Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard

A company is migrating its device management from on-premises Active Directory Group Policy Objects (GPOs) to Microsoft Intune. They have a critical GPO that configures a specific security setting for Windows Firewall that is not available in the Intune Settings Catalog or as a standard device restriction. The GPO is based on a custom ADMX file. How should the administrator import and deploy this setting to Windows 11 devices using Intune?

  1. AUse a 'Custom' device configuration profile with OMA-URI settings derived from the ADMX file.
  2. BImport the ADMX file directly into the Intune Settings Catalog.
  3. CConvert the GPO to a Win32 app and deploy it via Intune.
  4. DManually create a PowerShell script to configure the setting and deploy it via Intune scripts.
Show answer & explanation

Correct answer: A. Use a 'Custom' device configuration profile with OMA-URI settings derived from the ADMX file.

When a setting from a custom ADMX file is needed and not available in the Settings Catalog, a 'Custom' device configuration profile using OMA-URI is the correct approach. Administrators can derive the OMA-URI path and value from the ADMX file to configure the setting.

Why the other options are wrong

  • B. The Intune Settings Catalog does not support direct import of custom ADMX files; it's a curated list of settings provided by Microsoft.
  • C. Converting a GPO to a Win32 app is not a standard or efficient way to deploy a single policy setting; Win32 apps are for full application deployments.
  • D. While a PowerShell script could potentially set the firewall rule, it's not the direct method for deploying ADMX-backed settings and might lack the declarative management benefits of a configuration profile.

Intune Custom ADMX Deployment (OMA-URI)

Deploying settings from custom ADMX files in Intune by creating a 'Custom' device configuration profile and manually mapping the ADMX settings to OMA-URI (Open Mobile Alliance Uniform Resource Identifier) paths.

  • Used for settings not available in standard Intune profiles or Settings Catalog.
  • Requires knowledge of ADMX structure and OMA-URI syntax.
  • Enables granular control over specific Windows policy settings.

Memory trick: ADMX to OMA-URI for custom settings, it's a mapping task.

More Manage devices and apps (55-60%) questions