Intune ADMX policies - Apply synchronously?

Robert Meany 0 Reputation points
2024-05-10T14:42:36.82+00:00

I've been trying to build out a restrictive profile for public user accounts on shared laptops. We need the local profiles for these accounts to be deleted on logoff, and I've achieved this using a combination of Shared PC settings and Assigned Access. I had to write a custom Assigned Access XML to allow users to save to their external drives (the basic kiosk template provided in intune does not allow for this). Now that I've been able to give them access to external drives, I noted that they are able to access the settings app through the file explorer window. Normally I could remove the pinned shortcuts at the top of the file explorer window via admx templates assigned to the user, but it seems that admx templates do not apply during first user login, which will always be the case as we are deleting their profiles during logoff. I was wondering if there is a way to force admx processing synchronously, similar to synchronous policy processing in GP, to ensure they get their admx settings on first login?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,747 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 8,840 Reputation points Microsoft Vendor
    2024-05-13T05:29:33.75+00:00

    @Robert Meany,Thanks for posting in Q&A.

    Based on my experience, when you create ADMX policies from Intune or and assign them to a user, the user needs to log into the device and sync with Intune to get the relevant policy, you can try to sync with Intune to get the ADMX policy when user first login in.

    Honestly, I've never encountered this issue, but you could try assigning the ADMX policy to the device group and see if you can apply it the first time the user logs in.

    Hope it will help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.