Creating AAD Dynamic group targeting newly enrolled machines (not hybrid)

Copper Contributor

I want to run script ONLY on newly enrolled machines (no onPrem servers, I only have AAD and InTune)
i could not find any way to only target newly enrolled machines (either new machines or factory reset/SecureWiped)

I saw that there are Custom attributes when building the dynamic group rules, is there ANY way to reach my endgoal? Win10-21H2 machines

1 Reply
Any solution that meets my end goal is appreciated:
-Conditional Access custom device rule
-Dynamic AAD Group (custom rule,...)
-Else..