Forum Discussion

alexcolombari's avatar
alexcolombari
Copper Contributor
Jul 30, 2026

Defender Device Groups

Hello everyone,

I need some help creating a device group in Defender. I can't find anything related to Groups inside Microsoft Security. I'd read that it's possible to create one inside the Permissions tab, but I can't figure out how.

Someone can explain what's the process?

 

 

4 Replies

  • GokselATAKAN's avatar
    GokselATAKAN
    Brass Contributor

    Hi Alex,

    Device groups live under Settings, not directly under Permissions.

    Go to Settings > Endpoints > Permissions section > Device groups.

    or Direct link: https://security.microsoft.com/securitysettings/endpoints/machine_groups

    From there, select Add device group, then:

    1. On the General page, set a name, remediation level, and optional description
    2. On the Devices page, set the matching rule (device name, domain, tags, or OS platform) that determines which devices land in the group

    One thing worth knowing, creating device groups requires the Security Administrator role, so if the option isn't visible or feels greyed out, check your assigned role first before assuming it's a navigation issue.

    • alexcolombari's avatar
      alexcolombari
      Copper Contributor

      I couldn't find the path you mentioned, and when I tried the direct link, I was redirected to the home page.
      Is there any licensing restriction? I have the Security Administrator role.

       

      • GokselATAKAN's avatar
        GokselATAKAN
        Brass Contributor

        Hi Alex,

        Correction on my earlier reply, that path only applies if you're on standalone Defender for Endpoint Plan 1 or Plan 2.

        If your org is on Defender for Business (bundled with Business Premium, for example), there's no Device groups page under Settings at all. Device groups work differently there, you define them inline while creating or editing a policy at security.microsoft.com/policy-management, and they're stored in Microsoft Entra ID rather than in the Endpoint settings area. That would explain both the missing Permissions section and the redirect on the direct link.

        Can you confirm which Defender for Endpoint plan/license you're on? If you are on Endpoint P1/P2 and still hitting a redirect, that matches a known issue some tenants have reported where the Device groups page just doesn't provision correctly, in that case it needs a support ticket through Microsoft, not something fixable from the admin side.