Forum Discussion

Brian_ATL's avatar
Brian_ATL
Copper Contributor
Mar 24, 2025

Newly Created DfE Device Groups not immediately usable

I created a device group via https://security.microsoft.com/securitysettings/endpoints/machine_groups to apply a custom Indicator URL block for a single device based on an exact device name match. I ensured that the device is matched with the group rule using the Preview Device feature. Immediately after creating the device group, I clicked on Apply Changes on the device group page but after an hour, the device group still shows 0 device members and is not yet visible when creating the custom TI URL rule.

It's extremely frustrating when we need to respond quickly to threats but have to wait for back-end replication/scripts to run just for creating and using a Defender device group.

7 Replies

  • Brian_ATL's avatar
    Brian_ATL
    Copper Contributor

    The group finally was visible and useable after 2 hours of just...waiting. Now, 6 hours later, the device count for the group is still showing as 0 while the preview devices page still matches the rules against a single device. Really not a great user experience.

    • duliprb's avatar
      duliprb
      MCT

      Means asset group is not assigned, can you share a screenshot 

  • I think you need to check the promotor score and asset group in particular device in MDE., Until then it will not be applied to the device group. Hope this helps. Revalidate the configuration. Brian_ATL 

    • Brian_ATL's avatar
      Brian_ATL
      Copper Contributor

      Sorry, what you mean by "promotor score" and "asset group in particular device"?

      • duliprb's avatar
        duliprb
        MCT

        Promotor score in device group and Asset Group in Device.

Resources