Skip to main content

G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog

Blog

How to roll back a bad Microsoft Intune policy change (and prevent the next one)

Intune has no undo button. Learn how to roll back a bad Intune policy change with corrective policies, device checks, and backups.

A configuration profile hit the wrong Entra ID group an hour ago. Devices are applying it, the help desk queue is climbing, and you have just learned that Microsoft Intune has no undo button, no version history, and no native restore command.

Whether you own a Windows Cloud platform (Windows 365 and Azure Virtual Desktop), lead end-user computing (EUC) for the enterprise, or run a managed service provider (MSP) that keeps client baselines steady, this incident is a breakdown in how policy changes get reviewed, staged, and approved before they reach production.

Intune product owners need a real way to reverse a bad policy change correctly and stop the next one from reaching production.

Why you can't just undo a bad Intune policy change

Intune has no native rollback, versioning, or restore for any policy type, whether that's a configuration profile, a compliance policy, or a security baseline. Microsoft's own Q&A guidance for an accidentally deleted compliance policy confirms the policy cannot be restored. The closest native option is exporting a Settings Catalog policy as JSON, and that only works if someone exported it before the bad change.

Operationally, the rollback plan has to start outside the portal: find the previous values, recreate them, and push them back to devices. During an incident, that turns a quick undo into a reconstruction job.

Security baselines are stricter still where baseline versioning is forward-only. Once Microsoft ships a newer version, older-version profiles become read-only for settings, and Microsoft documents no downgrade path for profiles to an earlier baseline version. Microsoft also warns that when baseline settings are removed, the removal process "can't guarantee" that these settings return to their premanaged configuration. Baseline changes need a saved before-state too.

The harder problem sits on the device itself, where the accepted answer on Microsoft Q&A puts the behavior plainly: "If you exclude a group or remove the assignment, Intune doesn't remove the settings configured earlier by the policies. They stay on."

Admins call this policy tattooing. Intune is supposed to send a Remove command over SyncML when a policy is deleted or unassigned, and that action shows up on the device as Event 819. If Event 819 never fires, the setting keeps enforcing on the device even after the policy is gone from the portal.

To confirm what a machine is actually enforcing, check the registry key HKLM\SOFTWARE\Microsoft\PolicyManager\current\device. That's where the OS records the settings it's currently applying, and it's the fastest way to verify whether the portal state matches reality on the endpoint.

Every rollback needs a corrective policy plus this device-side check.

How to roll back a bad Intune policy change step by step

Rollback in Intune means overwriting the bad state with a corrective policy and confirming the device actually took it.

  1. Identify exactly what changed
    Go to Tenant administration > Audit logs in the Intune admin center, where every entry records who acted, which operation ran, which object changed, and whether it succeeded. Microsoft enables auditing for all customers, and admins cannot disable it. The UI filter reaches back only 30 days, and exporting to Log Analytics through Azure Monitor extends queryable retention to 730 days. One caveat: Audit events include old-value and new-value fields, but blank value fields may appear for policy settings, so don't count on the log to reconstruct a full policy body.
  2. Deploy a corrective policy and exclude the bad one
    Create a new policy with the intended (reverted) values, assign it to the same group, and add that group to the exclusions on the bad policy so the two never conflict. Conflicts matter here because configuration profiles of the same type have no precedence order, and when two set the same setting differently, Intune generates an error and applies neither.
    One platform caveat from Microsoft's troubleshooting docs: Android and iOS/iPadOS devices may need to be retired and re-enrolled to take a less restrictive policy.
  3. Force a sync rather than waiting for check-in
    A policy change triggers a push notification to online devices, typically within a few minutes for the first change. Intune then throttles further pushes to roughly one per 30 minutes per device. Steady-state Windows check-in runs about every 8 hours, and devices get only one maintenance sync per 6.5 hours regardless of client schedule. Use the Sync device action in the portal for individual machines, or push at scale with Graph PowerShell via Sync-MgDeviceManagementManagedDevice.
  4. Verify on the device, not in the portal
    Check Devices > Configuration profiles > Device status for per-device state, then confirm the registry values on a sample machine using the PolicyManager key above. If the bad policy broke compliance, budget for propagation lag before Conditional Access lets affected users back in.

That procedure covers configuration and compliance policies. Windows updates and drivers play by different rules.

Updates and drivers follow different rollback rules

When you deploy feature updates through update rings, they carry an uninstall period; once it lapses, Windows removes the rollback bits from devices and rollback is no longer possible, per Microsoft's update ring settings reference. For a problematic change inside a Windows update itself, Known Issue Rollback (KIR), Microsoft's mechanism for reverting a bad update change, deploys through a custom Intune profile.

Intune Windows driver update policies allow no rollback through those policies. Microsoft's documentation states that "policies for Windows driver updates don't support options to remove or roll-back driver updates," and admins cannot edit a driver policy's approval type after creation, so the manual-versus-automatic approval decision is permanent.

Every one of these paths assumes you know what the good state looked like. Rollback becomes a backup problem, which is why an automated snapshot carries so much weight.

Backups turn rollback from reconstruction into restore

Without a pre-change snapshot, "rollback" means rebuilding policies from memory and audit-log fragments. Native Intune offers one manual option: exporting Settings Catalog policies as JSON, one policy at a time, and imports do not carry assignments across.

Compliance policies and security baselines get no automatic coverage at all.

Community tools cover some native backup limitations:

  • The IntuneBackupAndRestore PowerShell module (jseerden) backs up and restores configuration through Microsoft Graph, including across tenants. IntuneCD commits Intune configuration to Git with automatic change detection, wired into Azure DevOps or GitHub Actions.
  • IntuneManagement tool adds a UI for exporting, importing, and comparing policies, though with documented caveats: Settings Catalog imports fail when the tenant doesn't use the Default scope tag, and its exported JSON can't be imported through the native Intune console.

Nerdio Manager for Enterprise can also create, back up, and restore Intune policies as part of the same console, a feature that carries the most weight on pooled multi-session Azure Virtual Desktop hosts, where a single misconfiguration can hit every user sharing that machine.

What a bad policy does to Windows 365 and Azure Virtual Desktop

Many enterprises run both Windows 365 and Azure Virtual Desktop, and a bad Intune policy lands differently on each. Intune manages Windows 365 Cloud PCs as their primary surface, so a bad compliance or configuration policy reaches every assigned Cloud PC on the normal sync schedule. On a pooled multi-session Azure Virtual Desktop host pool, users share hosts, so one misconfigured policy on a session host affects every user with a session on that machine; a lockout that would strand one laptop user strands an entire host's worth of sessions at once.

The tooling differs slightly too. Windows 365 audit events capture Cloud PC events for visibility and troubleshooting. For Group Policy-delivered settings on a Cloud PC, Microsoft's guidance in this scenario is to run gpupdate /force from an elevated prompt and restart. Intune policy changes still use the Intune sync path described above. dsregcmd /status verifies join state afterward.

Azure Virtual Desktop session hosts enrolled in Intune take policy like any other Windows endpoint, which means the tattooing behavior and the corrective-policy procedure apply to them unchanged.

The same corrective-policy procedure applies across both paths. Nerdio Manager extends Intune policy and profile management with documented backup, restore, and rollback capabilities.

Where Nerdio Manager fits on both paths

Nerdio Manager gives Intune admins the backup, restore, and approval layer that native tooling doesn't ship with, and the shape of that layer changes depending on whether you're running one enterprise environment or many client tenants.

The Enterprise edition focuses on approval workflows and per-edit backups inside a single organization, while the MSP edition adds Policy Baselines and drift detection across every tenant under management.

Enterprise: backup, restore, and approval in one console

Nerdio Manager extends Intune policy management by letting admins create, back up, and restore Intune policies from one console. That gives cloud desktops and Intune-managed endpoints a restore path outside native Intune.

A policy approval workflow lets a second RBAC-assigned admin review, approve, or deny Intune policy changes before they deploy, which puts a gate in front of the exact scenario this article opened with. Nerdio Manager also ships CIS-certified baseline templates, so admins get a prebuilt baseline starting point. Native Intune baselines are not formally CIS or NIST certified.

MSP: baselines, drift detection, and rollback across tenants

Nerdio Manager for MSP groups Intune policies into Policy Baselines assigned per customer, reports configuration drift, and can enforce desired state. Nerdio Manager backs up automatically every policy once a day and retains backups for 30 days, with manual point-in-time backups on demand. Backups cover all customer-level policies and assignments, even ones not actively managed through Nerdio.

When a policy drifts, the Rollback action reverts it to a chosen version with the changelog displayed, or the admin can accept the drift with an expiration of 30, 60, or 90 days. Solution Baselines extend the same model across Entra ID, Intune, Exchange Online, SharePoint, Microsoft Teams, and Microsoft Defender, with color-coded drift status per tenant.

Across both products, the operational effect is similar. Admins restore from a known backup version instead of rebuilding the policy from audit logs and memory. Nerdio Manager offers automated policy backup and restoration at the customer account level for Intune policies. Restore capability handles the last bad change. Prevention handles the next one.

How to prevent the next bad policy change from reaching production

Four controls do the bulk of the work.

  • Deployment rings reduce blast radius
    Microsoft's canonical model stages every change through Preview, Limited, and Broad deployment groups. The pilot ring should be representative. Per Microsoft's deployment planning guidance, IT staff, lab devices, and users with the newest hardware "usually don't have the applications or device drivers that are truly a representative sample of your network." Mission-critical devices typically stay back until the Broad ring completes.
  • Filters and tags narrow scope 
    Assignment filters narrow a policy by device properties and evaluate at check-in, with no group-membership processing delay. Scope tags cap which objects each admin can even see. Microsoft's Zero Trust guidance frames enforced scope tags as limiting "the blast radius of compromised accounts." A useful pattern from Microsoft's scale guidance puts shared policies in a group that sits outside every local admin's RBAC scope, so no regional admin can modify them.
  • Standing privilege should be reduced
    Microsoft's RBAC documentation is blunt about the Intune Administrator role: "Don't use this role for routine administration." The least-privileged built-in or custom role is the safer default, and scope groups should not include Add all users or Add all devices.
  • Sensitive changes can be gated with Multi Admin Approval
    Shipped in August 2025, MAA requires a second administrator to approve creates, edits, deletes, and assignments on protected resources, and audit logs record the full request and approval trail. It is a preventive control, not a rollback mechanism, and it has a known rough edge. Approvers holding custom Intune roles can't reliably see device-deletion requests, which can leave a request stuck for three days.

All four are versions of the discipline NIST SP 800-128 formalizes for configuration management. Changes "are controlled from the time the change is proposed to the implementation and testing of the change." The hour you just spent firefighting a mis-scoped profile while the ticket queue climbed is the business case for that process. The corrective-policy procedure above is the fallback for the day the process misses.

When the next configuration profile hits the wrong Entra ID group and the help desk queue starts climbing, audit logs and memory are not enough. Get a demo to see how Nerdio Manager backs up and restores Intune policy state across your Windows 365 and Azure Virtual Desktop environment, or try it free in your Azure tenant.

Frequently asked questions about how to roll back a bad Intune policy change

Ready to get started?