You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/group-policy-analytics.md
+18-14Lines changed: 18 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,14 +1,14 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Use group policy analytics to import GPOs in Microsoft Intune
4
+
title: Use group policy analytics to import and analyze GPOs in Microsoft Intune
5
5
description: Import and analyze your group policy objects in Microsoft Intune and Endpoint Manager. See the policies that have the same Configuration Service Provider (CSP) setting in the cloud, and assign to your Windows 10/11 users and devices.
6
6
keywords:
7
7
author: MandiOhlinger
8
8
9
9
ms.author: mandia
10
10
manager: dougeby
11
-
ms.date: 01/19/2022
11
+
ms.date: 02/03/2022
12
12
ms.topic: how-to
13
13
ms.service: microsoft-intune
14
14
ms.subservice: configuration
@@ -33,9 +33,7 @@ ms.collection:
33
33
34
34
# Analyze your on-premises group policy objects (GPO) using Group Policy analytics in Microsoft Endpoint Manager - Preview
35
35
36
-
Group policy objects (GPOs) are used on-premises to configure settings on personal computers, and other on-premises devices. In device management, GPOs help control security and features in the Windows OS, Internet Explorer, Office apps, and more.
37
-
38
-
Many organizations are looking at cloud solutions to support the growing remote workforce. **Group Policy analytics** is a tool and feature in Microsoft Endpoint Manager that analyzes your on-premises GPOs. It helps you determine how your GPOs translate in the cloud. The output shows which settings are supported in MDM providers, including Microsoft Intune. It also shows any deprecated settings, or settings not available to MDM providers.
36
+
**Group Policy analytics** is a tool and feature in Microsoft Endpoint Manager that analyzes your on-premises GPOs. It helps you determine how your GPOs translate in the cloud. The output shows which settings are supported in MDM providers, including Microsoft Intune. It also shows any deprecated settings, or settings not available to MDM providers.
39
37
40
38
If your organization uses GPOs, and you want to move some workloads to Microsoft Endpoint Manager and Intune, then Group Policy analytics will help.
41
39
@@ -44,11 +42,16 @@ This feature applies to:
44
42
- Windows 11
45
43
- Windows 10
46
44
47
-
This article shows you how export your GPOs, import the GPOs into Endpoint Manager, and review the analysis and results.
45
+
This article shows you how export your GPOs, import the GPOs into Endpoint Manager, and review the analysis and results.
46
+
47
+
> [!TIP]
48
+
> Looking for information on ADMX templates? See [Use Windows 10/11 Administrative Templates to configure group policy settings in Microsoft Endpoint Manager](administrative-templates-windows.md).
48
49
49
50
## Prerequisites
50
51
51
-
Sign in as the Intune administrator with a role that has the **Security Baselines** permission. For example, the **Endpoint Security Manager** role has the **Security Baselines** permission. For more information on the built-in roles, see [role-based access control](../fundamentals/role-based-access-control.md).
52
+
- In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), sign in as the Intune administrator with a role that has the **Security Baselines** permission.
53
+
54
+
For example, the **Endpoint Security Manager** role has the **Security Baselines** permission. For more information on the built-in roles, see [role-based access control](../fundamentals/role-based-access-control.md).
52
55
53
56
## Export GPOs as an XML file
54
57
@@ -62,7 +65,9 @@ Sign in as the Intune administrator with a role that has the **Security Baseline
62
65
63
66
Be sure the file is less than 4 MB and has a proper unicode encoding. If the exported file is greater than 4 MB, then include fewer GPOs when you save your report from the GPMC.msc tool.
64
67
65
-
## Use Group Policy analytics
68
+
## Import GPOs and run analytics
69
+
70
+
Currently, this feature provides importing and analysis. In a future release (no ETA), you'll be able to create a policy based off your imported GPO, and deploy the policy.
66
71
67
72
1. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Group Policy analytics (preview)**.
68
73
2. Select **Import**, and then select your saved XML file. When you select the XML file, Intune automatically analyzes the GPO in the XML file.
@@ -76,7 +81,7 @@ Be sure the file is less than 4 MB and has a proper unicode encoding. If the exp
76
81
-**MDM Support**: Shows the percentage of group policy settings in the GPO that have the same setting in Intune.
77
82
78
83
> [!NOTE]
79
-
> Whenever the Microsoft Intune product team makes changes to the mapping in Intune, the percentage under MDM Support automatically updates to reflect those changes.
84
+
> Whenever the Microsoft Intune product team makes changes to the mapping in Intune, the percentage under MDM Support automatically updates to reflect those changes.
80
85
81
86
-**Unknown Settings**: Shows GPO settings that fall outside of the list of the Configuration Service Providers (CSPs) that this tool can parse.
82
87
-**Targeted in AD**: **Yes** means the GPO is linked to an OU in on-premises group policy. **No** means the GPO isn't linked to an on-premises OU.
@@ -96,8 +101,6 @@ Be sure the file is less than 4 MB and has a proper unicode encoding. If the exp
96
101
97
102
**No** means there isn't a matching setting available to MDM providers, including Intune.
98
103
99
-
For more information on device configuration profiles, see [Apply features and settings on your devices using device profiles](device-profiles.md).
100
-
101
104
-**Value**: Shows the value imported from the GPO. It shows different values, such `true`, `900`, `Enabled`, `false`, and so on.
102
105
-**Scope**: Shows if the imported GPO targets users or targets devices.
103
106
-**Min OS Version**: Shows the minimum Windows OS version build numbers that the GPO setting applies. It may show `18362` (1903), `17130` (1803), and other Windows client versions.
@@ -106,7 +109,7 @@ Be sure the file is less than 4 MB and has a proper unicode encoding. If the exp
106
109
107
110
-**CSP Name**: A Configuration Service Provider (CSP) exposes device configuration settings in Windows client. This column shows the CSP that includes the setting. For example, you may see Policy, BitLocker, PassportforWork, and so on.
108
111
109
-
For more information on CSPs, see the [CSP reference](/windows/client-management/mdm/configuration-service-provider-reference).
112
+
The [CSP reference](/windows/client-management/mdm/configuration-service-provider-reference) lists the available CSPs, shows the supported OS editions, and more.
110
113
111
114
-**CSP Mapping**: Shows the OMA-URI path for the on-premises policy. You can use the OMA-URI in a [custom device configuration profile](custom-settings-configure.md). For example, you may see `./Device/Vendor/MSFT/BitLocker/RequireDeviceEnryption`.
112
115
@@ -151,10 +154,11 @@ Currently, the Group Policy analytics (preview) tool only supports non-ADMX sett
151
154
> [!NOTE]
152
155
> After you add or remove your imported GPOs, it can take about 20 minutes to update the Migration Readiness reporting data.
153
156
154
-
155
157
## Send product feedback
156
158
157
-
You can provide feedback on Group Policy Analytics when you select **Got feedback**. Examples of feedback areas:
159
+
You can provide feedback on Group Policy Analytics. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Group Policy analytics (preview)** > **Got feedback**.
160
+
161
+
Examples of feedback areas:
158
162
159
163
- You received errors during GPO import or analytics, and you need more specific information.
160
164
- How easy is it to use Group Policy analytics to find the supported group policies in Microsoft Intune?
0 commit comments