Bulk Edit Policies
Managing a large Microsoft Intune environment often means policies accumulate names that no longer match your current standards — after a baseline update, a tenant migration, or just over time. Renaming them one by one is slow and error-prone. Bulk Edit lets you apply naming changes and scope tag updates across many policies at once, safely.
What you can do
Add a prefix — e.g. turn
Windows - BitLockerintoLEGACY - Windows - BitLockerAdd a suffix — e.g. turn
Windows - BitLockerintoWindows - BitLocker - v1Replace text — e.g. change
DEVtoPRODacross all selected policiesAdd scope tags in bulk — assign one or more scope tags to a group of policies at once
How to use it
Go to Policies and filter or search to find the policies you want to edit.
Select the checkboxes next to the policies you want to change.
Click Bulk Edit in the toolbar.
Choose your action:
For renaming: select Add prefix, Add suffix, or Replace text, then fill in the value.
For scope tags: select Add scope tags and pick from the available tags. If the tag you need does not exist yet, type its name in the Create new scope tag field and click Create — the tag is created in Intune immediately and selected automatically. If a tag with that name already exists, it is selected for you instead of creating a duplicate.
Click Preview to see exactly what will change before anything is saved.
Review the preview table — each row shows the current name and the proposed new name (or which scope tags will be added).
If everything looks right, click Apply to execute the changes.
What you'll see in the preview
The preview shows a table with one row per selected policy:
Settings Catalog
WIN - Firewall - v1
LEGACY - WIN - Firewall - v1
—
Ready
Settings Catalog
WIN - BitLocker - v2
LEGACY - WIN - BitLocker - v2
—
⚠️ Name already exists
Rows marked with a warning will be skipped during execution — the rest will proceed. You'll see a final result table after applying.
Requirements
Available to all non-free customers (Standard with paid modules, Enterprise, MVP, NFR, MSP).
MSP admins can run bulk edits on their managed customer tenants by selecting the correct tenant from the tenant switcher.
You need the DeviceManagementConfiguration.ReadWrite.All Graph permission to rename policies and add scope tags. If IntuneAssistant hasn't been consented for this scope yet, you'll be prompted to consent first.
Creating a new scope tag requires the additional DeviceManagementRBAC.ReadWrite.All permission. If you do not have this permission, the Create button will return an error.
Safety rules
You can only add a prefix, add a suffix, or replace specific text — you cannot overwrite the entire name to a fixed value (to prevent accidental mass-renaming to the same name).
If the proposed new name already exists in the tenant, that policy is automatically skipped.
Scope tags that are already present on a policy are not added twice.
All changes are recorded in the Audit Log so you can always see what was changed, when, and by whom.
Tips
Use Replace to fix a typo or update a version number across all matching policies at once.
Run a preview first on a small selection to verify your pattern before applying to hundreds of policies.
If you need to undo a rename, just run Bulk Edit again with the reverse operation.
Last updated