Templates or the settings catalog. Choosing wrong once produces an estate nobody can audit three years later.
Templates group settings around a concept such as email, kiosk or firmware. The settings catalog lists every available setting in one place, and Microsoft describes it as similar to Group Policy but cloud native, with thousands of Windows settings including many the templates never had. Two templates are already deprecated for new policies.

- Two policy typesTemplates, or the settings catalog
- Four platformsWindows, macOS, iOS and iPadOS, Android
- Two deprecatedEndpoint protection and Extensions templates
- Conflict viewWhich profiles caused a conflicting setting
Seven things that decide whether your profile estate stays maintainable.
The settings catalog is the cloud-native Group Policy
Microsoft describes the settings catalog as listing all the settings you can configure in one place, not a template or a logical grouping, and as similar to configuring on-premises Group Policy Objects but cloud native. On Windows there are thousands of settings available, including many not found in the templates, which is why a complete configuration usually needs it.
Templates group settings around a concept
Templates include a logical grouping of settings that configure a feature or concept, with Microsoft naming email, kiosk devices and device firmware as examples, plus templates covering resource access such as virtual private network and Wi-Fi, and security such as antivirus, firewall and certificates. Where a template exists and fits, it is simpler than assembling the same result from the catalog.
Two templates are already closed to new policies
The Endpoint protection template and the Extensions template were both deprecated in the August 2024 service release. Microsoft states existing policies continue to work but you cannot create new policies using them, directing you to the settings catalog instead for the FileVault, Firewall and System Policy Control payloads and for System Extensions. Estates built on those templates need a migration plan.
Resource access profiles are what users actually notice
Wi-Fi profiles give users corporate wireless without configuring it themselves. Virtual private network profiles do the same for remote access. Email profiles create and monitor Exchange ActiveSync settings, which Microsoft notes helps with consistency, reduces support calls, and lets users access company email on personal devices without any setup on their part.
Certificates, so nobody types a password into a network prompt
Certificates authenticate users so they can reach applications and corporate resources through virtual private network, Wi-Fi or email profiles without entering usernames and passwords. Microsoft names trusted root, Simple Certificate Enrolment Protocol and Public Key Cryptography Standards certificates as the common types, and they are also used for signing and encrypting email.
Scripts, for everything the settings cannot express
PowerShell scripts on Windows through the Intune Management Extension, shell scripts on macOS, and existing Bash scripts on Linux, which Microsoft describes as similar to a custom configuration profile for settings not built into Intune. Custom profiles also exist, taking OMA-URI values on Android and imported Apple Configurator files on iOS and iPadOS.
Conflict resolution is a supported view, not detective work
Microsoft describes managing profiles to check device status and which profiles are assigned, and helping resolve conflicts by seeing the settings that cause a conflict and the profiles that include those settings. In an estate with many overlapping profiles, that view is the difference between a ten minute fix and an afternoon of elimination.
Two templates are deprecated. Your existing policies still work, and you cannot create new ones.
Both notices are published in the same words, and both apply to configurations that most Windows and macOS estates in the UAE are built on.
- Quoted, for the Endpoint protection template: it is deprecated in the August 2024 service release, existing policies continue to work, but you cannot create new policies using this template. Microsoft directs you to the settings catalog to configure the FileVault, Firewall and System Policy Control payloads instead.
- Quoted, for the Extensions template covering macOS system and kernel extensions: the same deprecation, with the settings catalog System Extensions payload as the replacement.
- The practical consequence is a split estate. Old policies from the templates, new policies from the catalog, and two places to look when somebody asks why a setting is what it is. That is manageable for a year and unmanageable by year three.
- The migration is not urgent in the sense that anything breaks. It is urgent in the sense that the longer both exist, the more expensive the eventual consolidation becomes, and it is far easier to do deliberately than during an incident.
Four things that stop a profile estate becoming unreadable.
We standardise on the settings catalog and document the exceptions
Microsoft describes the settings catalog as listing all available settings in one place, cloud native and closer to Group Policy in shape, with thousands of Windows settings including many the templates never had. Standardising there, and using templates only where a specific template genuinely fits, means one place to look rather than two.
We map the deprecated templates before they become urgent
The Endpoint protection and Extensions templates are both closed to new policies since the August 2024 service release. Existing policies keep working, which is exactly why nobody schedules the migration. Mapping which policies sit on those templates, and what the settings catalog equivalents are, converts a future problem into a planned piece of work.
We treat conflicts as a design signal rather than an incident
The conflict view shows which settings conflict and which profiles contain them. A conflict is almost always a symptom of two profiles overlapping because nobody drew a boundary. Fixing the specific conflict takes minutes and fixing the boundary takes an hour, and only the second one stops it recurring.
We run Group Policy analytics before recreating anything
Microsoft describes it as analysing your on-premises Group Policy Objects to determine how they translate in the cloud, with output showing deprecated settings and settings available or not available to mobile device management providers. That turns a migration from a manual recreation exercise into an informed one, and it consistently finds settings nobody needs any more.
Six UAE situations where profile design is the deciding factor.
A group migrating from Group Policy to Intune
Group Policy analytics analyses your existing objects and shows how they translate in the cloud, including deprecated settings and settings unavailable to mobile device management providers. Combined with the settings catalog, which Microsoft positions as cloud-native Group Policy, that is a far more structured migration than recreating policies from memory.
A business rolling out corporate Wi-Fi to personal devices
Wi-Fi and certificate profiles together mean users get corporate wireless without configuring anything and without entering a password, using trusted root, Simple Certificate Enrolment Protocol or Public Key Cryptography Standards certificates. That combination removes both a support burden and a shared credential.
An operator running Zebra devices on a warehouse floor
Mobility extensions expand on the built-in Intune settings to customise or add settings specific to Zebra devices, which Microsoft notes are commonly used on factory floors and in retail. Where an estate runs hundreds or thousands of them, that profile type is the difference between managed and merely enrolled.
A regulated firm hardening device firmware
BIOS configuration lets administrators password-protect BIOS access and apply a configuration file created with an original equipment manufacturer tool, and the device firmware configuration interface enables or disables UEFI settings through Intune. Microsoft notes firmware-level security is typically more resilient to malicious attacks, which is why auditors have started asking about it.
An education institution with shared devices and exams
Windows education settings configure the Take a Test app, where Microsoft notes no other apps can run on the device until the test is complete. On iOS and iPadOS, Classroom settings guide learning and control student devices, and iPads can be configured so several students share a single device.
An organisation with requirements Intune settings do not cover
Custom profiles take OMA-URI values on Android and imported Apple Configurator files on iOS and iPadOS. Scripts cover the rest: PowerShell on Windows through the Intune Management Extension, shell scripts on macOS, and existing Bash scripts on Linux. Those are the escape hatches, and they need the same change control as everything else.
How UAE organisations configure managed devices.
| Feature | Designed profile estate | Profiles added as needed | Group Policy only, unmanaged mobile |
|---|---|---|---|
Consistent settings across platforms | Yes | Partly | Windows only |
Settings catalog used for full coverage | Yes | Rarely | Not applicable |
Deprecated templates migrated | Yes | No | Not applicable |
Conflicts reviewed and resolved | Yes | When reported | Not applicable |
Profiles tested in rings | Yes | No | Sometimes |
Certificate-based network access | Yes | Sometimes | Rarely |
Mobile devices configured at all | Yes | Partly | No |
Anybody can explain a given setting | Yes | No | Sometimes |
Naming convention exists | Yes | No | Not applicable |
Effort to add a new requirement | Low | Low then rising | High |
What each type does, and which platforms it covers.
| Profile type | What it configures | Platforms | |
|---|---|---|---|
| Settings catalog | Every available setting, in one place, cloud native | Windows, macOS, iOS and iPadOS, Android Enterprise, Android AOSP | |
| Device restrictions | Security, hardware, data sharing, app store access, password requirements | Windows, macOS, iOS and iPadOS, Android | |
| Wi-Fi | Wireless network settings so users do not configure it themselves | Windows, macOS, iOS and iPadOS, Android | |
| Virtual private network | Secure remote access connection profiles | Windows, macOS, iOS and iPadOS, Android | |
| Wired networks | 802.1x wired connections with EAP types and server trust | Windows, macOS, iOS and iPadOS | |
| Certificates | Trusted root, SCEP and PKCS certificates for authentication and S/MIME | Windows, macOS, iOS and iPadOS, Android | |
| Exchange ActiveSync settings, created assigned and monitored | Windows, iOS and iPadOS, Android | ||
| Kiosk | Single app or multi app kiosk, with start menu and browser options | Windows, and via device restrictions on Android and Apple | |
| BIOS and firmware configuration | Password protection for BIOS, and UEFI settings through DFCI | Windows | |
| Domain join | Which domain and organisational unit a hybrid joined device joins | Windows | |
| Shared multi-user device | Sleep options, file saving and inactive credential cleanup on shared PCs | Windows and Windows Holographic for Business | |
| Custom profile | OMA-URI values, or an imported Apple Configurator file | Windows, macOS, iOS and iPadOS, Android | |
| Scripts | PowerShell on Windows, shell on macOS, Bash on Linux | Windows, macOS, Linux | |
| Delivery optimization | How software update content is downloaded to devices | Windows | |
| Windows health monitoring | Event data collection for Endpoint Analytics | Windows |
Five steps, and the naming convention matters more than it sounds.
- 1
Inventory what exists and what conflicts
Every profile, its platform, its assignment, and its owner if one can be identified. Then the conflict view, which shows the settings causing conflicts and the profiles containing them. In most estates this step alone produces a list of profiles nobody can justify and several conflicts nobody knew about.
- 2
Decide the structure and the naming convention
Settings catalog as the default with documented exceptions where a template genuinely fits. A baseline every device receives, plus targeted profiles for specific requirements, which is the pattern Microsoft describes. User assignment or device assignment decided per profile type rather than mixed arbitrarily. And a naming convention, because it is the only navigation the console gives you.
- 3
Run Group Policy analytics where relevant
For organisations still carrying on-premises Group Policy, the analytics tool shows how existing objects translate, which settings are deprecated, and which are available or unavailable to mobile device management providers. That prevents recreating settings that no longer apply and identifies the ones that genuinely need a different approach.
- 4
Build, test in rings, then assign
Profiles built to the agreed structure, tested against a pilot group that includes the awkward devices rather than a convenient sample, and assigned in rings. A restriction profile reaches everybody quickly and is noticed immediately, which is why this is the step we refuse to compress.
- 5
Plan the deprecated template migration and hand over
Policies on the Endpoint protection and Extensions templates mapped to their settings catalog equivalents with a scheduled migration, since new policies cannot be created on either. Then owners assigned per profile, a change record established, and a rhythm for reviewing conflicts rather than waiting for a user to report one.
What organisations ask about configuration profiles.
Fifteen decisions that keep configuration maintainable.
Structure
- Settings catalog or templates by default?Pick one and document the exceptions.
- How many profiles per platform?Fewer, larger profiles are easier to reason about.
- Assigned to users or to devices?Mixing both is a common source of confusion.
- Is there a baseline every device gets?Microsoft describes exactly this pattern.
- What is the naming convention?It is the only navigation you will have.
Platform reality
- Are you still using Android device administrator?Deprecated on Google Mobile Services devices.
- Any policies on the Endpoint protection template?Deprecated for new policies.
- Any policies on the Extensions template?Also deprecated for new policies.
- Do you need multi app kiosk on Windows 11?Windows 11 supports single app kiosk only.
- Are macOS preference files still needed?The settings catalog can replace some.
Operations
- Who reviews conflicts?The view exists, somebody has to look.
- Are profiles tested in a ring first?A bad restriction reaches everyone quickly.
- Is there a change record?Otherwise nobody can explain a setting later.
- Have you run Group Policy analytics?It shows what translates and what does not.
- Who owns each profile?Unowned profiles are never removed.
The pages around this one.
Open the conflict view. If it is empty, you either have a clean estate or nobody is looking.
It is a two minute check and it is the fastest indicator of whether your profile estate has structure or has accumulated. Both are recoverable, and the second one costs more the longer it runs.
Related Services
Explore more solutions that work great with this service
Endpoint Analytics
Measured device experience, and the refresh evidence
Security Baselines
Why deploying one does not make you CIS compliant
Intune Compliance Policies
The default that lets unassessed devices through Conditional Access
Microsoft Intune
Device management and endpoint security
Windows Autopilot Dubai
Zero-touch laptop deployment, supplier registration onward
MDM Solutions Dubai
Device management across Windows, Apple and Android
BitLocker Management
Silent encryption, recovery key escrow, and the assessment first
Kiosk and Shared Devices
Signage, terminals and handsets locked to the job they do