Skip to content
Intune & AutopilotProject guide

Moving From Group Policy to Intune: What to Keep, Translate, or Drop

Use Group Policy analytics to see what translates to Intune, sort your GPOs into keep, translate, and drop, and replace drive maps, printers, and logon scripts with cloud-native options.

If you're moving devices to Entra join and Intune, your Group Policy has to go somewhere. Most small businesses have years of GPOs, some critical, most forgotten. Copying all of them into Intune one-for-one is the slowest way to do this and brings every old mistake along. Sorting them first is faster, and you end up with a much cleaner result.

Step 1: Inventory what you have

Export a report of every GPO and where it's linked:

powershell
# On a domain controller or a machine with RSAT
Get-GPO -All | Select-Object DisplayName, GpoStatus, ModificationTime |
  Sort-Object ModificationTime | Format-Table -AutoSize
Get-GPOReport -All -ReportType Html -Path C:\Temp\AllGPOs.html

Also note which OUs each GPO is linked to, and whether it's enabled. Plenty of GPOs are linked nowhere and do nothing.

Step 2: Run Group Policy analytics

In Intune, Devices -> Manage devices -> Group Policy analytics accepts GPO backups (XML) and reports, setting by setting, whether each one has an Intune equivalent. Export your GPOs as XML and import them:

powershell
Backup-GPO -All -Path C:\Temp\GPOBackup

For supported settings, Group Policy analytics can also migrate them into a Settings catalog profile, which saves a lot of clicking. Treat that as a starting draft, not a finished policy.

Step 3: Sort every setting into three piles

PileWhat goes hereExample
KeepSettings you still need, with a direct Intune equivalentScreen lock timeout, Edge settings, Defender settings
TranslateNeeds still exist, but the cloud solution is differentDrive maps, printers, logon scripts, software installs
DropObsolete, or already the Windows defaultIE settings, XP-era hardening, settings that don't apply to Windows 11

The drop pile is usually the biggest. That's normal, and it's a good thing.

Step 4: Translate the hard ones

  • Mapped drives -> SharePoint and OneDrive. Move the data, then sync document libraries with OneDrive. If a share truly can't move yet, a small PowerShell script deployed through Intune can map it, but that's a stopgap.
  • Printers -> Universal Print or vendor cloud printing, or a script-based deployment for a handful of printers.
  • Logon scripts -> PowerShell scripts or remediations in Intune. Most logon scripts do three or four things, and each one needs a better home.
  • Software installs -> Win32 apps (packaging pitfalls).
  • Security baselines -> Intune security baselines or Settings catalog policies, rather than hand-copied GPO values.

Step 5: Avoid double management

During the transition, a hybrid-joined device can receive both GPO and Intune settings for the same thing. By default, Group Policy wins many of those conflicts. Plan it deliberately:

  • Move devices to Intune-only management in groups, not all at once.
  • For a device that gets both, either unlink the GPO from its OU first, or use the MDM-wins-over-GP setting (Policy CSP ControlPolicyConflict) where appropriate. Understand what it does before you use it.
  • For Entra-joined devices, GPOs don't apply at all. That's the cleanest end state.

Step 6: Retire the GPOs

Once a group of devices is fully managed by Intune, unlink (don't delete) the old GPOs for that group. Keep the backups. When everything has moved and nothing has broken for a month, delete them.

// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.