We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and MDM
  2. Configuration profiles
Microsoft Intune configuration profiles, UAE

Templates or the settings catalog. Choosing wrong once produces an estate nobody can audit three years later.

Templates group settings around a concept such as email, kiosk or firmware. The settings catalog lists every available setting in one place, and Microsoft describes it as similar to Group Policy but cloud native, with thousands of Windows settings including many the templates never had. Two templates are already deprecated for new policies.

Book a configuration profile reviewSee the two policy types
Microsoft Intune configuration profile design for UAE organisations
  • Two policy typesTemplates, or the settings catalog
  • Four platformsWindows, macOS, iOS and iPadOS, Android
  • Two deprecatedEndpoint protection and Extensions templates
  • Conflict viewWhich profiles caused a conflicting setting
How profiles work

Seven things that decide whether your profile estate stays maintainable.

Microsoft describes configuration profiles as the container for the settings and features you enable or disable on devices, created per platform and assigned to user or device groups. It also notes that it is common to have many profiles for each platform, which is precisely the problem this page is about.

The settings catalog is the cloud-native Group Policy

Microsoft describes the settings catalog as listing all the settings you can configure in one place, not a template or a logical grouping, and as similar to configuring on-premises Group Policy Objects but cloud native. On Windows there are thousands of settings available, including many not found in the templates, which is why a complete configuration usually needs it.

Templates group settings around a concept

Templates include a logical grouping of settings that configure a feature or concept, with Microsoft naming email, kiosk devices and device firmware as examples, plus templates covering resource access such as virtual private network and Wi-Fi, and security such as antivirus, firewall and certificates. Where a template exists and fits, it is simpler than assembling the same result from the catalog.

Two templates are already closed to new policies

The Endpoint protection template and the Extensions template were both deprecated in the August 2024 service release. Microsoft states existing policies continue to work but you cannot create new policies using them, directing you to the settings catalog instead for the FileVault, Firewall and System Policy Control payloads and for System Extensions. Estates built on those templates need a migration plan.

Resource access profiles are what users actually notice

Wi-Fi profiles give users corporate wireless without configuring it themselves. Virtual private network profiles do the same for remote access. Email profiles create and monitor Exchange ActiveSync settings, which Microsoft notes helps with consistency, reduces support calls, and lets users access company email on personal devices without any setup on their part.

Certificates, so nobody types a password into a network prompt

Certificates authenticate users so they can reach applications and corporate resources through virtual private network, Wi-Fi or email profiles without entering usernames and passwords. Microsoft names trusted root, Simple Certificate Enrolment Protocol and Public Key Cryptography Standards certificates as the common types, and they are also used for signing and encrypting email.

Scripts, for everything the settings cannot express

PowerShell scripts on Windows through the Intune Management Extension, shell scripts on macOS, and existing Bash scripts on Linux, which Microsoft describes as similar to a custom configuration profile for settings not built into Intune. Custom profiles also exist, taking OMA-URI values on Android and imported Apple Configurator files on iOS and iPadOS.

Conflict resolution is a supported view, not detective work

Microsoft describes managing profiles to check device status and which profiles are assigned, and helping resolve conflicts by seeing the settings that cause a conflict and the profiles that include those settings. In an estate with many overlapping profiles, that view is the difference between a ten minute fix and an afternoon of elimination.

The migration nobody has scheduled

Two templates are deprecated. Your existing policies still work, and you cannot create new ones.

Both notices are published in the same words, and both apply to configurations that most Windows and macOS estates in the UAE are built on.

  • Quoted, for the Endpoint protection template: it is deprecated in the August 2024 service release, existing policies continue to work, but you cannot create new policies using this template. Microsoft directs you to the settings catalog to configure the FileVault, Firewall and System Policy Control payloads instead.
  • Quoted, for the Extensions template covering macOS system and kernel extensions: the same deprecation, with the settings catalog System Extensions payload as the replacement.
  • The practical consequence is a split estate. Old policies from the templates, new policies from the catalog, and two places to look when somebody asks why a setting is what it is. That is manageable for a year and unmanageable by year three.
  • The migration is not urgent in the sense that anything breaks. It is urgent in the sense that the longer both exist, the more expensive the eventual consolidation becomes, and it is far easier to do deliberately than during an incident.
Ask us to map your deprecated templates
How we approach it

Four things that stop a profile estate becoming unreadable.

Configuration profiles are easy to create and nearly impossible to consolidate later. Everything below is about decisions taken early that stay cheap, versus decisions deferred that become expensive.

We standardise on the settings catalog and document the exceptions

Microsoft describes the settings catalog as listing all available settings in one place, cloud native and closer to Group Policy in shape, with thousands of Windows settings including many the templates never had. Standardising there, and using templates only where a specific template genuinely fits, means one place to look rather than two.

We map the deprecated templates before they become urgent

The Endpoint protection and Extensions templates are both closed to new policies since the August 2024 service release. Existing policies keep working, which is exactly why nobody schedules the migration. Mapping which policies sit on those templates, and what the settings catalog equivalents are, converts a future problem into a planned piece of work.

We treat conflicts as a design signal rather than an incident

The conflict view shows which settings conflict and which profiles contain them. A conflict is almost always a symptom of two profiles overlapping because nobody drew a boundary. Fixing the specific conflict takes minutes and fixing the boundary takes an hour, and only the second one stops it recurring.

We run Group Policy analytics before recreating anything

Microsoft describes it as analysing your on-premises Group Policy Objects to determine how they translate in the cloud, with output showing deprecated settings and settings available or not available to mobile device management providers. That turns a migration from a manual recreation exercise into an informed one, and it consistently finds settings nobody needs any more.

Where this matters most

Six UAE situations where profile design is the deciding factor.

Microsoft notes it is common to have many device profiles for each platform, ranging from antivirus settings to custom settings. Managing that sprawl deliberately is what separates a maintainable estate from an accumulated one.

A group migrating from Group Policy to Intune

Group Policy analytics analyses your existing objects and shows how they translate in the cloud, including deprecated settings and settings unavailable to mobile device management providers. Combined with the settings catalog, which Microsoft positions as cloud-native Group Policy, that is a far more structured migration than recreating policies from memory.

A business rolling out corporate Wi-Fi to personal devices

Wi-Fi and certificate profiles together mean users get corporate wireless without configuring anything and without entering a password, using trusted root, Simple Certificate Enrolment Protocol or Public Key Cryptography Standards certificates. That combination removes both a support burden and a shared credential.

An operator running Zebra devices on a warehouse floor

Mobility extensions expand on the built-in Intune settings to customise or add settings specific to Zebra devices, which Microsoft notes are commonly used on factory floors and in retail. Where an estate runs hundreds or thousands of them, that profile type is the difference between managed and merely enrolled.

A regulated firm hardening device firmware

BIOS configuration lets administrators password-protect BIOS access and apply a configuration file created with an original equipment manufacturer tool, and the device firmware configuration interface enables or disables UEFI settings through Intune. Microsoft notes firmware-level security is typically more resilient to malicious attacks, which is why auditors have started asking about it.

An education institution with shared devices and exams

Windows education settings configure the Take a Test app, where Microsoft notes no other apps can run on the device until the test is complete. On iOS and iPadOS, Classroom settings guide learning and control student devices, and iPads can be configured so several students share a single device.

An organisation with requirements Intune settings do not cover

Custom profiles take OMA-URI values on Android and imported Apple Configurator files on iOS and iPadOS. Scripts cover the rest: PowerShell on Windows through the Intune Management Extension, shell scripts on macOS, and existing Bash scripts on Linux. Those are the escape hatches, and they need the same change control as everything else.

Three positions

How UAE organisations configure managed devices.

The middle column is what happens when profiles accumulate one requirement at a time over several years, with no structure and no owner. It works, until somebody has to explain it.
Consistent settings across platforms
Designed profile estateYes
Profiles added as neededPartly
Group Policy only, unmanaged mobileWindows only
Settings catalog used for full coverage
Designed profile estateYes
Profiles added as neededRarely
Group Policy only, unmanaged mobileNot applicable
Deprecated templates migrated
Designed profile estateYes
Profiles added as neededNo
Group Policy only, unmanaged mobileNot applicable
Conflicts reviewed and resolved
Designed profile estateYes
Profiles added as neededWhen reported
Group Policy only, unmanaged mobileNot applicable
Profiles tested in rings
Designed profile estateYes
Profiles added as neededNo
Group Policy only, unmanaged mobileSometimes
Certificate-based network access
Designed profile estateYes
Profiles added as neededSometimes
Group Policy only, unmanaged mobileRarely
Mobile devices configured at all
Designed profile estateYes
Profiles added as neededPartly
Group Policy only, unmanaged mobileNo
Anybody can explain a given setting
Designed profile estateYes
Profiles added as neededNo
Group Policy only, unmanaged mobileSometimes
Naming convention exists
Designed profile estateYes
Profiles added as neededNo
Group Policy only, unmanaged mobileNot applicable
Effort to add a new requirement
Designed profile estateLow
Profiles added as neededLow then rising
Group Policy only, unmanaged mobileHigh
Feature
Designed profile estate
Profiles added as needed
Group Policy only, unmanaged mobile
Consistent settings across platforms
YesPartlyWindows only
Settings catalog used for full coverage
YesRarelyNot applicable
Deprecated templates migrated
YesNoNot applicable
Conflicts reviewed and resolved
YesWhen reportedNot applicable
Profiles tested in rings
YesNoSometimes
Certificate-based network access
YesSometimesRarely
Mobile devices configured at all
YesPartlyNo
Anybody can explain a given setting
YesNoSometimes
Naming convention exists
YesNoNot applicable
Effort to add a new requirement
LowLow then risingHigh
The profile types

What each type does, and which platforms it covers.

Profile types and platform support as published. This is the list most organisations discover piecemeal, one requirement at a time, over several years.
Profile typeWhat it configuresPlatforms
Settings catalogEvery available setting, in one place, cloud nativeWindows, macOS, iOS and iPadOS, Android Enterprise, Android AOSP
Device restrictionsSecurity, hardware, data sharing, app store access, password requirementsWindows, macOS, iOS and iPadOS, Android
Wi-FiWireless network settings so users do not configure it themselvesWindows, macOS, iOS and iPadOS, Android
Virtual private networkSecure remote access connection profilesWindows, macOS, iOS and iPadOS, Android
Wired networks802.1x wired connections with EAP types and server trustWindows, macOS, iOS and iPadOS
CertificatesTrusted root, SCEP and PKCS certificates for authentication and S/MIMEWindows, macOS, iOS and iPadOS, Android
EmailExchange ActiveSync settings, created assigned and monitoredWindows, iOS and iPadOS, Android
KioskSingle app or multi app kiosk, with start menu and browser optionsWindows, and via device restrictions on Android and Apple
BIOS and firmware configurationPassword protection for BIOS, and UEFI settings through DFCIWindows
Domain joinWhich domain and organisational unit a hybrid joined device joinsWindows
Shared multi-user deviceSleep options, file saving and inactive credential cleanup on shared PCsWindows and Windows Holographic for Business
Custom profileOMA-URI values, or an imported Apple Configurator fileWindows, macOS, iOS and iPadOS, Android
ScriptsPowerShell on Windows, shell on macOS, Bash on LinuxWindows, macOS, Linux
Delivery optimizationHow software update content is downloaded to devicesWindows
Windows health monitoringEvent data collection for Endpoint AnalyticsWindows
How an engagement runs

Five steps, and the naming convention matters more than it sounds.

Typically six to twelve weeks for a full profile design across platforms. Creating profiles is fast. Agreeing the structure, and testing before assignment, is what makes it durable.
  1. 1

    Inventory what exists and what conflicts

    Every profile, its platform, its assignment, and its owner if one can be identified. Then the conflict view, which shows the settings causing conflicts and the profiles containing them. In most estates this step alone produces a list of profiles nobody can justify and several conflicts nobody knew about.

  2. 2

    Decide the structure and the naming convention

    Settings catalog as the default with documented exceptions where a template genuinely fits. A baseline every device receives, plus targeted profiles for specific requirements, which is the pattern Microsoft describes. User assignment or device assignment decided per profile type rather than mixed arbitrarily. And a naming convention, because it is the only navigation the console gives you.

  3. 3

    Run Group Policy analytics where relevant

    For organisations still carrying on-premises Group Policy, the analytics tool shows how existing objects translate, which settings are deprecated, and which are available or unavailable to mobile device management providers. That prevents recreating settings that no longer apply and identifies the ones that genuinely need a different approach.

  4. 4

    Build, test in rings, then assign

    Profiles built to the agreed structure, tested against a pilot group that includes the awkward devices rather than a convenient sample, and assigned in rings. A restriction profile reaches everybody quickly and is noticed immediately, which is why this is the step we refuse to compress.

  5. 5

    Plan the deprecated template migration and hand over

    Policies on the Endpoint protection and Extensions templates mapped to their settings catalog equivalents with a scheduled migration, since new policies cannot be created on either. Then owners assigned per profile, a change record established, and a rhythm for reviewing conflicts rather than waiting for a user to report one.

Straight answers

What organisations ask about configuration profiles.

The settings catalog for most things. Microsoft describes it as listing all the settings you can configure in one place, not a template or a logical grouping, and as similar to on-premises Group Policy Objects but cloud native. On Windows there are thousands of settings including many not found in the templates. Templates remain useful where you want a logical grouping around a feature such as email or kiosk.

Two, both in the August 2024 service release. The Endpoint protection template, where Microsoft directs you to the settings catalog for the FileVault, Firewall and System Policy Control payloads. And the Extensions template for macOS system and kernel extensions, where the settings catalog System Extensions payload is the replacement. In both cases existing policies continue to work but new ones cannot be created.

Android, iOS and iPadOS, macOS and Windows, with some settings unique to each platform. The settings catalog supports iOS and iPadOS, macOS, Android Enterprise, Android AOSP and Windows. Linux appears for shell scripts rather than as a full profile platform, where Microsoft describes adding existing Bash scripts to configure features not built into Intune.

Not on modern devices. Microsoft states Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services, and recommends switching to another Android management option if you currently use it. Support and documentation remain for some Android 15 and earlier devices without Google Mobile Services, which in practice means a small and shrinking population.

Microsoft provides a view for exactly this. Managing your profiles lets you check the status of devices and the profiles assigned, and helps resolve conflicts by showing the settings that cause a conflict and the profiles that include those settings. The fix is usually a boundary problem rather than a setting problem, so we treat a conflict as a signal that two profiles overlap.

Single app kiosk only. Microsoft states that explicitly in the kiosk profile documentation. Kiosk settings are also available as device restrictions for Android, Android Enterprise through device experience, and iOS and iPadOS, so the multi app kiosk requirement on Windows 11 needs a different approach that is worth establishing before the hardware is bought.

Certificates. Microsoft describes using certificates to authenticate users so they can access applications and corporate resources through virtual private network, Wi-Fi or email profiles, with the result that end users do not need to enter usernames and passwords. The common types are trusted root certificates, Simple Certificate Enrolment Protocol certificates and Public Key Cryptography Standards certificates.

Three routes. A custom profile, taking OMA-URI values on Android or an imported Apple Configurator configuration file on iOS and iPadOS. A script, using PowerShell on Windows through the Intune Management Extension, shell scripts on macOS, or existing Bash scripts on Linux. Or, for Android Enterprise, OEMConfig, where an original equipment manufacturer publishes a schema that Intune reads and exposes as configurable settings.

Both are supported and the choice should be per profile type rather than arbitrary. Device assignment suits configuration that should apply regardless of who signs in, such as restrictions, firmware and shared device settings. User assignment suits configuration that follows a person, such as email and some resource access. The problem is not either choice, it is mixing them without a rule.

Yes, through Group Policy analytics. Microsoft describes it as analysing your on-premises Group Policy Objects to help determine how they translate in the cloud, with output showing any deprecated settings and the settings that are available or not available to mobile device management providers including Intune. It is the right first step in any Group Policy to Intune migration.

They still exist and Microsoft notes that macOS settings are continually being added to the settings catalog, with some of those settings able to replace preference files. So the direction of travel is towards the catalog, and a new macOS requirement is worth checking against the catalog before reaching for a preference file that will need maintaining separately.

Fewer and larger, with a clear boundary between them, rather than many small ones added per requirement. Microsoft notes it is common to have many profiles per platform, which is a description of what happens rather than a recommendation. Every additional profile is another place a setting could be defined, and conflicts scale with overlap rather than with count alone.

Always, and particularly restriction profiles. A device restriction reaches every targeted device quickly and is noticed by users immediately, which makes it the profile type most likely to produce a support queue and a rollback. Testing against a ring that includes the awkward devices, rather than a convenient sample, is what prevents that.

On Windows, yes. BIOS configuration lets administrators password-protect BIOS access and apply a configuration file created with an original equipment manufacturer tool. The device firmware configuration interface enables or disables UEFI settings through Intune, and Microsoft notes this enhances security at the firmware level, which is typically more resilient to malicious attacks.

We scope per organisation, driven by how many platforms are in scope, how much existing configuration needs consolidating, and whether a Group Policy migration is part of the work. The inventory and conflict review is usually the fastest way to establish the real size, and it frequently finds more profiles than anybody expected.
Designing the profile estate

Fifteen decisions that keep configuration maintainable.

The first group is structure, the second is platform reality, and the third is the operational half that determines whether anybody can still explain the configuration in two years.

Structure

  • Settings catalog or templates by default?
    Pick one and document the exceptions.
  • How many profiles per platform?
    Fewer, larger profiles are easier to reason about.
  • Assigned to users or to devices?
    Mixing both is a common source of confusion.
  • Is there a baseline every device gets?
    Microsoft describes exactly this pattern.
  • What is the naming convention?
    It is the only navigation you will have.

Platform reality

  • Are you still using Android device administrator?
    Deprecated on Google Mobile Services devices.
  • Any policies on the Endpoint protection template?
    Deprecated for new policies.
  • Any policies on the Extensions template?
    Also deprecated for new policies.
  • Do you need multi app kiosk on Windows 11?
    Windows 11 supports single app kiosk only.
  • Are macOS preference files still needed?
    The settings catalog can replace some.

Operations

  • Who reviews conflicts?
    The view exists, somebody has to look.
  • Are profiles tested in a ring first?
    A bad restriction reaches everyone quickly.
  • Is there a change record?
    Otherwise nobody can explain a setting later.
  • Have you run Group Policy analytics?
    It shows what translates and what does not.
  • Who owns each profile?
    Unowned profiles are never removed.
Related reading

The pages around this one.

Intune security baselines

The security-specific configuration layer, and how drift from it is detected.

Learn more

Intune compliance policies

What is evaluated after configuration is applied, and how Conditional Access uses it.

Learn more

Microsoft Intune

The product overview and how the pieces fit together.

Learn more
Next step

Open the conflict view. If it is empty, you either have a clean estate or nobody is looking.

It is a two minute check and it is the fastest indicator of whether your profile estate has structure or has accumulated. Both are recoverable, and the second one costs more the longer it runs.

Book a configuration profile reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Endpoint Analytics

Measured device experience, and the refresh evidence

Learn more

Security Baselines

Why deploying one does not make you CIS compliant

Learn more

Intune Compliance Policies

The default that lets unassessed devices through Conditional Access

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Windows Autopilot Dubai

Zero-touch laptop deployment, supplier registration onward

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

BitLocker Management

Silent encryption, recovery key escrow, and the assessment first

Learn more

Kiosk and Shared Devices

Signage, terminals and handsets locked to the job they do

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy