Your environment includes an on-premises Active Directory domain and an Azure AD tenant. You want to migrate the settings from the existing Default Domain Policy GPO into a device configuration profile in Intune. Which device configuration profile template type should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Device restrictions.
Why this is the answer
The Device restrictions template is the most appropriate choice for migrating settings from a Group Policy Object (GPO) like the Default Domain Policy. This template offers a wide range of configurable settings that directly correspond to many common GPO settings, including security, privacy, and device functionality. It's designed to manage various aspects of device behavior and user experience. Administrative Templates are also used for GPO-like settings, but they are a more specific subset focused on ADMX-backed policies. While useful, 'Device restrictions' offers a broader and more general set of controls that align better with a direct migration of a comprehensive GPO. Endpoint protection focuses specifically on security features like antivirus and firewall, not general device settings. Custom profiles are for settings not available in other templates and would require creating OMA-URI settings, which is more complex than necessary for a direct GPO migration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed