This topic discusses general Intune policy management at the MSP level.
In order to configure policies and profiles on devices, you need to assign policies and profiles to security groups and then manage Intune devices through security groups. You can view global policies and profiles at the MSP level and publish them down to accounts. In addition, Nerdio Manager allows partners to manage policies and profiles at the customer account level.
In addition to the built-in policies and profiles, Nerdio Manager allows you to import policies and profiles that are in the MSP's tenant. This provides the ability to create custom policies with advanced configurations. Once policies are imported at the global level, you can assign them to specific customer accounts.
Policies and profiles can be imported directly from the source tenant, imported from a JSON or TXT file, or checked against the source tenant for newly available policies, using the Import Actions menu.
To import policies and profiles from the source tenant:
-
In Nerdio Manager, at the MSP level, expand Policies.
-
Select one of the following policy types to work with:
-
Entra
-
Conditional Access
-
-
Devices
-
Configuration Profiles
-
MAM Policies
-
Autopilot Profiles
-
Enrollment Status Pages
-
-
Security
-
Security Baselines
-
Compliance Policies
-
Update Rings
-
Endpoint Security Policies
-
Defender O365 Policies
-
-
-
From the Import Actions dropdown, select Import.
The Import page for the selected policy type opens, showing four stages: Available Policies, Selected Policies, Policy Options, and Summary.
-
On the Available Policies stage, select the checkbox next to each policy you want to import, and then select Next.
Note
Policies that have already been imported are listed but cannot be selected, and are labeled (Already imported).
-
On the Selected Policies stage, review the policies you selected. To remove a policy from the import, select the delete icon next to it. Once finished, select Next.
-
On the Policy Options stage, optionally configure the following, and then select Next:
-
Tags: select or enter a tag for the imported policies, used for searching and organization.
-
Changelog: enter a description of this import for your records.
-
Evaluate user/group assignments: select this option to load user/group assignments on the status page.
-
Overwrite if already exists: select this option to re-import a policy or profile that already exists in Nerdio Manager.
Note
When this option is selected, all the existing assignments stay the same.
-
Overwrite Authentication Context if already exists (Conditional Access policies only): select this option to overwrite an existing Authentication Context configuration in the customer tenant with the configuration from the imported policy.
Caution
Authentication Context configurations are stored in a shared set of predefined IDs (c1-c199) in the customer tenant, and other Conditional Access policies may reference the same ID. Overwriting a configuration can affect those policies as well as the one you are importing. This option is off by default so that you can review the existing configuration before deciding whether to overwrite it. To review a customer's existing Authentication Context configurations, go to Microsoft Entra admin center > Protection > Conditional Access > Authentication contexts.
-
-
On the Summary stage, review the policies to import, tags added, changelog, and policy options, and then select Import.
The imported policy or profile appears in the policy list.
To import a policy from JSON:
-
From the Import Actions dropdown, select Import from JSON.
The Import Policy from JSON dialog box opens.
-
Do one of the following:
-
Select Browse File and select a JSON or TXT file containing the policy definition.
-
Paste the policy definition directly into the Paste JSON here field.
-
-
From the Policy Type drop-down list, select the type of policy you are importing.
The dialog box displays additional fields: Tags, Changelog, and Evaluate user/group assignments.
-
Optionally configure the Tags, Changelog, and Evaluate user/group assignments fields.
-
Select Validate.
Nerdio Manager validates the policy definition and advances to the Summary stage of the import wizard.
-
On the Summary stage, review the policy details, and then select Import.
The imported policy appears in the policy list.
To manually check the source tenant for new policies:
-
Select Import Actions, and then select Source tenant check.
A Confirm Action dialog box opens, asking whether you want to manually check all policies in the source tenant for changes that have not yet been imported.
-
Select Apply.
Note
This check runs automatically every four hours. Use this option if you need to refresh the list of available policies sooner.
Nerdio Manager checks the source tenant and refreshes the list of policies available for import.
To create global-level compliance policies, configuration profiles, or security policies, sign in to the Microsoft Endpoint Manager admin center with an MSP-level Azure tenant. In Nerdio Manager, you can only view them.
Once policies are created at the global level, you can assign them to specific customer accounts.
Note
-
For Conditional Access policies, tenant-specific objects such as locations, applications, and authentication context are detected and replaced with customer-specific values when publishing. For details on how importing a policy can overwrite existing Authentication Context configurations, see Import policies and profiles at the MSP level.
-
MAM policies based on tenant specific application IDs are supported.
To assign policies and profiles to customers at the MSP level:
-
In Nerdio Manager, at the MSP level, expand Policies.
-
Select one of the following policy types to work with:
-
Entra
-
Conditional Access
-
-
Devices
-
Configuration Profiles
-
MAM Policies
-
Autopilot Profiles
-
Enrollment Status Pages
-
-
Security
-
Security Baselines
-
Compliance Policies
-
Update Rings
-
Endpoint Security Policies
-
Defender O365 Policies
-
-
-
Locate the policy or profile you wish to work with.
-
Select Assign, and then select Add assignments.
-
Enter the following information:
-
Select assignments: From the drop-down list, select the account(s) to assign this policy or profile to.
Note
-
Select All to assign this policy or profile to all accounts.
-
If an account is grayed out, Intune may not be enabled for the account. Hover over the account name for more information.
-
If Intune has been disabled for an account that has a policy or profile assigned to it, you receive this message.
-
-
Add: Select this option to add the selected customer account(s) to the existing assignments.
-
Overwrite: Select this option to replace the existing assignments with the new selection(s).
-
-
Once you have selected all the desired account(s), select Confirm.
-
On the Assignments page, enter the following information:
-
Sync Type: Select the sync type.
Note
By default the sync type is set to Manual. When applying the assignment, the policy is published from the global level to the assigned customer accounts. If the assignment is set to Automatic, the policy is regularly republished to all assigned customer accounts. Any changes to the source policy on the global level are applied to assigned customer accounts. If the policy is assigned to All customers, any newly added customer accounts also get the policy published automatically.
-
Version: From the drop-down list, select the version.
-
-
For Conditional Access policies only, from the drop-down list, select the desired State.
-
Once you have entered all the desired information, select Apply and close.
The accounts are assigned to the policy.
After policies and profiles have been assigned to customers, they can be removed from the customers.
To remove assigned policies and profiles from an account at the MSP level:
-
In Nerdio Manager, at the MSP level, expand Policies.
-
Select one of the following policy types to work with:
-
Entra
-
Conditional Access
-
-
Devices
-
Configuration Profiles
-
MAM Policies
-
Autopilot Profiles
-
Enrollment Status Pages
-
-
Security
-
Security Baselines
-
Compliance Policies
-
Update Rings
-
Endpoint Security Policies
-
Defender O365 Policies
-
-
-
Locate the policy or profile you wish to work with.
-
Select Assign.
-
Locate the account you wish to remove and select Remove.
After policies have been assigned to customers, they can be directly assigned to all users and/or all devices in that customer. Alternatively, you may directly assign policies to group templates.
Due to Microsoft limitations:
-
The Filters feature applies only to the following policies and profiles. See List of platforms, policies, and app types supported by filters in Microsoft Intune for details.
-
Security baselines
-
Configuration profiles
-
Update rings
-
Enrollment Status pages
-
Endpoint security policies
-
Conditional Access policies
-
Defender for Office365 policies
Note
Direct assign for Defender for O365 policies accepts only group templates based on M365 groups. Regular security groups do not work.
-
-
The Group Templates feature applies only to the following policies and profiles. See the Microsoft Support Matrix for details.
-
Compliance policies
-
Security baselines
-
Configuration profiles
-
Update rings (Expedite, Windows driver update, Windows feature update, Windows quality update, and Windows updates rings policies including Hotpatches).
-
Autopilot Profiles (only All Devices)
-
Enrollment Status pages
-
Endpoint security policies
-
To directly assign policies to users, devices, or group templates in an account at the MSP level:
-
In Nerdio Manager, at the MSP level, expand Policies.
-
Select one of the following policy types to work with:
-
Devices
-
Configuration Profiles
-
Autopilot Profiles
-
Enrollment Status Pages
-
-
Security
-
Compliance Policies
-
Security Baselines
-
Update Rings
-
Endpoint Security Policies
-
-
-
Locate the policy you wish to work with.
-
Select Assign.
-
Select Add assignments.
-
Enter the following information:
-
Select assignments: From the drop-down list, select the account(s) to assign this policy or profile to.
-
Add: Select this option to add the selected customer account(s) to the existing assignments.
-
Overwrite: Select this option to replace the existing assignments with the new selection(s).
-
-
Once you have selected all the desired account(s), select Confirm.
-
Select the pencil
icon to configure the direct assignments.
-
The Configure Direct Assignment dialog contains a number of steps, depending on the type of policy you're assigning:
-
Users & Groups (all policy types):
-
To assign the policy to all users in the customer account, select Add All Users.
-
To assign the policy to all devices in the customer account, select Add All Devices.
-
To add a specific user group to the assignment, select Add Group.
A new row appears in the Included Groups table containing a Select a group dropdown.
-
In the Select a group dropdown, select the desired group.
-
Select the Excluded Groups area to configure groups that are excluded from the policy scope.
-
To add emergency access accounts to the excluded groups, select Add Emergency Access Users.
An Emergency Access Users entry appears in the Excluded Groups table.
-
To add a security group to the excluded groups, select Add Group.
A new row appears in the Excluded Groups table containing a Select a group dropdown.
-
In the Select a group dropdown, select the desired group.
-
Select Next to proceed.
-
-
Directory Roles (Conditional Access policies only):
Use this step to define specific Entra roles to include and exclude from the assignment.
-
In the Included Roles dropdown, start typing to search for a role, and select the desired role to add it to the assignment.
-
By default, the Preserve Included Roles from the source policy checkbox is checked to ensure that any roles specified in the policy itself are carried over to the direct assignment. Uncheck this box to override these inherited role specifications and apply only role assignments configured in this dialog.
-
Select the Excluded Roles area to configure roles that are excluded from the policy scope.
-
In the Excluded Roles dropdown, select the desired role.
-
By default, the Preserve Excluded Roles from the source policy checkbox is checked to ensure that any role exclusions specified in the policy itself are carried over to the direct assignment. Uncheck this box to override these inherited role specifications and apply only role exclusions configured in this dialog.
-
Select Next to proceed.
-
-
Guests & External Users (Conditional Access policies only):
Use this step to define guest and external users to be allowed access.
-
Select the Included Users area.
-
In the Guest or External Users dropdown, select the desired user type(s).
-
To add a partner tenant, select the Enter tenant ID or verified domain field, type the tenant ID or domain, then select the Add tenant option that appears.
-
Select Next to proceed to the excluded users configuration.
-
Optionally, select the Excluded Users area.
-
In the Guest or External Users dropdown, select the desired user type(s).
-
Select Next to proceed to the Summary step.
-
-
Summary: Review all assignments configured in the previous step(s).
-
To edit one or more settings, select Back.
-
To save your changes and implement the direct assignment, select Confirm.
-
-
After policy baselines have been assigned to customers, they can be directly assigned to all users and/or all devices in that customer. Alternatively, you may directly assign policies to group templates.
To directly assign policy baselines to all users and/or all devices or Group Templates in an account at the MSP level:
-
In Nerdio Manager, at the MSP level, expand Baselines.
-
Select Policy Baselines.
-
Locate the policy baseline you wish to work with.
-
Select Edit policies.
-
Locate the policy you wish to work with.
-
Select Edit.
-
Enter the following information:
-
Sync mode.Select the sync mode.
-
Version : From the drop-down list, select the version.
-
In the Configure Direct Assignment dialog box, configure the following information:
-
Included Groups: Select the Add All Users or Add Group button, and then configure each one as follows:
-
Add All Users: From the drop-down list, select the filter required, and then select the toggle to Exclude or Include.
-
Add Group: From the drop-down lists, select the group template, and the filter required, and then select the toggle to Exclude or Include.
-
-
Excluded Groups: Configure the excluded groups as follows:
-
Select the Add Group button to select groups to be excluded.
-
From the drop-down list, select the group template.
-
-
State: From the drop-down list select how to publish this policy.
-
Evaluate user/group assignment: Select this option to load assignments on the status page.
-
-
-
Select Save.
-
Select Apply and Close.
Once policies and profiles are created at the MSP level and assigned to customer accounts, you can change them at the MSP level and republish to the assigned customer accounts. This enables you to publish changes from the policies at MSP level to customer accounts.
Note
This option is available only for policies and profiles that are assigned to customer(s).
To republish policies and profiles to customers at the MSP level:
-
In Nerdio Manager, at the MSP level, expand Policies.
-
Select one of the following policy types to work with:
-
Entra
-
Conditional Access
-
-
Devices
-
Configuration Profiles
-
MAM Policies
-
Autopilot Profiles
-
Enrollment Status Pages
-
-
Security
-
Security Baselines
-
Compliance Policies
-
Update Rings
-
Endpoint Security Policies
-
Defender O365 Policies
-
-
-
Locate the policy or profile you wish to re-publish.
-
From the action menu, select Re-publish.
-
In the confirmation dialog box, review the information and select Confirm.
Note
If Intune has been disabled for an account that has a policy or profile assigned to it, you receive this message.
When making policy changes, Nerdio Manager allows you to select whether or not to republish manual assignments, or to immediately publish automatic assignments.
To publish updated policies and profiles
-
In Nerdio Manager, at the MSP level, expand Policies.
-
Select the policy you want to work with, and make the required edits and updates.
-
Depending on the assignments types included in the policy, select Re-publish for manual sync type assignments or Publish now for automatic sync type assignments.
-
Select Confirm.
The selected polices are now published.
Nerdio Manager allows you to export a list of polices as a CSV file.
To export a list of policies as a CSV file:
-
At the MSP level, expand Policies.
-
Select one of the following policy types to work with:
-
Entra
-
Conditional Access
-
-
Devices
-
Configuration Profiles
-
MAM Policies
-
Autopilot Profiles
-
Enrollment Status Pages
-
-
Security
-
Security Baselines
-
Compliance Policies
-
Update Rings
-
Endpoint Security Policies
-
Defender O365 Policies
-
-
-
Select the download
icon to download the selected policy as a CSV file.
-
The file is downloaded to the downloads folder in your browser.
Comments (0 comments)