maciejrebisz.com

IT

How to control both MDM and GPO settings on Windows 10 – Mobile-First Cloud-First

maximios October 17, 2021

Windows 10 has the possibility to be member of a on-prem active directory domain and MDM managed with Intune. Before Windows 10 1709 it was a manual process to get Windows 10 domain joined devices under MDM management, with the 1709 release Microsoft has created a GPO setting that allows hybrid joined devices to be automatic MDM enrolled. This is pretty cool for now it is useful in many scenarios, like Co-management or light way management of Windows 10 for companies that is on the cloud journey.  The MDM auto enrollment has been available for AzureAD joined devices since the first release of Windows 10.

With the next major Windows 10 update there will be a new settings – I have tested this with Windows 10 insider build 17093, In this blog post I will walk through the new feature. When we are using this new MDM we can control the MDM settings always wins over the same settings coming from a GPO.

Before you begin you need this setup:

  • Windows 10 hybrid AzureAD joined devices
  • Windows insider build 17093 or later
  • Automatic MDM enrollment GPO deployed
  • Intune and AzureAD licens for the user

How to setup Control Policy Conflict:

First you need to create a Windows 10 custom Device configuration profile in Intune.

Name: ControlPolicyConflict/MDMWinsOverGP

Description:

1 – The MDM policy is used and the GP policy is blocked.

OMA-URI:

./Vendor/MSFT/Policy/Config/ControlPolicyConflict/MDMWinsOverGP

Data Type:

Integer

Value:

1

The supported value is: 0 (default)

1 – The MDM policy is used and the GP policy is blocked.

The policy should be set at every sync to ensure the device removes any settings that conflict with MDM just as it does on the very first set of the policy. This ensures that:

  • GP settings that correspond to MDM applied settings are not conflicting
  • The current Policy Manager policies are refreshed from what MDM has set
  • Any values set by scripts/user outside of GP that conflict with MDM are removed

Where can we deploy this new policy:

How does it look from the client-side:

In the settings app under Managed by. we can seethe new COntrolPolicyConflict area

When we are creating a advanced diagnostic report we can see more detailed which Group Policy that has been blocked.

From Windows 10 insider build 17115 this is showing up in the MDMDiagReport so now we can see what MDM settings and what GPO settings gets applied on the device.

More information:

How to configure hybrid Azure Active Directory joined devices

Policy CSP – ControlPolicyConflict

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ How to upgrade Windows 10 1607 with SCCM 1606 (Inplace Task Sequence) – Mobile-First Cloud-First › How to auto assign Windows Autopilot profiles in Intune – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes