Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard
A company is migrating its device management from on-premises Active Directory Group Policy Objects (GPOs) to Microsoft Intune. They have a critical GPO that configures a specific security setting for Windows Firewall that is not available in the Intune Settings Catalog or as a standard device restriction. The GPO is based on a custom ADMX file. How should the administrator import and deploy this setting to Windows 11 devices using Intune?
- AUse a 'Custom' device configuration profile with OMA-URI settings derived from the ADMX file.
- BImport the ADMX file directly into the Intune Settings Catalog.
- CConvert the GPO to a Win32 app and deploy it via Intune.
- DManually create a PowerShell script to configure the setting and deploy it via Intune scripts.
Show answer & explanationAnswer & explanation
Correct answer: A. Use a 'Custom' device configuration profile with OMA-URI settings derived from the ADMX file.
When a setting from a custom ADMX file is needed and not available in the Settings Catalog, a 'Custom' device configuration profile using OMA-URI is the correct approach. Administrators can derive the OMA-URI path and value from the ADMX file to configure the setting.
Why the other options are wrong
- B. The Intune Settings Catalog does not support direct import of custom ADMX files; it's a curated list of settings provided by Microsoft.
- C. Converting a GPO to a Win32 app is not a standard or efficient way to deploy a single policy setting; Win32 apps are for full application deployments.
- D. While a PowerShell script could potentially set the firewall rule, it's not the direct method for deploying ADMX-backed settings and might lack the declarative management benefits of a configuration profile.
Intune Custom ADMX Deployment (OMA-URI)
Deploying settings from custom ADMX files in Intune by creating a 'Custom' device configuration profile and manually mapping the ADMX settings to OMA-URI (Open Mobile Alliance Uniform Resource Identifier) paths.
- Used for settings not available in standard Intune profiles or Settings Catalog.
- Requires knowledge of ADMX structure and OMA-URI syntax.
- Enables granular control over specific Windows policy settings.
Memory trick: ADMX to OMA-URI for custom settings, it's a mapping task.