When will you let us manage by AAD groups?

%3CLINGO-SUB%20id%3D%22lingo-sub-2308607%22%20slang%3D%22en-US%22%3EWhen%20will%20you%20let%20us%20manage%20by%20AAD%20groups%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2308607%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20a%20model%20where%204k%20our%20of%20our%2012k%20users%20are%20not%20formally%20managed%20by%20us.%3C%2FP%3E%3CP%3EThat%20means%20they%20can%20access%20our%20tenant%20and%20freely%20download%20M365%20apps%2C%20but%20we%20do%20not%20manage%20their%20hardware%20therefore%20we%20don't%20want%20to%20control%20if%20they%20are%20on%20current%20or%20semi..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWill%20you%20give%20us%20the%20ability%20to%20restrict%20servicing%20to%20targeted%20groups%20within%20our%20AAD%20at%20some%20point%2C%20or%20will%20config.office.com%20always%20be%20based%20on%20telemetry%20within%20a%20given%20instance%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20would%20also%20in%20our%20case%20include%20personal%20devices%20who%20have%20downloaded%20M365%20apps%20to%20use%20for%20%3CA%20href%3D%22mailto%3Ahome%40work%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehome%40work%3C%2FA%3E%26nbsp%3Btype%20situations%20but%20don't%20necessarily%20want%20this%20channel.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20in%20the%20works%2C%20or%20will%20it%20always%20be%20one%20tenant%20one%20model%20regardless%20of%20attribute%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2314097%22%20slang%3D%22en-US%22%3ERe%3A%20When%20will%20you%20let%20us%20manage%20by%20AAD%20groups%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2314097%22%20slang%3D%22en-US%22%3EIf%20they%20are%20not%20connected%20to%20the%20AAD%20%2C%20then%20you%20couldn't%20manage%20them%20and%20it%20is%20up%20to%20the%20user%2C%20however%20in%20case%20they%20sign-in%20to%20Microsoft%20365%20with%20Office%20Application%2C%20then%20you%20could%20manage%20their%20office%20applications.%20However%20once%20they%20sign%20out%2C%20you%20will%20lose%20control.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2316290%22%20slang%3D%22en-US%22%3ERe%3A%20When%20will%20you%20let%20us%20manage%20by%20AAD%20groups%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2316290%22%20slang%3D%22en-US%22%3EFirst%20off%2C%20only%20Apps%20health%20from%20the%20Apps%20admin%20center%20(aka%20config.office.com)%20is%20based%20on%20Diagnostic%20Data%20coming%20from%20M365Apps%20instances.%20Inventory%2C%20OCPS%20and%20Servicing%20Profiles%20do%20not%20rely%20on%20Diagnostic%20Data-%20Regarding%20managing%20updates%2C%20a%20feature%20to%20restrict%20the%20scope%20of%20the%20Servicing%20Profile%20to%20an%20AzureAD%20group%20is%20in%20the%20works%20and%20should%20land%20in%20the%20next%20few%20weeks.%3C%2FLINGO-BODY%3E
New Contributor

We have a model where 4k our of our 12k users are not formally managed by us.

That means they can access our tenant and freely download M365 apps, but we do not manage their hardware therefore we don't want to control if they are on current or semi..

 

Will you give us the ability to restrict servicing to targeted groups within our AAD at some point, or will config.office.com always be based on telemetry within a given instance?

 

This would also in our case include personal devices who have downloaded M365 apps to use for home@work type situations but don't necessarily want this channel.

 

Is this in the works, or will it always be one tenant one model regardless of attribute?

2 Replies
If they are not connected to the AAD , then you couldn't manage them and it is up to the user, however in case they sign-in to Microsoft 365 with Office Application, then you could manage their office applications. However once they sign out, you will lose control.
First off, only Apps health from the Apps admin center (aka config.office.com) is based on Diagnostic Data coming from M365Apps instances. Inventory, OCPS and Servicing Profiles do not rely on Diagnostic Data- Regarding managing updates, a feature to restrict the scope of the Servicing Profile to an AzureAD group is in the works and should land in the next few weeks.