With the Intune configuration profile and compliance policies. When a working copy is created for a profile or policy that currently has an assignment and/or a filter that the profile or policy will not be cordoned off like a GPO working copy, it will be applied to the user/groups and filters that are assigned to it.
This could cause an issue as new devices are enrolled in Intune check in for policies and profiles every 3 minutes for the first 15 minutes, 15 minutes for the next 2 hours then around every 8 hours after that.
If an admin checks out a profile or policy and makes changes those changes will get applied to newly enrolled devices. This will also hold true for already enrolled devices if the administrator checks out a policy or profile and leaves that policy or profile checked out for more than 8 hours.
Enhancement ID 569826 created to be evaluated for inclusion in a future version of GPOADmin to prevent Intune working copies from being applied to any objects in the live Intune environment.