Intune: Policies or Profiles?

M. Jeffrey 0 Reputation points
2026-09-25T15:31:44.1333333+00:00

I've been studying Intune and Entra for a long time now, but something that always bothered me is that the use of "Policies" versus "Profiles" is scattered and inconsistent.

The most ergregious examples are the "Feature updates" and "Quality updates".

Quality updates are "Quality update policies"

policy1

Furthermore, Device Configuration is called a "Device Configuration policy" within the Intune environment...

policy3

policy4

Here's one more example of a page mentioning both "Policies" AND "Profiles" !

policy5

Would love to hear from you why it is this way. Why not refer to it as one name to prevent confusion?

Microsoft Security | Intune | Configuration
0 comments No comments

1 answer

Sort by: Newest
  1. Marcin Policht 109.8K Reputation points MVP Volunteer Moderator
    2026-09-25T17:17:25.4833333+00:00

    This is largely the result of legacy platform history, multiple product teams, and terminology that evolved as cloud management capabilities were added. Microsoft did not design the entire Intune management model from scratch with one consistent naming convention. Instead, terminology from mobile device management, Windows management, Group Policy, Configuration Manager, Entra ID, and Windows Update for Business accumulated in the same administrative experience.

    There are particularly strong historical reasons for the word “profile.” Mobile device management was heavily influenced by platforms such as Apple’s configuration framework, where configuration profiles were a fundamental concept. A profile represented a package of settings that could be delivered to a device, such as Wi-Fi, VPN, email, certificates, or device restrictions. Windows management came from a different tradition, where administrators were accustomed to Group Policy Objects and security policies. When Intune expanded into a unified management platform for Windows, iOS/iPadOS, macOS, Android, and other platforms, these different concepts and terms came together.

    There was originally a reasonably useful conceptual distinction between the two terms. A profile generally represented a collection of configuration settings that would be applied to a user or device. A Wi-Fi profile, VPN profile, email profile, or Windows configuration profile fits that model. A policy generally represented a rule governing behavior or determining whether a condition was satisfied. A compliance policy defines what constitutes a compliant device, while an app protection policy defines rules governing how organizational data can be used by an application.

    That distinction is useful, but it is not a strict architectural boundary in modern Intune. Microsoft uses “policy” much more broadly now, and individual Intune workloads have their own terminology. Feature update policies and quality update policies are good examples. These are specialized Windows Update management objects rather than generic collections of configuration settings, so Microsoft calls them policies because they govern how Windows updates are deployed and managed. Device configuration profiles, on the other hand, are configuration objects containing settings that are applied to devices or users.

    The confusion becomes even greater with the Settings Catalog. You create a configuration profile in the Intune interface, populate that profile with settings, and then assign it to users or devices. Conceptually, you are using a profile to deploy a set of configuration rules. As a result, documentation can legitimately describe the same activity in terms of configuring a profile or deploying a configuration policy. The terminology starts describing the purpose of the object rather than providing a precise technical classification.

    This is also why you can encounter “Device Configuration Policy” in Microsoft documentation or the Intune interface even though the actual object is a “configuration profile.” In many cases, “policy” is being used generically to mean a set of management instructions rather than as the precise name of the underlying Intune object type.

    The same issue exists across Entra and Intune because they contain different generations of management functionality. Conditional Access policies, authentication policies, compliance policies, update policies, app protection policies, configuration profiles, endpoint security policies, and Settings Catalog profiles were not all created as variations of one original object model. They represent different workloads that Microsoft has progressively brought together under a common administrative experience.

    So I would not treat “policy” versus “profile” as a universal technical distinction in Intune. A useful working model is that a profile generally describes the configuration object or package of settings, while a policy generally describes rules or management behavior. But Microsoft does not enforce that distinction consistently. “Policy” is now a broad product term, while “profile” remains the name of several specific configuration-object types.

    The result is admittedly confusing for those trying to develop a precise mental model. Microsoft could theoretically standardize the terminology, but doing so would require renaming established objects, documentation, APIs, Graph resources, PowerShell commands, training material, and years of administrator knowledge. The current terminology is largely the accumulated result of that history. In practical terms, the safest approach is to learn the specific object type associated with each Intune workload rather than assume that “policy” and “profile” have a consistent technical meaning everywhere in the product.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.