Practical guide
How to restore a deleted Intune policy
You can restore a deleted Intune policy only if you have a copy of it, because Intune has no recycle bin and Microsoft documents no restore path for deleted policies. With a backup you recreate the policy from the saved settings; without one you rebuild it by hand, using audit logs to work out what it contained. Either way the restored policy gets a new object ID, so assignments and references need checking.
At a glance
- Microsoft documents no recycle bin, undelete or support-based restore for deleted Intune policies.
- A recreated policy always gets a new object ID, whichever tool recreates it.
- Intune audit logs record the deletion and which properties changed, but not the full policy content.
- TenuVault Community restores one item at a time as an unassigned copy; Pro and MSP can recreate it under its original name and restore its assignments.
- Assignments point to Entra groups by ID, so they come back only if those groups still exist.
1. Confirm what was deleted and when
Open Tenant admin > Audit logs in the Intune admin center and filter for the deletion. A Microsoft staff answer on Microsoft Q&A shows a deleted compliance policy appearing there as a Delete DeviceCompliancePolicy record. Note the policy name, the time, the administrator who deleted it and the object type. Microsoft documents that Graph returns two years of audit events and the admin center filter covers up to the previous year.
Check whether the policy was really deleted or whether its group was. If an Entra group was soft deleted, Intune shows it in the admin center and its assignments stop applying. Microsoft states that if the group is restored, its previous assignments are reinstated automatically, which is a much smaller fix than recreating a policy.
Also consider the devices. When a profile is deleted, Microsoft says its settings are removed from devices, except that some Windows settings stay (tattooing) and, on Android, settings are not removed for the profile types Microsoft groups as all other profile types. Decide how urgent the restore is from what devices lost.
2. Restore from a TenuVault backup on Community
Community restores one item at a time as an unassigned copy. It is the safest mode because nothing existing changes, and it is enough to bring back a single deleted policy.
- Open Backup & Restore, select the tenant and open Backup History. Pick a backup taken before the deletion and choose Restore from this backup.
- Search for the policy by name and select it. Check Recovery readiness for warnings such as missing dependencies or external artifacts.
- Choose Create copies and review the plan. The policy is created as [Restored] followed by its original name, with a new ID and no assignments.
- Rename it in Intune if you want the original name, then recreate its assignments for the right groups and filters.
3. Recreate in place with assignments on Pro and MSP
Pro and MSP add Replace in place and Restore assignments. In the review step, a deleted item is labelled Recreate: deleted from the tenant and is recreated under its original name. With Restore assignments on, it is assigned to the same groups and filters as in the backup.
Drift detection offers a shortcut for recent deletions. When a policy disappears between your two newest complete backups, its card offers Recreate on Pro and MSP, which restores it under the original name without assignments, and Restore as copy on every plan.
Some types need assignments handled in Intune. Windows Autopilot deployment profiles, Apple user enrollment profiles, terms and conditions and Intune roles cannot have their assignments replaced in place. Restore them with assignments off and reconcile assignments in the admin center.
What you lose: IDs, assignments and group references
No restore brings back the original object. A recreated policy is a new object with a new ID, and the table shows what that means in practice.
- Assignments are saved as references to group IDs. If a targeted group was deleted too, restore it in Entra first or the assignment cannot point to it.
- Assignments inherited from a policy set are not restored as direct assignments; restore the policy set to bring them back.
- Reports, scripts or documentation that use the old policy ID need updating.
- App installers, Apple tokens and private keys are never in a backup, so apps that need an installer and Apple enrollment tokens have to be uploaded again.
| Property | Restore as copy (all plans) | Recreate in place (Pro and MSP) |
|---|---|---|
| Object ID | New ID | New ID |
| Name | [Restored] prefix added | Original name |
| Assignments | None; assign in Intune | Same groups and filters as the backup when Restore assignments is on |
| Groups | Not part of the backup | Not part of the backup; deleted groups must be restored or recreated first |
| References from other objects | Rewritten only for items restored in the same run | Rewritten only for items restored in the same run |
Restoring with other backup tools
The same principle applies to every tool: a deleted policy comes back as a new object. What differs is how each tool names it and handles assignments, so check this before an incident rather than during one.
IntuneBackupAndRestore restores by creating new objects, with configuration and assignments restored in two separate steps. IntuneManagement imports exported JSON and offers modes that always import or skip objects that already exist, and its cross-tenant import can recreate missing groups. IntuneCD compares a backup with the tenant by display name and creates configurations that are missing, updating assignments only when you ask it to. All three are free and open source under the MIT license.
Check the restored policy
Treat the restore as finished only when the policy does what it did before. A created object is not the same as working configuration.
- Compare the restored settings with the backup or export you restored from.
- Confirm the assignments, exclusions and filters against your change records, and that every targeted group still exists.
- Add the policy back to any policy set it belonged to, unless you restored the policy set in the same run.
- Check device status reports after the next check-in, starting with a few known devices.
- Record the old and new object IDs, the backup used and the time, and run a fresh backup so the restored state is captured.
Without a backup: what Microsoft supports
Microsoft documents no recycle bin or restore path for deleted Intune policies, and no official article describes Microsoft support recovering one. In a 2022 Microsoft Q&A thread about a deleted compliance policy, the asker states that a deleted Intune policy cannot be restored; the Microsoft staff answer does not dispute it and points to the audit logs to reconstruct the policy name and assignments.
So the documented approach is to rebuild. Use the audit log entries for the policy, which list the properties changed over time, along with any JSON export, documentation or screenshot you have. Recreate the policy in the admin center, compare it with what devices report, then reassign it. A settings catalog export from before the deletion can be imported directly as a new policy.
Prevent the next deletion
Multi Admin Approval can require a second administrator to approve Delete actions on apps, compliance policies, settings catalog policies and scripts. Combine it with scheduled backups and a restore you have practiced, so the next deletion is a restore from a known procedure rather than a rebuild from memory.
Read the technical guides
Product scope reviewed . Check your installed release and the current plan table before using a workflow.
Frequently asked questions
Can I restore a deleted Intune policy from the admin center?+
No. Intune has no recycle bin or undelete for policies. You need a prior export or backup of the policy to recreate it; otherwise you rebuild it by hand.
Can Microsoft support recover a deleted Intune policy?+
Microsoft documents no support path for recovering a deleted Intune policy. In a 2022 Microsoft Q&A thread, the Microsoft staff answer pointed to the audit logs to reconstruct the policy rather than to a restore.
Does a restored Intune policy keep its original ID?+
No. A deleted policy is recreated as a new object with a new ID, whichever tool recreates it. Anything that referenced the old ID, such as reports or scripts, needs updating.
Are assignments restored with a deleted policy?+
In TenuVault Pro and MSP, yes, if you turn on Restore assignments and the targeted groups still exist. On Community the policy comes back unassigned and you assign it in Intune. Windows Autopilot profiles, Apple user enrollment profiles, terms and conditions and Intune roles are restored with assignments off and reassigned in Intune on every plan.
What happens to devices when an Intune policy is deleted?+
Microsoft states that the profile's settings are removed from devices, with exceptions. Some Windows settings remain on the device, which is called tattooing, and on Android settings are not removed for the profile types Microsoft groups as all other profile types.
Can the Intune audit log recreate a deleted policy?+
Not on its own. The audit log shows the deletion and the properties that changed in earlier edits, which helps you rebuild the policy, but it does not store the complete configuration.