Lab 20: Intune Device Restrictions Baseline

Created a Windows device-restrictions profile, assigned it to a controlled Intune pilot group, synchronised CL2 and confirmed that every configured setting deployed successfully.

Overview

This lab introduced a baseline Windows device restrictions policy for the Intune-managed pilot estate. The configuration focused on low-risk restrictions that reduce consumer-facing experiences and apply basic SmartScreen-related controls without blocking core device functionality.

The policy was deployed only to a dedicated pilot device group containing CL2. This kept the rollout controlled and provided clear evidence of policy creation, assignment, device sync, deployment status and per-setting success.

Objective

The objective was to create WIN-CFG-02-Device-Restrictions-Baseline, assign it to GRP_Intune_Windows_Pilot_Devices, and validate successful deployment on the pilot device CL2.

Environment

Environment
ComponentValue
CompanyNietz Ltd
Tenant / public domainnietz.co.uk
Intune profileWIN-CFG-02-Device-Restrictions-Baseline
Profile typeWindows 10 and later - Device restrictions
Target groupGRP_Intune_Windows_Pilot_Devices
Target deviceCL2
Primary user[email protected]
Deployment methodDevice-targeted Intune configuration profile
Previous lab dependencyLab 19: Intune Configuration Profiles

Configuration

1. Confirmed the existing Intune configuration profile baseline

I confirmed the Windows configuration policies area before creating the new device restrictions profile. The only existing profile at the starting point was the Lab 19 endpoint user experience profile.

Intune Windows configuration policies list before the device restrictions profile was created
Figure 1The Windows configuration policy list showed the existing Lab 19 profile before the new device restrictions baseline was added.
Context: Capturing the starting point made the new Lab 20 profile easy to identify after creation.

2. Created the device restrictions profile

I created a Windows device restrictions profile using a clear naming convention and a description that explained the purpose of the pilot policy.

Intune device restrictions profile basics showing WIN-CFG-02-Device-Restrictions-Baseline
Figure 2The profile was named WIN-CFG-02-Device-Restrictions-Baseline and created as a Windows 10 and later device restrictions profile.
Context: The naming convention separates the device restrictions baseline from the previous endpoint user experience profile.

3. Configured baseline restriction settings

I configured a limited set of safe device restriction settings. The profile required SmartScreen for Microsoft Edge Legacy, blocked malicious site access and unverified file downloads, and blocked selected Windows Spotlight and Ink workspace suggestions.

Configured Microsoft Defender SmartScreen and Windows Spotlight settings in Intune device restrictions
Figure 3The configured settings included SmartScreen-related controls, Windows Spotlight blocking and Ink workspace app suggestion blocking.
Context: Only a small set of non-disruptive settings was configured so later labs can cover Defender Antivirus, firewall, update rings and security baselines separately.

4. Assigned the profile to the Windows pilot device group

I assigned the profile to GRP_Intune_Windows_Pilot_Devices, which contained one pilot device and no user members.

Device restrictions profile assigned to GRP_Intune_Windows_Pilot_Devices
Figure 4The profile was assigned to GRP_Intune_Windows_Pilot_Devices with one device member, no filters and no excluded groups.
Context: Device-group assignment kept the rollout limited to CL2 and avoided applying the baseline across all Windows endpoints.

5. Reviewed the final configuration before creation

I reviewed the profile summary before creating it. The review page confirmed the profile name, description, configured settings and assignment target.

Review and create summary for the Intune device restrictions baseline profile
Figure 5The review page confirmed the SmartScreen, Windows Spotlight and pilot group assignment settings before creation.
Context: The review step provides a clear audit point before committing the Intune profile.

Validation

6. Confirmed the profile was created in Intune

I returned to the Windows configuration policies list and confirmed the new device restrictions profile was visible alongside the existing Lab 19 profile.

Intune Windows configuration policies list showing the new device restrictions baseline profile
Figure 6WIN-CFG-02-Device-Restrictions-Baseline appeared in the Intune policy list as a device restrictions profile.
Context: The policy list confirms the profile was created and available for monitoring.

7. Synced CL2 with Intune

I triggered a manual Intune sync from CL2 using the Windows work or school account management page. The device showed a successful sync with Nietz Ltd management.

CL2 Windows settings showing Managed by Nietz Ltd and a successful Intune sync
Figure 7CL2 completed a successful sync after the device restrictions policy was created.
Context: Manual sync reduces waiting time during policy validation and confirms the endpoint can check in with Intune.

8. Confirmed successful deployment to CL2

I checked the device assignment status report and confirmed the profile deployed successfully to CL2 for Chloe Bennett with no errors, conflicts, not-applicable results or in-progress status.

Intune device restrictions profile deployment status showing CL2 success
Figure 8The profile deployment report showed CL2 with a check-in status of Success and one succeeded device.
Context: Device assignment status confirms the policy reached the intended pilot endpoint.

9. Verified per-setting success on CL2

I opened the CL2 profile settings report and confirmed each configured setting reported a succeeded state.

CL2 profile settings report showing all configured device restriction settings succeeded
Figure 9All five configured settings reported Succeeded for CL2, with the error code column blank.
Context: Per-setting status provides stronger validation than summary counts because it confirms each individual configuration item applied successfully.

Key Technical Outcomes

This lab demonstrated Intune device restrictions profile creation, controlled device-group assignment, manual endpoint sync, device deployment status validation and per-setting reporting for a pilot Windows endpoint.

Summary

  • Confirmed the existing Windows configuration profile baseline before adding a new policy.
  • Created WIN-CFG-02-Device-Restrictions-Baseline as a Windows device restrictions profile.
  • Configured a small, safe set of SmartScreen, Windows Spotlight and Ink workspace restriction settings.
  • Assigned the profile to GRP_Intune_Windows_Pilot_Devices.
  • Synced CL2 with Intune after policy creation.
  • Confirmed the policy deployed successfully to CL2.
  • Verified all configured settings reported succeeded status for CL2.