Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy

In my previous post (Group Policy Vs. Intune Policy), we discussed how Intune policy wins over GP when there is a policy conflict. We covered the workflow with an example setting (IE Home Page).

This post will show how Windows 10 handles conflicting GP settings if Intune is unenrolled from the Windows 10 computer.

I try to explain the policy workflow after removing Intune management from a Windows 10 machine via Registry and Event Logs. Review the post for more details about workflow, testing, and research.

In this post, you will get all the details of the Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy. When a device is unenrolled from Microsoft Intune, its impact on policies varies depending on whether it was deployed via Intune or Group Policy.

Patch My PC

Intune policies, which are applied through mobile device management (MDM), typically get removed from the device upon enrollment.

Workflow – Group Policy Vs. Intune Policy – Intune Unenrollment

I turned off the “Mdmwinovergp” registry. Now, the machine understands Intune MDM policy will not win over GP.

Adaptiva
  • Computer\HKEY_LOCAL_MACHINE_Microsoft\PolicyManager\current\device\ControlPolicyConflict
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.1
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.1

Evaluate if any GP blocking record has been created.

  • Found existing blocking records. Re-evaluating
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.2
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.2

I identified a block record for the IE Home Page setting. In the previous post, we discussed how GP block records are created when there is a policy conflict.

  • I found a blocking record reg key that needs to be deleted. The Parent Key is (Software/Policies/Microsoft/MicrosoftEdge/Internet Settings), and the Child key is (ProvisionedHomePages).
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.3
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.3

GP value restored from Registry backup. In the previous post, we saw how Intune backs up GP settings during policy conflicts.

  • Attempted to restore GP Value. GP Location: (Software/Policies/Microsoft/MicrosoftEdge/Internet Settings), GP ValueName: (ProvisionedHomePages), Result: (The operation completed successfully.).
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.4
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.4

The blocking record was deleted.

  • I am trying to delete the blocking record reg key. Key: (ProvisionedHomePages), Level: (0x3), Result:(The operation completed successfully.). Failures are expected if this key has child nodes.
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.5
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.5

Block record registry key deleted.

  • I’m trying to delete the blocking record reg key. Key: (Software/Policies/Microsoft/MicrosoftEdge/Internet Settings), Level: (0x2), Result:(The operation completed successfully.). Failures are expected if this key has child nodes.
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.6
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.6

After registry key deletion. There are no block records inside the registry hive “MDMWins.”

  • Computer\HKEY_LOCAL_MACHINE\Software\Microsoft\MDMWins
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.7
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.7

Verifies whether all conflicting GP settings are unblocked. At last, Intune, the policy was removed, and all the GP settings were applied back

  • All GP locations that were to be unblocked have been unblocked successfully. Forced? : (0x1)
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy - Fig.8
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Fig.8

Additional Tips

MDM CSP (Configuration Service Provider) is an interface in the client operating system between configuration settings specified in a provisioning document and configuration settings on the device. It is the primary management channel for AAD Joined Devices.

Microsoft provides options to configure Windows 10 settings via traditional management via WMI bridge and WMI provider.

Common Device Configurator helps devices automatically resolve conflicts and select the best-secured policy. The segregation of Intune policies depends on the complexity of implementation.

Additional Tips
Out-of-box Intune console (easy)
Custom CSP > OMA – URI (medium)
ADMX files (complex)
Group Policy Vs Intune Policy after Intune Unenrollment Microsoft Intune Policies AD Group Policy – Table 1

References

  1. Microsoft. https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-controlpolicyconflict#controlpolicyconflict-mdmwinsovergp

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Vimal has more than 10 years of experience in SCCM device management solutions. His primary focus is Device Management technologies like Microsoft Intune, ConfigMgr (SCCM), OS Deployment, and Patch Management. He writes about technologies like SCCM, Windows 10, Microsoft Intune and MDT.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.