25 September 2026

Stop Scripting Everything: Simplifying Windows Configuration Alongside Intune

ProfileUnity intune Windows Group Policies Privilege Elevation App Management
Stop Scripting Everything Blog

In the evolution to modern workspace management through Microsoft Intune, we left the old way of management behind. Gone are the days of Group Policy Preferences, ADMX templates and the many years of configurable items that made these up. In its place, Microsoft introduced Configuration Service Provider (CSP) and these CSPs are now more easily accessible through the Settings Catalog: everything you need to configure in Windows with Microsoft Intune. There’s a catch however, and that is that there are a lot of things that cannot be configured this way. 

When scripting becomes a full-time job
Quickly configuring a registry key, adding a printer or drive mapping; all things that could be configured in a couple of clicks using Group Policy, now require scripting to get done. But it’s not limited to these. What about setting the correct default app for opening applications or setting some environment variables? The best Intune administrator is the one that knows how to script. But what if you’re not as great at it? And what happens when the script stops working due to Microsoft changes or when the script creator leaves the company? Plus, in this day and age where everybody can vibe code any script in Claude or ChatGPT – how can you ensure that the contents of these scripts do not cause more havoc? The task also doesn’t end with the creation of the script as its deployment requires sound detection logic, which can cause lengthy retries when set up incorrectly. It’s safe to say that simple settings that used to take 30 seconds can now take up half a day. 

ProfileUnity: Windows configuration made simple 
This is where ProfileUnity comes in for the configuration of Windows. As a platform-agnostic solution, it can work across any Windows session no matter where they are – be it Windows 365, Citrix or on physical machines managed through Microsoft Intune. ProfileUnity offers a clear interface with modules for the simple configuration of shortcuts, registry items, file type associations, printers, drive mappings, file redirection and more. And I mean simple. Creating a registry key is just a matter of choosing the action (adding or deleting a key or value), the hive it pertains to (HLKM, HKCU etc) and then the details of the key you’re modifying. Once saved, the settings are immediately reflected on the endpoint after a logon or refresh of the environment. 

Start menu shortcuts that actually look right 
In this world of SaaS applications, companies want to provide access to these in the place their employees have been looking for years – the start menu. But have you ever tried adding a web app to a start menu? It turns out as an Edge (or browser of choice) icon, as that is exactly what the shortcut calls. Getting a nice icon for the SaaS app in question then requires a bunch of scripting to look presentable. In ProfileUnity you simply point to the location of the icon in the configuration of the shortcut and it appears – it is that simple. 

Privilege Elevation and Application Control 
And what to think of extended features like Privilege Elevation or Application White- and Blacklisting? The former requires an add-on on top of Intune, whereas it is included with ProfileUnity. The latter can be done with App Control for Business, which is a continuation of AppLocker. It works, but is a hassle. ProfileUnity’s App Restrictions simply ask you what application you want to target and whether you want to block or allow it. Getting to the executable can be done through a file path, contains or by publisher. Blocked apps can be hidden from the user, so they do not even appear to be installed . All this can be configured in 30 seconds. 

Granular and dynamic 
But most importantly, it should be remembered that Microsoft Intune is a tool for Device Management and therefore views everything through that lens. If you want to target specific users, granularly, it becomes very tricky. ProfileUnity works with filters that work using and/or logic, making it easy to build dynamic rules to find who to assign settings or apps to. This can be based on Active Directory- or Entra ID groups, hardware- and OS types, IP addresses, device names or even based on the presence of a file or app and many, many more. It’s easy to quickly build any combination of conditions to target users on, and even better when triggers are applied to validate if that situation still valid. Perhaps we don’t want the same settings to apply as soon as the employee moves to a different office location? This granularity and responsiveness make a great difference to managing your Microsoft Intune environment. And the best part? Liquidware ProfileUnity can exist side by side with Intune and enhance the experience.