SOLVED

Dynamic Groups Help

%3CLINGO-SUB%20id%3D%22lingo-sub-155136%22%20slang%3D%22en-US%22%3EDynamic%20Groups%20Help%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-155136%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe're%20about%20to%20migrate%20from%20MobileIron%20to%20Intune%20and%20I've%20been%20building%20the%20service%20ready%20for%20our%20users.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20MobileIron%2C%20we%20previously%20had%20different%20policies%20and%20configurations%20for%20users%20based%20upon%20dynamic%20groups%20(labels)%20that%20filtered%20on%20both%20user%20and%20device%20attributes%20e.g.%20user%20is%20in%20xxx%20AD%20group%20and%20has%20an%20iOS%20device%20with%20DEP%20enabled.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECurrently%20I%20can't%20see%20how%20this%20can%20be%20achieved%20in%20Intune.%20Would%20I%20have%20to%20use%20nested%20Dynamic%20groups%20(if%20this%20is%20supported)%20to%20segregate%20by%20device%20attribute%2C%20and%20then%20from%20that%20group%20by%20user%20attribute%3F%20Or%20do%20I%20need%20to%20rethink%20about%20how%20we're%20applying%20configurations%20and%20policies%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESecondly%2C%20we%20have%20subsets%20of%20users%20that%20need%20slightly%20different%20policies%20(such%20as%20VIPs%2C%20or%20users%20with%20specialist%20devices).%20Are%20we%20able%20to%20prioritise%20policies%2Fconfigurations%20so%20that%2C%20if%202%20are%20pushed%20to%20the%20same%20device%2C%20one%20is%20given%20priority%20over%20the%20other%2C%20or%20do%20I%20need%20to%20figure%20a%20way%20to%20separate%20them%20out%20from%20the%20'main'%20group%3F%20The%20only%20way%20I%20can%20think%20of%20doing%20this%20is%2C%20again%2C%20create%20a%20dynamic%20group%20that%20says%20%22everyone%20with%20xxx%20AD%20group%22%2C%20and%20then%20create%20a%20second%20dynamic%20group%20which%20is%20%22everyone%20not%20already%20in%20that%20other%20dynamic%20group%22.%20Would%20this%20be%20the%20ideal%20solution%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAny%20help%20or%20insight%20with%20this%20would%20be%20hugely%20appreciated.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%3C%2FP%3E%0A%3CP%3EDan%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-155136%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDynamic%20Group%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-159912%22%20slang%3D%22en-US%22%3ERe%3A%20Dynamic%20Groups%20Help%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-159912%22%20slang%3D%22en-US%22%3EHi%20Oliver%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20for%20your%20response.%20I%20can%20see%20I'm%20going%20to%20need%20a%20complete%20rethink%20about%20how%20we%20sort%20our%20policies%20and%20groupings!%3CBR%20%2F%3E%3CBR%20%2F%3ED%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-159736%22%20slang%3D%22en-US%22%3ERe%3A%20Dynamic%20Groups%20Help%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-159736%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Dan%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eplease%20have%20a%20look%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-groups-dynamic-membership-azure-portal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-groups-dynamic-membership-azure-portal%3C%2FA%3E%3C%2FP%3E%0A%3CP%3Eyou%20will%20need%20to%20come%20up%20with%20a%20different%20strategy%20how%20to%20assign%20configurations.%20As%20of%20now%20there%20is%20no%20way%20to%20build%20a%20query%20like%20person%20x%20not%20member%20in%20group%20y.%3C%2FP%3E%0A%3CP%3EThe%20way%20Microsoft%20is%20thinking%20about%20the%20Intune%20assignments%20are%20user%20centric.%20So%20a%20VIP%20group%20will%20get%20different%20settings%20and%20is%20not%20member%20of%20the%20broad%20employee%20group%20for%20example.%20This%20leads%20to%20separation%20in%20the%20end.%20Your%20example%20of%20user%20has%20iOS%20and%20DEP%20is%20also%20not%20directly%20addressable.%20We%20can't%20mix%20user%20and%20device%20attributes.%20We%20would%20assign%20a%20policy%20to%20a%20user%20group%20and%20if%20the%20user%20has%20an%20Android%20all%20iOS%20device%20policies%20would%20be%20marked%20as%20%22not%20applicable%22.%20If%20the%20user%20now%20enrolls%20a%20iOS%20device%20the%20iOS%20policies%20would%20apply.%20Makes%20sense%3F%3C%2FP%3E%0A%3CP%3ECertainly%20not%20the%20flexibility%20you%20may%20be%20familiar%20with%20MobileIron%2C%20but%20that's%20how%20it%20is.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E
Daniel Hudson
Regular Contributor

Hi All

 

We're about to migrate from MobileIron to Intune and I've been building the service ready for our users.

 

In MobileIron, we previously had different policies and configurations for users based upon dynamic groups (labels) that filtered on both user and device attributes e.g. user is in xxx AD group and has an iOS device with DEP enabled.

 

Currently I can't see how this can be achieved in Intune. Would I have to use nested Dynamic groups (if this is supported) to segregate by device attribute, and then from that group by user attribute? Or do I need to rethink about how we're applying configurations and policies?

 

Secondly, we have subsets of users that need slightly different policies (such as VIPs, or users with specialist devices). Are we able to prioritise policies/configurations so that, if 2 are pushed to the same device, one is given priority over the other, or do I need to figure a way to separate them out from the 'main' group? The only way I can think of doing this is, again, create a dynamic group that says "everyone with xxx AD group", and then create a second dynamic group which is "everyone not already in that other dynamic group". Would this be the ideal solution?

 

Any help or insight with this would be hugely appreciated.

 

Thanks

Dan

2 Replies
Solution

Hi Dan,

 

please have a look here: https://docs.microsoft.com/en-us/azure/active-directory/active-directory-groups-dynamic-membership-a...

you will need to come up with a different strategy how to assign configurations. As of now there is no way to build a query like person x not member in group y.

The way Microsoft is thinking about the Intune assignments are user centric. So a VIP group will get different settings and is not member of the broad employee group for example. This leads to separation in the end. Your example of user has iOS and DEP is also not directly addressable. We can't mix user and device attributes. We would assign a policy to a user group and if the user has an Android all iOS device policies would be marked as "not applicable". If the user now enrolls a iOS device the iOS policies would apply. Makes sense?

Certainly not the flexibility you may be familiar with MobileIron, but that's how it is.

 

best,

Oliver

Hi Oliver

Thank you for your response. I can see I'm going to need a complete rethink about how we sort our policies and groupings!

D
Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies