Practical guide
How to roll back a bad Intune policy change
To roll back a bad Intune policy change, you need the previous version of the policy, because Intune keeps no version history. Find the change, compare the current settings with your last good backup, then put the old version back in place or restore it as a copy and test it on pilot devices first. Without a backup, the audit log tells you which properties changed and you set them back by hand.
At a glance
- Intune has no per-policy version history, so a rollback needs a previous export or backup.
- Intune audit logs list which properties changed and who changed them.
- TenuVault drift detection compares your two newest complete backups, down to the individual setting.
- Revert in place is available on TenuVault Pro and MSP; restoring the previous version as a copy works on every plan.
- A replace in place does not keep the version it overwrites, so run a backup first if you may want it back.
1. Find the change
Start with the Intune audit log. Each entry shows the object, the administrator and, in the Target(s) section, the properties that were changed. Filter by time and object type around the moment problems started. Microsoft documents two years of audit events through Graph and up to one year in the admin center filter.
If you back up with TenuVault, run a fresh backup and open Drift Detection. It compares your two newest complete backups and lists added, modified and deleted items. Each modified item shows the changed settings with the old and new value and an impact assessment. The exported drift report, and Check all on the Tenants page for MSP, also give each change a severity; deleted compliance policies and changes to settings such as firewall, antivirus or BitLocker are critical. Drift detection compares backups, not the live tenant, which is why the fresh backup matters.
2. Compare the bad version with the last good one
Before you roll back, make sure you know exactly what will change. A rollback that also reverts a legitimate fix made in the same window creates a second incident.
In TenuVault, open Backup History, select the backup and choose View Changes to see what changed since the previous backup, setting by setting. To compare with an older backup, open the restore wizard from that backup and use Review snapshot content, which shows the exact JSON that would be restored. If you use another tool, diff the two exports; IntuneCD keeps exports in Git, and IntuneBackupAndRestore has compare cmdlets for backup files and folders.
Note any change to assignments separately from settings. A bad change is sometimes a new group assignment rather than a new setting value, and the two are restored differently.
3. Choose how to roll back
TenuVault offers three ways to put a previous version back. Pick by plan, by how many items changed and by whether assignments were part of the change.
- Use Revert when one policy's settings are wrong and its targeting is right.
- Use the restore wizard with Restore assignments on when the bad change included assignments; assignments added since the backup are removed and deleted ones come back.
- Run a backup immediately before any replace in place. The overwritten version is not kept by the restore itself.
- Tenant defaults, such as the default enrollment configuration and the default Company Portal branding, cannot be copied, only updated in place, which needs Pro or MSP.
| Method | Plans | What happens | Assignments |
|---|---|---|---|
| Revert from drift detection | Pro and MSP | The existing policy is put back to its backed-up version and keeps its ID | Stay as they are |
| Restore previous version as copy | All plans | A new [Restored] policy with the old settings is created; the current policy does not change | None; the copy is unassigned |
| Restore wizard, Replace in place | Pro and MSP | One or more items are compared with the tenant and overwritten where they differ | Replaced as a whole when Restore assignments is on |
4. Verify on pilot devices before the full rollback
For a high-impact policy, test the old version before you overwrite production. Restore the previous version as a copy, which is unassigned, and assign it in Intune to a small pilot group that you exclude from the current policy. Confirm on those devices that the old behavior returns, then revert the production policy and remove the copy.
Restored and overwritten items reach devices at their next check-in, so allow time before you judge the result. On Windows, remember that removing a setting does not always undo it on the device; Microsoft notes that some configuration service providers keep a setting after the profile no longer applies. Rolling back to an explicit previous value is more reliable than removing the setting.
Record what you rolled back, from which backup, and the result on the pilot devices. If the rollback fails partway, TenuVault reports incomplete objects and offers Retry failed items for safe retries.
Rolling back with other tools
If you keep Intune configuration in another tool, check how it writes to the tenant before you depend on it for a rollback. IntuneCD's update command compares the backup with the tenant and pushes the differences, matching objects by display name, and its report option shows the changes without applying them. IntuneManagement offers an Update import mode, marked as preview, that updates an existing object in place; its documentation notes that Endpoint Security settings are not cleared because there is no API for removing settings. IntuneBackupAndRestore restores by creating new objects, so a rollback with it gives you a new policy to reassign rather than an updated one.
Common rollback mistakes
Most failed rollbacks come from restoring the wrong thing rather than from the tool.
- Rolling back to a backup that is older than a legitimate fix, which reverts the fix as well.
- Restoring settings when the actual change was an assignment, or the reverse.
- Assigning a restored copy to the same devices as the original, so two versions of the policy apply at once.
- Skipping the backup before a replace in place, which leaves no copy of the version you are about to overwrite.
- Judging the result before devices have checked in.
If you have no backup of the earlier version
Use the audit log entries for the policy to list each property that changed, then set those properties back by hand in the admin center. Have a second administrator review the result, because the audit log does not store the complete previous policy.
For settings catalog policies, export the current policy to JSON before you edit it. If your fix makes things worse, you can import the export as a new policy and compare. This is manual, but it costs nothing and works today.
Make the next rollback faster
A rollback is only as good as the version you have to roll back to. The habits below make sure that version exists, is recent enough and has been restored at least once before you need it under pressure.
- Back up before planned changes and on a schedule: weekly on Community, daily on Pro and MSP.
- Keep enough history to reach the last good version; Community keeps up to 30 days, Pro and MSP 7 to 365 days or forever.
- Require a second approver for sensitive changes with Microsoft's Multi Admin Approval.
- Practice a restore of a test policy so the procedure is known before an incident.
Read the technical guides
Product scope reviewed . Check your installed release and the current plan table before using a workflow.
Frequently asked questions
Does Intune keep previous versions of a policy?+
No. Intune has no version history or rollback for policies. You need an export or backup taken before the change to put the previous version back.
How do I see what changed in an Intune policy?+
Open Tenant admin > Audit logs in the Intune admin center. Each entry shows who made the change and lists the properties that were changed. With TenuVault, drift detection also shows old and new values setting by setting between two backups.
Can I roll back an Intune policy without changing its ID?+
Yes, with TenuVault Pro or MSP. Revert from drift detection and Replace in place both update the existing policy to the backed-up version, so the policy keeps its ID.
Can I roll back on the free Community plan?+
Yes, as a copy. Community can restore the previous version as a new unassigned policy with a [Restored] prefix. You then assign it in Intune and retire the changed policy yourself. Tenant defaults, such as the default enrollment configuration and the default Company Portal branding, cannot be copied, only updated in place, which needs Pro or MSP.
Does rolling back also restore assignments?+
Revert from drift detection leaves current assignments as they are. The restore wizard on Pro and MSP replaces assignments with those in the backup when Restore assignments is turned on.
How long until a rollback reaches devices?+
Restored and overwritten policies reach devices at their next check-in. Allow for that delay before judging whether the rollback worked.