Dynamic device group for Company devices
You can use this dynamic device group to target Corporate devices and not BYOD (personal) devices. This group can be used for Intune assignments where you want to include all Company managed computers and exclude BYOD laptops
Create new Entra ID dynamic group
Microsoft Entra ID
Groups
New group
Dynamic group settings
Group type: Security
Group name: Windows Company Devices
Membership type: Dynamic Device
Click Add dynamic query
Dynamic group membership rules
Configure Rules
Rule syntax - Edit
Enter the rule syntax and click OK
(device.deviceOSType -contains "Windows") and (device.deviceOwnership -eq "Company")
Click Save
Click Create
Validate dynamic group membership rules
Dynamic membership rules
Validate rules - Add devices
Select a BYOD (personal) device and a company device
Note the personal device is showing "Not in group"
Reference:
Dynamic membership rules for groups in Microsoft Entra ID
https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership
Subscribe
Report