Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Custom OMA-URI policies are created and deployed through Microsoft Intune, not directly from the traditional Configuration Manager (SCCM/ConfigMgr) console. In a co-managed environment, Configuration Manager can continue handling its assigned workloads while Intune delivers Windows MDM policies. To deploy one, identify a supported Windows Configuration Service Provider (CSP) setting, create a Windows custom configuration profile in Intune, assign it to a pilot group, and verify the result on the device.
This distinction matters: installing the Configuration Manager client or enabling co-management does not add an OMA-URI editor to the ConfigMgr console. The steps below cover the Intune workflow and explain where ConfigMgr fits.
What an OMA-URI policy is
An OMA-URI is a path to a setting exposed by a Windows Configuration Service Provider (CSP). Intune sends the setting through Windows MDM using the OMA-DM protocol; the CSP processes it on the device. It is not an arbitrary registry path, and you cannot make a valid URI simply by guessing a registry location. The CSP documentation defines the node, scope, supported operations, data type, value format, and Windows applicability. See Microsoft’s overview of deploying OMA-URIs to a target CSP.
Free tools Windows power users keep installed
One-click scans. No signup required.
Use a custom OMA-URI profile when a required CSP setting is not exposed in Intune’s normal interface, or when you need to configure a documented CSP value directly. If the setting is already available in the Settings Catalog, Administrative Templates, Endpoint security, or a dedicated profile, prefer that interface: it is easier to validate and maintain.
#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Before you create the profile
- Intune management: The Windows device must be enrolled in Intune MDM or managed through a co-management arrangement that includes Intune. You also need permission to create device configuration profiles, such as the Policy and Profile Manager role or equivalent custom permissions.
- A verified CSP setting: Start at the relevant Microsoft CSP reference—for example, the Policy CSP, ApplicationManagement CSP, AccountManagement CSP, BitLocker CSP, or Firewall CSP. Confirm the exact setting in its current documentation rather than relying on an old example.
- Scope and applicability: Check whether the setting is user- or device-scoped and which Windows releases, builds, and editions support it. The profile’s “Windows 10 and later” platform label does not mean every setting works on every Windows version or edition.
- A pilot and rollback plan: Test on a device or small group first. Find out how the CSP removes or reverses the setting before deploying it broadly.
- A conflict check: Check whether Group Policy, ConfigMgr, another Intune profile, a script, or a vendor agent already manages the same setting.
Before building the profile, record the CSP and node, exact OMA-URI and capitalization, scope, data type, permitted value, supported Windows versions, and any documented Add, Replace, or Delete behavior. The CSP—not a general Intune rule—determines the correct payload.
Create a custom profile in Intune
In the current Intune admin center, go to Devices > Manage devices > Configuration > Create > New policy. Set Platform to Windows 10 and later, then choose Custom as the profile type. Depending on the portal experience, Custom may appear under Templates > Custom. Microsoft’s custom settings profile instructions describe the workflow. Portal labels can change; older layouts used paths such as Devices > Windows > Configuration profiles.
- Name the profile. Use a name that identifies the CSP, setting, scope, and purpose—for example,
Windows - Connectivity - AllowVPNOverCellular - Device - Pilot. Add a description with the CSP source, supported Windows version, owner, expected behavior, change reference, and rollback notes. - Add a configuration setting. In Configuration settings, select Add. Enter a readable name and description, then provide the exact OMA-URI, data type, and value specified by the CSP documentation.
- Review the setting. Check every character of the URI, including the leading
./where specified, as well as scope, data type, value format, and Windows applicability. - Configure scope tags if needed. Scope tags limit which administrative groups can view or manage the profile; they do not replace assignment targeting.
- Assign the profile to a pilot. Select the appropriate user or device group, review exclusions, and use a small test group before expanding deployment.
- Review and create. Confirm the setting, assignment, exclusions, and tags, then select Create.
A profile can contain multiple OMA-URI settings. Keep settings together only when they share scope, ownership, rollout timing, and rollback needs. Separate profiles make conflicts and changes easier to trace when settings have different owners or risk levels.
Rank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
Example: allow VPN over cellular
Microsoft’s custom-profile guidance includes this example. Treat it as an illustration of the fields, not as a universal policy: verify the current CSP documentation and device applicability before deploying.
| Field | Example value |
|---|---|
| Profile platform and type | Windows 10 and later; Custom |
| Name | Allow VPN over cellular |
| OMA-URI | ./Vendor/MSFT/Policy/Config/Connectivity/AllowVPNOverCellular |
| Data type | Boolean |
| Value | True |
The URI and Boolean type come from the underlying CSP setting, not from a generic Intune convention. Do not copy them for another policy or assume another URI accepts the same type.
Use the correct scope
Policy CSP paths commonly distinguish user and device scope, as in these general forms:
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
./User/Vendor/MSFT/Policy/Config/AreaName/PolicyName
./Device/Vendor/MSFT/Policy/Config/AreaName/PolicyName
Result paths commonly use ./User/Vendor/MSFT/Policy/Result/... or ./Device/Vendor/MSFT/Policy/Result/.... These are general patterns, not instructions to add a scope segment to every URI. Follow the specific CSP node’s documented path; do not change its scope based on a different example.
Roll out and verify the policy
Use a staged rollout: one test device, an IT pilot, a representative user pilot, and then broader groups as results allow. A device group is generally the natural target for device-scoped configuration, and a user group for user-scoped configuration, but the CSP’s requirements and your assignment design govern. Confirm group membership and exclusions before expanding deployment.
After assignment, review the profile’s per-device status and, where available, per-setting status in Intune. Check for errors and conflicts, and confirm that the device checked in. An assignment or success status alone does not prove that users will observe the expected behavior.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
On Windows, inspect the MDM diagnostic report and the Event Viewer log at:
Applications and Services Logs
> Microsoft
> Windows
> DeviceManagement-Enterprise-Diagnostics-Provider
> Admin
You can also trigger a manual sync from the device’s Work or School account settings. A sync request does not guarantee immediate application: delivery depends on connectivity, enrollment, check-in, and policy processing. Validate the actual setting behavior and consider whether it requires a restart, sign-out, or a new session.
Troubleshoot by where the failure occurs
- The profile is not assigned or has not reached the device. Verify Intune MDM enrollment, group membership, the correct user or device targeting, exclusions, last check-in, and the device’s MDM authority. In co-management, check whether the relevant workload is assigned to Intune.
- The device receives the profile, but the setting reports an error. Compare the URI character by character with the CSP reference. Check capitalization, scope, data type, permitted value, operation, Windows edition/build, and any XML or Base64 requirements. For ADMX-backed settings, verify prerequisites and the expected payload structure. Use the event log’s error details to narrow the cause.
- Intune reports success, but behavior has not changed. Check for another policy source, wrong user/device scope, an unsupported build, or a requirement to restart or sign out. A CSP can accept a value without producing an immediate visible change in the current session.
- The setting behaves unexpectedly after another policy is applied. Look for overlapping configuration from Group Policy, ConfigMgr scripts or compliance settings, Intune Settings Catalog, Administrative Templates, Endpoint security, another custom profile, or a vendor management agent. Precedence varies; do not assume Intune always wins.
- Removing the profile does not restore the prior state. Reversion is CSP-specific. Unassigning or deleting an Intune profile does not universally restore the Windows default. Check the CSP’s removal behavior and, where supported, prepare an explicit rollback value or Delete operation. Test rollback before production rollout.
What Configuration Manager and co-management do
Configuration Manager (formerly commonly called SCCM) manages its own workloads through the ConfigMgr console and client. It can continue handling applications, software updates, operating-system deployment, client settings, task sequences, and configuration baselines. Its custom client settings are not the same thing as an Intune custom OMA-URI profile; see Microsoft’s Configuration Manager client settings documentation.
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
In co-management, Configuration Manager and Intune can manage the same Windows device, with workloads divided between them. Intune remains the normal place to author and deliver OMA-URI profiles. Co-management does not add an OMA-URI editor to ConfigMgr. Review Microsoft’s co-management FAQ and coexistence guidance, and avoid having both systems independently configure the same setting unless the desired precedence and behavior are understood and tested.
Choose the right configuration method
| Need | Good first choice | Why |
|---|---|---|
| The setting is already exposed in Intune | Settings Catalog or a dedicated profile | Less manual URI and data-type entry; easier to maintain. |
| A traditional administrative-template setting | Administrative Templates or supported ADMX ingestion | Provides a managed interface for the policy; avoids manually constructing a payload where possible. |
| A documented Windows CSP setting absent from Intune’s UI | Custom OMA-URI profile | Delivers the documented setting through Windows MDM. |
| Conditional logic or a complex action not exposed by a CSP | PowerShell script or Intune remediation | Can evaluate conditions and log custom actions, but needs careful handling of execution context, idempotency, and rollback. |
| A ConfigMgr-managed compliance or remediation task | Configuration Manager baseline | Uses the ConfigMgr client and collections; it is not a substitute for MDM CSP delivery. |
| Assess whether a device complies with a requirement | Compliance policy or ConfigMgr baseline | Evaluation is different from configuring a value. |
For ADMX-backed settings, use Settings Catalog or imported templates when the required policy is available there rather than hand-building an OMA-URI payload. Microsoft documents ADMX template configuration for Windows in Intune. For Microsoft Edge, also avoid overlapping custom OMA-URI and Administrative Template settings; Microsoft’s Edge MDM guidance warns that duplicate policy sources can lead to unpredictable results.
Plan lifecycle and rollback before broad deployment
Keep each profile understandable and owned. Document its CSP source, URI, type, value, supported versions, target group, and removal procedure. Test assignment, change, and unassignment on a pilot device. If the CSP requires a separate rollback value or operation, prepare that explicitly rather than relying on profile deletion. This makes it easier to distinguish a delivery problem from a setting conflict or a CSP-specific removal behavior.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

