Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Redmond desk8 min

Create and Deploy Windows Device Restriction Policies in Microsoft Intune (2026 Guide)

A current, practical guide to creating Windows device restriction profiles in Intune, choosing settings, staging assignments, checking status, and resolving conflicts.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Intune device restriction profiles let you control selected Windows features and user experiences—such as password behavior, Microsoft Edge, Settings access, Store usage, connectivity, Start, Search, and Windows Spotlight—on enrolled devices. In the current Intune admin center, create the profile for Windows 10 and later, assign it to carefully scoped Microsoft Entra groups, and verify that devices actually receive and process it.

Windows 10 reached end of support on October 14, 2025. Intune may still allow eligible Windows 10 devices to enroll and process supported settings, but Microsoft warns that functionality is not guaranteed. Treat Windows 10 policies as transitional where possible and prioritize a supported Windows 11 plan.

What a device restriction profile does

A device restriction profile is a Windows configuration profile containing policy settings that enable, disable, or limit selected device and user behaviors. The available controls depend on Windows edition, build, management mode, and the current Intune service. Microsoft’s setting reference is the authority for individual support requirements: Windows device restriction settings.

Typical uses include reducing unwanted consumer features, limiting access to managed settings, standardizing lock-screen behavior, controlling selected Edge features, and restricting Bluetooth, tethering, Store, or personalization options. A setting labelled “Block” may remove a user-interface path without eliminating every technical route to the same capability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

What it is not

Policy type Primary purpose
Device restrictions Control selected Windows features and user/device behavior.
Settings catalog Offer a broader, granular collection of configurable settings.
Security baseline Apply Microsoft-recommended security configurations.
Endpoint security Manage Defender, antivirus, firewall, encryption, account protection, and attack-surface reduction.
Compliance policy Evaluate whether a device meets requirements; it does not primarily configure the device.
Conditional Access Control access to resources based on identity, device, risk, or compliance.
Enrollment restriction Control which platforms, ownership types, or categories may enroll.

Enrollment restrictions decide whether a device can enroll; device restriction profiles configure an enrolled device. See the distinction in Intune enrollment restrictions. Device restrictions can replace some Group Policy scenarios, but they are not a universal Group Policy replacement.

Supported Windows versions and editions

The portal selection is generally Windows 10 and later. Individual controls can require a particular edition, build, or Policy CSP capability, so check the Microsoft setting reference before making a control a design dependency. Windows 10 is beyond standard support as of October 14, 2025; do not build a long-term security architecture around unsupported Windows 10 merely because Intune still accepts a device.

Microsoft’s security baseline overview explains the lifecycle and supported baseline context. Validate every important setting on the exact Windows edition and build used by your organization.

Prerequisites and preparation

  • An active Intune tenant and appropriate Intune licensing for the targeted users or devices.
  • Windows devices enrolled through a supported MDM enrollment method. Creating a profile does not enroll a device.
  • Intune RBAC permissions to create profiles, assign groups, and view device status.
  • A Microsoft Entra security group containing the intended pilot users or devices.
  • A documented owner for each setting, a pilot population, and a rollback or exception plan.
  • Awareness that a device must check in before it can receive an updated assignment.

Create the profile in the current Intune admin center

Microsoft changes portal labels periodically. The current documented configuration area is under Devices > Manage devices > Configuration; older articles may call this “Device Configuration > Profiles.” Use the current labels shown in your tenant.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Sign in to the Microsoft Intune admin center.
  2. Open Devices, then Manage devices > Configuration.
  3. Select Create or Create policy/profile.
  4. Choose Platform: Windows 10 and later.
  5. Choose the Device restrictions template.
  6. Enter a descriptive name and description. For example, use WIN-DeviceRestrictions-Pilot-Corporate and explain that it is a pilot profile whose conflicts and user impact must be reviewed.
  7. Configure only the settings you have a documented reason to manage.
  8. Apply scope tags if your tenant uses RBAC segmentation.
  9. Assign the profile to a pilot user or device group.
  10. Review the configuration and select Create.

For the general profile workflow, see Create device configuration profiles. Assignment details are covered in Assign device profiles.

Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
  • 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
  • 4GB DDR4 System Memory; 128GB Solid State Drive
  • 11.6" HD (1366 x 768) Multi-Touch Display
  • Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
  • Windows 11 Pro

Choose restrictions deliberately

Prefer Not configured unless the organization has a clear business, support, privacy, or security reason to manage a setting. For each non-default control, record the risk addressed, expected user impact, test owner, and rollback method.

Category Practical use Test before rollout
Password Require selected password behavior where supported. Interaction with Windows Hello for Business and authentication policy.
Personalization Limit user changes to managed branding or appearance. Accessibility, user experience, and support requests.
Locked screen experience Standardize lock-screen behavior. Shared-device usability and sign-in workflows.
Microsoft Edge Control selected browser features and data-sharing behavior. Enterprise sites, extensions, authentication, and line-of-business applications.
Control Panel and Settings Reduce users’ ability to alter managed configuration. Help-desk diagnostics and administrative support procedures.
App Store Control Store access or Store-app updates. Application distribution and update dependencies.
Defender Configure selected Defender-related controls. Overlap with endpoint-security policies and security baselines.
Connectivity Restrict selected Bluetooth, Wi-Fi, cellular, VPN, or tethering behaviors where supported. Peripherals, remote work, and required network access.
Start and Search Limit consumer-oriented features or interface changes. Productivity, accessibility, and support workflows.
Cloud and storage Control selected synchronization or cloud-storage behaviors. Data-access requirements and approved collaboration tools.
Windows Spotlight and Display Manage selected content and display experiences. Usability and device-specific display behavior.

Avoid casual Defender exclusions: an exclusion can weaken malware protection. Validate password restrictions against Windows Hello for Business, and check edition support for every control that matters to the design.

Assign the policy without creating a large blast radius

Use a staged rollout

  1. Create a small pilot device group containing representative corporate devices.
  2. Deploy to that group and test standard users, administrators, accessibility tools, shared-device scenarios, and line-of-business applications.
  3. Expand to a department or business unit only after reviewing status and support impact.
  4. Deploy broadly after the pilot has produced no unacceptable conflicts.

Choose user or device targeting

  • Device groups: best when the requirement belongs to hardware, shared devices, or corporate-owned computers regardless of who signs in.
  • User groups: useful when settings should follow a person across applicable managed devices or are defined by role or department.
  • Dynamic groups: membership changes with attributes; validate the membership rule before relying on it for a high-impact control.
  • Filters: narrow applicability by properties such as ownership, manufacturer, OS version, or enrollment type without creating many groups.

Use exclusions for break-glass accounts, test devices, kiosks, privileged administrators, or special-purpose hardware. A user assignment can affect multiple devices; a device assignment can affect every user on a shared computer.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify that the policy was actually applied

An assignment entry proves targeting, not successful processing. After devices check in, inspect:

  • The profile overview and included or excluded assignments.
  • User and device check-in information.
  • Per-device and, where available, per-setting status.
  • Succeeded, Pending, Error, Conflict, and Not applicable states.
  • The actual Windows behavior, not just the portal status.

When portal data is insufficient, review Windows MDM diagnostic logs and relevant Event Viewer entries. Confirm whether another Intune profile, security baseline, endpoint-security policy, Group Policy object, Configuration Manager workload, local setting, or third-party agent controls the same underlying setting.

Rank #3
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Troubleshoot common failures

The device never receives the profile

  • Confirm that the device is MDM-enrolled and belongs to the intended group.
  • Check that the assignment is not excluded by a group or filter.
  • Verify that the device has checked in; do not assume immediate application after saving.
  • Confirm that the selected platform and enrollment scenario match the device.

The status is Not applicable

Common causes include an unsupported Windows edition or build, an unavailable prerequisite, an incorrect platform, or a management mode that does not implement the setting. “Not applicable” is not automatically an Intune service failure.

The status is Conflict or Error

Look for two device restriction profiles setting different values, overlap with a security baseline or endpoint-security profile, competing Group Policy, co-management ownership, or multiple baseline versions. Establish one policy owner for each setting domain rather than allowing several profiles to compete.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The setting remains after removal

Changing a profile normally takes effect after the device receives the update, but removing a profile does not always restore the prior local value. “Not configured” and deletion are not universally equivalent; behavior depends on the setting and its Policy CSP. Test rollback on a pilot device before promising automatic restoration.

Recovery and rollback procedure

  1. Remove the affected device or user from the assignment group.
  2. Add it to an approved remediation or exception group if one exists.
  3. Trigger a manual sync from Windows or the Intune admin center.
  4. Review per-device status and identify the conflicting policy.
  5. Deploy a tested replacement or restore the previous value through the correct policy owner.
  6. Verify the local result and document whether any value persisted after removal.

Keep device restrictions in the right policy architecture

Microsoft security baselines are collections of recommended security settings and can overlap with device configuration and endpoint-security policies. Use a baseline for Microsoft’s recommended security posture, endpoint-security profiles for focused Defender, firewall, encryption, account-protection, and attack-surface-reduction controls, device restrictions for selected user-interface and feature behavior, compliance policies to evaluate requirements, Conditional Access to protect resource access, enrollment restrictions to control enrollment eligibility, and update policies for Windows servicing.

Microsoft documents baseline overlap and conflict considerations in its security baselines overview. Dedicated endpoint-security controls are described in Endpoint protection settings, while compliance evaluation is covered by Windows compliance settings.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Example deployment design

  1. Pilot: Assign WIN-DeviceRestrictions-Pilot-Corporate to a small device group with representative hardware and users.
  2. Review: Check conflicts, unsupported settings, application compatibility, accessibility, and help-desk procedures.
  3. Department rollout: Expand to a business unit and monitor status through another check-in cycle.
  4. Broad deployment: Assign to the production device group with documented exclusions and filters.
  5. Governance: Record the owner, reason, test evidence, exceptions, and rollback steps for every non-default setting.

Frequently asked questions

Does creating a profile enroll a Windows device?

No. Enrollment must already exist through a supported Intune MDM method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does the profile make a device compliant?

No. A configuration profile changes settings; a compliance policy evaluates whether requirements are met.

Can I assign a device restriction profile to users?

Yes. User assignments are supported, but the resulting scope can include multiple applicable devices. Use device assignments when the requirement is tied to hardware.

Can device restrictions replace a security baseline?

No. Restrictions and baselines serve different purposes and may overlap. Define a single owner for each setting to avoid conflicts.

Why does a setting show Not applicable?

The edition, build, platform, enrollment mode, or prerequisite may not support that control. Check the Microsoft setting reference for the exact requirement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
15.6 Inch Win 11 Laptop Computer, N4020, 4GB DDR4 RAM, 128GB Storage
  • WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
  • 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
  • 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
  • CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
  • LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.

How quickly will a change apply?

The assignment is saved immediately, but application depends on the device’s next Intune check-in and successful policy processing. No universal application time should be promised.

Frequently Asked Questions

Is this a replacement for Group Policy?

Intune can replace some Group Policy scenarios, but coverage, policy precedence, CSP support, and coexistence requirements vary. Avoid configuring the same setting through both systems unless the interaction is understood.

What should I do before assigning restrictions to all devices?

Use a representative pilot group, test standard and privileged users, review conflicts and support impact, document exceptions, and maintain a tested rollback procedure.

The Bottom Line

Use Windows device restriction profiles for narrowly defined feature and user-experience controls, deploy them through staged Microsoft Entra assignments, and verify per-device results after check-in. Combine them with security baselines, endpoint-security, compliance, Conditional Access, and update policies—and treat Windows 10 as a migration priority after its October 14, 2025 end of support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99
Bestseller No. 2
Dell Latitude 3190 11.6' HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core; 4GB DDR4 System Memory; 128GB Solid State Drive
Bestseller No. 3
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$294.98

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.