Intune device configuration profiles— what is best practice?

Posted by Axelpeach@reddit | sysadmin | View on Reddit | 20 comments

We use Intune for our MDM. Was curious to know how y’all configure your configuration profiles for Windows devices.

I guess my main dilemma is that an individual on our security team is pushing us to lump ALL settings of the same policy type into one profile. (Ie, all settings catalog settings in one profile, all administrative templates in one profile). As a way to lessen the amount of profiles that we have.

Eg, All edge settings, M365 app settings, chrome settings into one profile.

Is this frowned upon?

I guess I would create+name them by their purpose/function. This seems like what a lot of orgs do, l based on initial research.