy from Intune

To delete an Intune policy for security or operational reasons. It is simple to do. I will demonstrate how to delete an Intune policy through the Simplify Quick Settings Policy. Click the three dots, then click the Delete option.

For detailed information, you can refer to our previous post How to Delete Allow Clipboard History Policy in Intune Step by Step Guide.

Prevent Users from Changing Important Windows Device Settings using Intune - Fig.14
Prevent Users from Changing Important Windows Device Settings using Intune – Fig.14

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows,  Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Leave a Comment