SOLVED

Delegated or Segmented Device Management?

%3CLINGO-SUB%20id%3D%22lingo-sub-1410154%22%20slang%3D%22en-US%22%3EDelegated%20or%20Segmented%20Device%20Management%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1410154%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20a%20way%20for%20a%20helpdesk%20group%2C%20say%20in%20Europe%2C%20to%20manage%20Europe%20devices%20but%20not%20manage%20devices%20in%20other%20regions%3F%3C%2FP%3E%3CP%3EThe%20new%20Administrative%20Units%20(Preview)%20looks%20promising%20but%20it%20doesn't%20appear%20to%20include%20devices%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fusers-groups-roles%2Fdirectory-administrative-units%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fusers-groups-roles%2Fdirectory-administrative-units%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1410154%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1410194%22%20slang%3D%22en-US%22%3ERe%3A%20Delegated%20or%20Segmented%20Device%20Management%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1410194%22%20slang%3D%22en-US%22%3EHi%20Joe%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20you%20are%20looking%20for%20are%20scope%20tags%20I%20believe.%3CBR%20%2F%3EYou%20should%20add%20a%20tag%20to%20a%20device%20group%20and%20add%20the%20tag%20to%20all%20policies.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fscope-tags%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fscope-tags%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThere%20is%20no%20sync%20between%20scope%20tags%20and%20AUs%3C%2FLINGO-BODY%3E
Highlighted
Super Contributor

Is there a way for a helpdesk group, say in Europe, to manage Europe devices but not manage devices in other regions?

The new Administrative Units (Preview) looks promising but it doesn't appear to include devices:

https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-administrative-...

1 Reply
Highlighted
Best Response confirmed by Joe Stocker (Super Contributor)
Solution
Hi Joe

What you are looking for are scope tags I believe.
You should add a tag to a device group and add the tag to all policies.
https://docs.microsoft.com/en-us/mem/intune/fundamentals/scope-tags

There is no sync between scope tags and AUs