About the project

The preferences didn't come with you.

Cloud Policy Preferences exists to close one specific gap: the settings Group Policy Preferences handled every day, that configuration profiles in Intune never picked up.

Why it was built

Moving a Windows estate from Active Directory to Intune goes well right up until somebody asks about the drive mappings. Group Policy Preferences — GP Prefs, to most of the people who relied on it — is where that conversation lands. Configuration profiles cover the settings Microsoft exposes through a CSP, and they cover them well — but Group Policy Preferences was never a CSP story. The registry items, drive and printer mappings, shortcuts, scheduled tasks, environment variables and file copies that an environment quietly depends on have nothing to migrate to.

So they get rebuilt as PowerShell. A login script here, a remediation there, a share of scripts nobody owns, and a domain controller kept alive for one last policy. It works, roughly, until the person who wrote the scripts moves on and nobody can say which device got what.

Cloud Policy Preferences takes that work back off the scripts. You define preferences in a portal — with the fields each type actually needs, targeted at the Entra ID groups you already have — and the platform delivers them through the same Intune remediation channel you already run. One remediation, seven policy types, and a record of what landed on which device.

What it is, and what it isn't

What it is

  • A free community tool, offered as a managed multi-tenant service on Azure
  • A way to define the seven preference types and target them at Entra ID groups
  • Delivery through the Intune remediation channel you already operate
  • Per-tenant encryption, role-based access and an audit trail of what changed

What it isn't

  • A Microsoft product — this is an independent project, not affiliated with or endorsed by Microsoft
  • A replacement for configuration profiles; where a CSP exists, use it
  • Another agent to install, patch and worry about on every device
  • A domain controller in disguise — nothing here needs Active Directory
The gap, in one table

Seven types that never made the journey.

Preference type Group Policy Preferences Intune configuration profiles Cloud Policy Preferences
RegistryYesNo direct equivalentYes
File deploymentYesNo direct equivalentYes
Drive mappingYesNo direct equivalentYes
Printer mappingYesNo direct equivalentYes
ShortcutYesNo direct equivalentYes
Scheduled taskYesNo direct equivalentYes
Environment variableYesNo direct equivalentYes

Configuration profiles deliver the settings Microsoft exposes through a CSP. The seven types above have no direct equivalent, which is why they are usually rebuilt as scripts. Use configuration profiles wherever a CSP exists — this fills what is left.

About the author

Maurice Daly

Creator and maintainer of Cloud Policy Preferences

Maurice built Cloud Policy Preferences and maintains it as a free tool for the endpoint management community. It grew out of the gap described above — cloud migrations that ran smoothly until somebody asked where the drive mappings had gone — and it is shaped by the people who use it, so feedback and feature requests are welcome through the portal's Feedback Hub.

Cloud Policy Preferences is an independent community project. Microsoft, Intune, Entra ID and Azure are trademarks of Microsoft Corporation; this project is not affiliated with, endorsed by or supported by Microsoft.

Bring the preferences with you.

Sign in with the Entra ID account you already have and put your first policy on a device today.

Launch the portal