Group Policy to Intune: Group Policy Analytics, the Settings Catalog, and the Policies That Do Not Translate
Most 20–500-seat organizations that move their Windows devices to Intune arrive with somewhere between 30 and 150 Group Policy Objects, many older than the people who now manage them. The migration is not a copy. Some settings translate one to one into the Intune settings catalog, some become endpoint security policies, some become scripts, and some should be dropped. This guide covers Group Policy analytics, the four buckets every setting lands in, the deployment order, coexistence while both engines apply, and the settings that have no MDM equivalent.
Why this is a translation, not a copy
Group Policy is evaluated by a domain-joined computer against the organizational units it sits in. Intune policy is evaluated by the device's MDM client against the Windows configuration service providers (CSPs) and targeted at Entra ID groups and filters. Three consequences follow.
First, a setting exists in Intune only if Windows exposes it through a CSP. The settings catalog is built from those CSPs and includes the ADMX-backed templates for Windows, Office and Edge, plus custom ADMX files you import. It is broad, but it is not a mirror of every Group Policy template ever written.
Second, Group Policy Preferences (drive maps, printers, scheduled tasks, shortcuts, registry items) were never policies in the CSP sense. They have to be re-implemented, usually as scripts or apps.
Third, targeting changes. OU links, security filtering, WMI filters and loopback processing become group assignments and Intune filters, and the groups have to exist first.
Plan the migration as a re-authoring exercise, not an import.
Step one: export the GPOs and run Group Policy analytics
Group Policy analytics lives in the Intune admin center under Devices. The workflow, from Microsoft's documentation as updated in June 2026:
- In the Group Policy Management Console, right-click each GPO, choose Save report, and save it as an XML file. A single file must be under 4 MB.
- In Intune, select Import, pick one or more XML files, assign a scope tag if you use them, and create. Analysis runs on its own.
- Open the report. For each GPO, Intune shows the share of settings that have an equivalent in Intune, and for each setting: whether MDM supports it, the imported value, the scope (device or user), the minimum Windows version, the CSP name and the OMA-URI.
- Each setting carries a status: Ready for migration, Not supported, or Deprecated.
Two limits matter. Analytics reads the Policy, PassportForWork, BitLocker, Firewall and AppLocker CSPs and does analyze Group Policy Preferences, but it supports non-ADMX settings only in English. And the report tells you whether a setting exists in Intune, not whether you still need it.
Before you import, prune: delete unlinked and disabled GPOs and merge duplicates. Every GPO you retire before analysis is one you never have to translate.
Step two: put every setting in one of four buckets
Work through the analytics report with the owner of each GPO and label every setting.
Bucket A, settings catalog. The setting is Ready for migration. Use the Migrate action: tick the GPOs, choose the settings, review the values, name the profile, assign it to a group. Where the same setting appears in several GPOs with different values, Intune stops you until you choose one. Some settings map to an alternate setting with a similar effect rather than the identical one, which Microsoft says is common with older Office and Chrome templates.
Bucket B, endpoint security policy or baseline. Firewall rules and AppLocker rules appear in analytics, but the migrate wizard will not move them; Microsoft points you to the Endpoint security firewall policy and to application control instead. BitLocker, Defender antivirus, attack surface reduction, account protection and local administrator password settings also belong here. Microsoft's security baselines for Windows, Edge, Microsoft 365 Apps and Defender for Endpoint are a sound starting point.
Bucket C, no MDM equivalent. Drive maps, printer maps, logon scripts, scheduled tasks, shortcuts and most other preferences. These become platform scripts, remediation scripts, Win32 apps, or a different product feature: Universal Print, OneDrive Known Folder Move, Windows LAPS, Cloud PKI. The table at the end lists the common ones.
Bucket D, drop. Internet Explorer settings, Windows 7-era hardening, settings whose owner cannot say what they do, and anything a baseline already covers. In our migrations roughly a third of imported settings end up here.
Step three: the deployment order and the test rings
The order matters because later layers depend on earlier ones.
- Groups and filters. Create the device groups and Intune filters you will assign to before any policy exists.
- Compliance policies. Conditional Access reads device compliance, so compliance comes first: BitLocker on, Defender running, a minimum OS build, a grace period. Keep the Conditional Access rule in report-only mode while devices enroll; the policies to start with are in Conditional Access policies every business should have.
- Endpoint security: the Windows baseline, Defender for Endpoint onboarding, firewall, disk encryption and LAPS. These are the settings you cannot afford to have missing while both engines apply.
- Settings catalog profiles migrated from Bucket A, one profile per former GPO purpose rather than one giant profile.
- Apps and scripts: the Bucket C replacements, and Win32 packages that replace GPO software installation.
- Update rings or Windows Autopatch, replacing WSUS Group Policy.
Test in rings. Ring 0 is the IT team's own devices for a week. Ring 1 is one department for two weeks. Ring 2 is everyone else, in batches sized to what the help desk can absorb. Provisioning new devices with Autopilot is a separate track, covered in our Windows Autopilot prerequisites and setup and zero-touch deployment articles.
Coexistence: who wins when both apply
During the migration most devices are hybrid joined: domain-joined and enrolled in Intune at the same time. They process Group Policy and MDM policy. By default, when the same setting is configured in both and the values conflict, Group Policy wins.
Windows has a switch, MDMWinsOverGP in the ControlPolicyConflict area of the Policy CSP. Set to 1 through a settings catalog or custom profile, the MDM value wins and the conflicting Group Policy value is blocked. Two caveats, as reported in community write-ups of Microsoft's CSP documentation (we could not open Microsoft Learn from our environment; verify there): the switch applies only to settings in the Policy CSP, not to settings in other CSPs such as the Defender CSP, and it does not cover every Group Policy setting.
The cleaner approach is to avoid the conflict. As each ring's Intune policy is verified, unlink the corresponding GPO from that ring's OU. Entra joined devices never process Group Policy at all, which is one of the arguments for the cloud-only path in retiring on-premises Active Directory.
A Conflict state in the per-setting reports usually means two Intune profiles disagree, not Intune versus Group Policy; consolidate the profiles.
Licensing, effort and where we fit
Intune Plan 1 is included in Microsoft 365 Business Premium and Microsoft 365 E3, and is sold on its own at $96.00 per user per year, an $8.00 per month equivalent (Microsoft list price, September 2026 price list; see Microsoft Intune Plan 1). Nothing here needs the Intune Suite except Microsoft Cloud PKI, if you use it to replace AD CS auto-enrollment. Our Intune licensing explainer covers what Business Premium, E3, E5 and F3 already include.
Effort scales with GPO count and with Bucket C. A 60-device firm with 25 GPOs of Windows hardening and Office settings is a two- to three-week project. A 300-device firm with 120 GPOs, drive maps for six offices and logon scripts nobody wrote down is closer to eight weeks.
Our Microsoft Intune Initial Setup for Windows Device Management ($6,500 per project, 8 weeks) covers the tenant setup, compliance, baselines, the analytics pass and the migration of Buckets A and B; Bucket C scripting is scoped once the inventory exists.
Frequently asked questions
Can Intune replace Group Policy completely?
For workstations, yes for policy, with scripts and apps filling the gaps left by preferences. Not for servers: Intune does not manage Windows Server, so GPOs that target servers stay with the domain controllers.
Does Group Policy analytics migrate GPOs automatically?
No. It analyzes an exported XML report and, for settings marked Ready for migration, creates a settings catalog profile with the values you select. Firewall and AppLocker rules are excluded, preferences are not migrated, and you still assign and test the result.
What happens to Group Policy on hybrid joined devices after Intune is set up?
It keeps applying. If a setting is in both, Group Policy wins by default unless MDMWinsOverGP is set for that Policy CSP setting. The end state is to unlink the GPOs ring by ring and to move new devices to Entra join.
How long does a GPO to Intune migration take?
Two to three weeks for about 25 GPOs with no drive maps or scripts to rebuild. Six to ten weeks for 100 or more GPOs across several offices, because scripts have to be written, signed and tested per ring.
Do I need Intune Plan 2 or the Intune Suite for this?
No. Group Policy analytics, the settings catalog, security baselines, endpoint security policies, LAPS, platform scripts and remediations are all in Intune Plan 1.
Sources
- Microsoft Learn source files on GitHub (MicrosoftDocs/memdocs), opened: "Use Microsoft Intune to import and analyze group policies", ms.date 06/22/2026; "Migrate your imported group policy to a policy in Microsoft Intune", ms.date 02/20/2025; Intune "Security baselines overview", ms.date 06/09/2026; "Use ADMX templates on Windows devices", ms.date 09/25/2025
- Microsoft Learn source files on GitHub, opened: "Overview of Windows LAPS with Microsoft Intune", ms.date 05/29/2025; "Configure Universal Print policy", ms.date 05/13/2026; "Microsoft Cloud PKI fundamentals", ms.date 12/06/2024
- Microsoft Learn: "ControlPolicyConflict Policy CSP" (MDMWinsOverGP), as reported by HTMD Blog, "MDM Wins Over GPO", and search results on 27 September 2026; not opened; verify on Microsoft Learn
- IT Partner blog: content/blog/new/intune-licensing-plan-1-vs-plan-2-vs-intune-suite-remote-help-epm.json; conditional-access-policies-every-business-should-have.json; refreshed Autopilot and zero-touch articles
- IT Partner pages: content/services/ITPWW310IMPOT, ITPWW350MSPRC and ITPWW080SECOT; Microsoft Intune Plan 1 (CFQ7TTC0LCH4)
- IT Partner engineering notes from Intune migrations, September 2026
| Group Policy setting or preference | In Intune (mid-2026) | What to do instead |
|---|---|---|
| Drive mappings | No native policy | User-context script, or move the share to SharePoint, OneDrive or Azure Files |
| Printer deployment | No native policy | Universal Print policy (needs a Universal Print license), or a script |
| Folder redirection | No equivalent | OneDrive Known Folder Move |
| Logon scripts, scheduled tasks, shortcuts, files | No equivalent | Platform script, remediation script or Win32 app |
| Registry items (preferences) | Partial | Settings catalog if a CSP exists; otherwise a script |
| Local users and groups | Partial | Account protection policy; Windows LAPS for the local admin password |
| Software installation (MSI) | No equivalent | Win32 apps or line-of-business apps |
| WSUS settings | Replaced | Update rings or Windows Autopatch |
| Windows Firewall and AppLocker rules | Analyzed, not migrated | Endpoint security firewall and application control policies |
| AD CS certificate auto-enrollment | No equivalent | SCEP or PKCS with a connector, or Cloud PKI (Intune Suite) |
| Internet Explorer settings | Deprecated | Drop; Edge policies if IE mode is still needed |
| Loopback, WMI filters, security filtering | No equivalent | Device or user scope, Entra groups, Intune filters |
| Advanced audit policy, legacy security options | Mostly present | Settings catalog; verify each setting name |
Key takeaways
- Group Policy analytics tells you which GPO settings have an Intune equivalent; it does not decide what you still need, and it will not migrate firewall rules, AppLocker rules or preferences.
- Sort every setting into four buckets: settings catalog, endpoint security or baseline, script or app, or drop. About a third of a typical tenant's settings belong in the last bucket.
- Deploy in order: groups and filters, compliance, endpoint security, configuration profiles, apps and scripts, update rings. Test in three rings.
- While devices are hybrid joined, Group Policy wins conflicts by default; MDMWinsOverGP flips that only for Policy CSP settings. Unlink GPOs ring by ring instead.
- Drive maps, printers, folder redirection, logon scripts and scheduled tasks are the usual gaps; they become scripts, Known Folder Move, Universal Print, or a reason to retire the file server.
If you want the analytics pass, the bucket sort and the Intune build done by people who have done it before, Microsoft Intune Initial Setup for Windows Device Management is $6,500 per project over 8 weeks, fixed price, paid after approval. Managed Microsoft Intune Service ($5 per device, monthly) keeps baselines and policies current afterwards, and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices ($3,500 per project, 15 days) is the usual next step. Book a call with your GPO count and we will scope it.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.