Configuration Policies
Lists the configuration policies on the selected tenant, showing what type each policy is and who it is assigned to. Selecting a row opens a flyout with the policy's settings, which is useful for reviewing a policy in detail or copying its configuration into another system or script.
Action Buttons
Deploy Policy
Opens a drawer that applies a saved policy template to one or more tenants.
Select Tenants
The tenants to deploy to. Several can be selected, and the same template is applied to each.
Please choose a template to apply.
The policy template to deploy, chosen from those saved in Policy Templates. Refresh Templates reloads the list if a template was added since the drawer was opened.
Assignment
Who the deployed policy is assigned to: Do not assign, Assign to all users, Assign to all devices, Assign to all users and devices, or Assign to Custom Group.
Custom Group Names
Shown when Assign to Custom Group is chosen. Group display names separated by commas, where * may be used as a wildcard.
Exclude Group Names
Shown for every option except Do not assign. Group display names to exclude, again comma separated and accepting * as a wildcard.
Assignment Filter (Optional)
An assignment filter from the tenant to narrow which devices the policy applies to.
Assignment Filter Mode
Whether the filter includes or excludes matching devices. Shown once a filter is chosen.
The template's configuration is displayed below the picker so it can be checked before deploying.
Where the template contains variables written as %name%, the drawer asks for a value for each one, per tenant, before it will deploy. %tenantid% and %tenantdomain% are filled in automatically for each selected tenant.
Deploying a template does not always create a new policy. CIPP first looks for a policy in the target tenant whose name exactly matches the template's, and where one is found it overwrites that policy in place. A new policy is only created where no match exists.
Because the match is on the name alone, a policy created by hand under the same name will be overwritten, and a deployed policy that has since been renamed in Intune will not be recognised, so the next deployment creates a duplicate alongside it. Where two policies share a name, the more recently modified one is the one overwritten.
The assignment chosen here is added to the policy's existing assignments rather than replacing them.
What an overwrite does to settings the template does not mention depends on the policy type.
For Settings Catalog and Administrative Templates this means any change made directly in the Microsoft Intune admin center since the template was captured is lost on the next deployment.
Settings Catalog
Removed. The policy's settings become exactly what the template holds.
Administrative Templates
Removed. Every configured setting on the policy is cleared before the template's are applied.
All other types
Left as they are. The template's settings are merged over the existing ones.
Table Details
Display Name
The name of the policy.
Policy Type Name
The kind of policy, for example Device Configuration, Administrative Templates, Compliance Policy or Endpoint Security.
Policy Assignment
The groups and broad targets the policy is assigned to. All Devices, All Users and All Licenced Users appear here where those targets are used.
Policy Exclude
The groups and broad targets excluded from the policy.
Description
The description recorded against the policy.
Last Modified Date Time
When the policy was last changed.
The flyout for a Settings Catalog or Administrative Templates policy fetches the policy's settings along with Microsoft's own descriptions for each one, so the settings read as names rather than identifiers. This takes a moment to load, and other policy types show their stored details without the extra lookup.
Table Actions
Create template based on policy
Creates a policy template based on the selected policy(ies)
Edit Name & Description
Allows you to edit the name and description of the selected policy(ies)
Clone Policy
Creates a clone of the selected policy(ies) with the ability to set a new name and description
Assign to All Users
Assigns the policy(ies) to all users, with optional exclusion groups and an optional assignment filter
Assign to All Devices
Assigns the policy(ies) to all devices, with optional exclusion groups and an optional assignment filter
Assign Globally (All Users / All Devices)
Assigns the policy(ies) to all users and all devices, with optional exclusion groups and an optional assignment filter
Assign to Custom Group
Assigns the policy(ies) to a custom group from the tenant. Options are to include or exclude the group and replace or append to existing assignments. You can also apply an existing assignment filter to further restrict assignment.
Delete Policy
Deletes the selected policy(ies)
More Info
Opens the Extended Info flyout
Feature Requests/Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

