Endpoint Services, MECM, Group Policy interaction in MECM
Overview
What is the recommended use of MECM versus group policy objects (GPOs)?Systems
Microsoft Endpoint Configuration Manager (MECM)
Intended Audience
University of Illinois IT Pros leveraging MECM, hosted by Technology Services' Endpoint Services team
General Information
Group Policy Objects (GPOs) remain unchanged by MECM; IT Pros can continue to apply configuration settings or restrictions for software via GPOs. Endpoint Services recommends that you deploy applications via MECM instead of GPOs, as MECM has many more features.
MECM can also manage compliance via Configuration Items and Configuration Baselines:
- Configuration Items are often scripts that evaluate whether an endpoint is set up properly for a particular purpose. For example: Is the endpoint configured to use a device-based subscription for Office 365? Does the endpoint have a valid certificate from Active Directory Certificate Services?
- Navigate to \Assets and Compliance\Overview\Compliance Settings\Configuration Items in the console to view configuration items managed by Endpoint Services
- Navigate to \Assets and Compliance\Overview\Compliance Settings\Configuration Items in the console to view configuration items managed by Endpoint Services
- Configuration Baselines are collections of Configuration Items. Configuration Baselines are useful for summarizing compliance with a set of more detailed requirements, such as determining if a set of applications used in a unit or college are installed on the endpoint.
- Navigate to \Assets and Compliance\Overview\Compliance Settings\Configuration Baselines in the console to view configuration baselines managed by Endpoint Services
Microsoft has published a step-by-step guide to writing configuration items and creating configuration items.