Microsoft intune with domain joined computers

Porat Arzouan 21 Reputation points
2020-11-23T15:11:23.967+00:00

Hey everybody, I have got a question from my customer which I didn't find answer in Microsoft documents, so I hope I find it here from more experienced guys. If there is a computer enrolled with Intune and he is domain joined as well (I know its kinda contradict itself), and both of the them have password complexity policy (not windows hello from intune), Which one is overtaking over the other?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,893 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 48,581 Reputation points Microsoft Vendor
    2020-11-24T06:22:41.56+00:00

    @Porat Arzouan , Based as I know, windows 10 versions 1709 and earlier Group Policy will override MDM policies, even if an identical policy is configured in MDM. On Windows 10 version 1803 and beyond there is a new Policy CSP setting called ControlPolicyConflict that includes the policy of MDMWinsOverGP, where the preference of which policy wins can be controlled, i.e. Microsoft Intune MDM policy. We can see more details in the following link:
    https://video2.skills-academy.com/en-us/windows/client-management/mdm/policy-csp-controlpolicyconflict#controlpolicyconflict-mdmwinsovergp

    Meanwhile, share a link I find with a detailed description of this:
    https://www.anoopcnair.com/windows-10-mdm-csp-policies-override-group-policy-settings/
    Note: Non-Microsoft link, just for the reference.

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Jason Sandys 31,291 Reputation points Microsoft Employee
    2020-11-23T16:59:02.987+00:00

    I know its kinda contradict itself

    Not at all. This is perfectly valid.

    Which one is overtaking over the other?

    This is undefined and non-deterministic to my knowledge. The best path is to choose one or the other although keep in mind that the policy in Intune is for local device accounts only and does not impact domain accounts so they may not actually have a conflict here.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.