Lab 19: Intune Configuration Profile

Created and validated a Microsoft Intune settings-catalog profile to standardise the Microsoft Edge startup experience on the cloud-native Windows pilot device.

Overview

This lab continued the Nietz Ltd Intune pilot by moving from device enrolment, compliance, and Conditional Access validation into Windows configuration management. I used Microsoft Intune to deploy a settings catalog profile that configures Microsoft Edge to open the Microsoft 365 apps page at startup on the pilot device group.

The completed configuration targeted the cloud-native Windows pilot device CL2, assigned to Chloe Bennett. The final evidence confirms the policy was created, assigned to the correct device group, delivered successfully to CL2, visible in Edge policy state, and working in the browser.

Objective

The objective was to create a device-targeted Intune configuration profile that applies a standard Microsoft Edge startup URL for Nietz Ltd pilot devices, then validate the policy through Intune deployment status, Windows sync evidence, Edge policy reporting, and the final user experience.

Environment

Environment
ComponentValue
CompanyNietz Ltd
Microsoft 365 / Entra domainnietz.co.uk
Management platformMicrosoft Intune
Configuration profileWIN-CFG-01-Endpoint-User-Experience-Standards
Profile typeWindows 10 and later - Settings catalog
Target groupGRP_Intune_Windows_Pilot_Devices
Pilot deviceCL2
Primary user[email protected]
Join typeMicrosoft Entra joined
Previous dependencyLab 18: Conditional Access pilot validation

Configuration

1. Confirmed the Intune Windows Device Inventory

I confirmed that both Windows pilot devices were visible in Intune, compliant, corporate-owned, and reporting their expected join types before creating the new configuration profile.

Intune Windows device inventory showing CL1 and CL2
Figure 1 Intune Windows device inventory showed CL1 and CL2 as compliant managed devices.
Context: This confirmed the pilot estate was ready for device-targeted configuration deployment.

2. Confirmed the Pilot Device Group

I validated that GRP_Intune_Windows_Pilot_Devices contained only CL2, keeping the first endpoint user experience policy limited to the cloud-native pilot device.

GRP Intune Windows Pilot Devices membership showing CL2
Figure 2 The pilot device group contained CL2 as the single direct device member.
Context: Using a device group kept the policy assignment predictable and avoided impacting the hybrid pilot device during this stage.

3. Created the Settings Catalog Profile

I created the Intune profile WIN-CFG-01-Endpoint-User-Experience-Standards using the Windows settings catalog profile type.

Intune settings catalog profile basics for endpoint user experience standards
Figure 3 Profile basics showed the configured name, description and Windows platform.
Context: Settings catalog profiles provide granular Intune configuration for modern Windows management.

4. Configured Microsoft Edge Startup Behaviour

I configured Microsoft Edge to open a defined startup URL and set the URL to https://www.microsoft365.com/apps.

Microsoft Edge startup URL configured in Intune settings catalog
Figure 4 Microsoft Edge startup settings were configured to open the Microsoft 365 apps page.
Context: This creates a consistent start point for users and demonstrates device-based browser policy management through Intune.

5. Assigned the Profile to the Pilot Device Group

I assigned the profile to GRP_Intune_Windows_Pilot_Devices, with no filters and no excluded groups.

Intune configuration profile assigned to Windows pilot device group
Figure 5 The configuration profile was assigned to the pilot device group containing one device.
Context: A narrow pilot assignment reduces rollout risk and matches a staged endpoint management approach.

6. Confirmed the Profile Was Created

I confirmed the new configuration profile appeared in the Intune configuration policy list with the expected platform, policy type and default scope tag.

Intune configuration profile created in policy list
Figure 6 The endpoint user experience standards profile appeared in the Intune policy list.
Context: The policy list provided portal-level evidence that the configuration profile was created successfully.

Validation

7. Synced CL2 with Intune

I manually synced CL2 from Windows Settings and confirmed the device remained managed by Nietz Ltd after the configuration profile assignment.

CL2 Access work or school sync successful after Intune policy assignment
Figure 7 CL2 showed a successful Intune sync from the Access work or school management page.
Context: Manual sync shortened the validation cycle and confirmed the device could receive management updates.

8. Confirmed Successful Deployment to CL2

I validated the Intune device assignment report and confirmed CL2 reported a successful check-in for the profile.

Intune policy deployment succeeded for CL2
Figure 8 The profile deployment report showed CL2 with check-in status Success.
Context: This linked the policy assignment to the actual managed device rather than only showing a profile summary.

9. Validated Microsoft Edge Policy State

I confirmed the applied Edge policies from edge://policy, including RestoreOnStartup and RestoreOnStartupURLs, both applying to the device at mandatory level.

Edge policy page showing RestoreOnStartup and RestoreOnStartupURLs applied
Figure 9 Edge policy reporting showed the configured startup policy values applied successfully.
Context: Browser-side policy validation confirmed the Intune setting was active on the endpoint.

10. Confirmed the User Experience

I opened Microsoft Edge on CL2 and confirmed the browser landed on the Microsoft 365 apps page for Chloe Bennett.

Microsoft Edge opening the Microsoft 365 apps page on CL2
Figure 10 Microsoft Edge opened the Microsoft 365 apps page as configured by Intune.
Context: The final validation connected the admin-side policy to a visible endpoint user experience.

Key Technical Outcomes

The completed work covers Intune settings-catalog profile creation, device-group targeting, controlled pilot assignment, manual device sync, deployment validation, Edge policy verification and confirmation of the endpoint user experience.

Summary

  • Confirmed CL1 and CL2 were visible as compliant Intune-managed Windows devices.
  • Validated GRP_Intune_Windows_Pilot_Devices contained CL2 as the pilot target.
  • Created WIN-CFG-01-Endpoint-User-Experience-Standards as a Windows settings catalog profile.
  • Configured Microsoft Edge to open https://www.microsoft365.com/apps at startup.
  • Assigned the profile to the pilot device group with no filters or exclusions.
  • Synced CL2 and confirmed the Intune deployment completed successfully.
  • Validated the applied Edge policy and confirmed the Microsoft 365 apps page opened on CL2.