Tech Community Live: Endpoint Manager edition
Jul 21 2022, 08:00 AM - 12:00 PM (PDT)

Locking Intune Device Categories by Azure groups

%3CLINGO-SUB%20id%3D%22lingo-sub-3295188%22%20slang%3D%22en-US%22%3ELocking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3295188%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20a%20way%20to%20assign%20an%20azure%20group%20to%20a%20device%20category.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20only%20users%20that%20are%20in%20that%20azure%20group%20are%20able%20to%20enrol%20their%20device%20into%20that%20device%20category.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOr%20so%20users%20can%20only%20see%20the%20device%20categories%20that%20they%20have%20been%20given%20access%20to%20by%20the%20azure%20group(s)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20to%20tighten%20up%20the%20enrollment%20process%20and%20just%20making%20it%20a%20cleaner%2Fquicker%20approach%20for%20users.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3295188%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297401%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297401%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F379977%22%20target%3D%22_blank%22%3E%40shehanjp%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYeah%20can%20see%20how%20that%20works.%20Just%20seems%20odd%20that%20this%20function%20isn't%20in%20Intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMigrating%20from%20AirWatch%20MDM%20to%20Intune%20seems%20like%20always%20finding%20things%20that%20you%20would%20expect%20as%20standard%20and%20it%20not%20being%20there.%20Not%20saying%20that%20Intune%20is%20bad%2C%20but%20just%20like%20changing%20to%20anything%20new%20and%20working%20my%20way%20through.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297394%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297394%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1373785%22%20target%3D%22_blank%22%3E%40NeilPD%3C%2FA%3E%26nbsp%3BAnother%20way%20to%20look%20at%20this%20without%20using%20device%20categories..%20%3CSTRONG%3EGroup%20tags%3C%2FSTRONG%3E%20can%20be%20used%20to%20tag%20machines%20from%20the%20Device%20Registration%20page.%20You%20can%20use%20different%20enrollment%20profiles%20as%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F934188%22%20target%3D%22_blank%22%3E%40MMelkersen_MVP%3C%2FA%3E%26nbsp%3Bmentioned%20that's%20assigned%20to%20Group%20Rag%20based%20Dynamic%20AAD%20Device%20groups.%3CBR%20%2F%3EAlso%20same%20AAD%20groups%20can%20be%20used%20to%20deploy%20Apps%20and%20device%20profiles%20if%20needed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297389%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297389%22%20slang%3D%22en-US%22%3Eok%2C%20but%20what%20if%20they%20choose%20wrong%20category%20then%3F%3CBR%20%2F%3EWhy%20not%20use%20different%20enrollment%20profiles%20and%20then%20filter%20your%20apps%20and%20policies%20on%20that%20in%20Intune%3F%20your%20deployments%20will%20be%20much%20faster%20and%20more%20reliable.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297365%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297365%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EYeah%20that%20is%20what%20I%20was%20thinking%2C%20shame.%20Thanks%20for%20clearing%20it%20up.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297256%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297256%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1373785%22%20target%3D%22_blank%22%3E%40NeilPD%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20no%20Intune%20or%20Azure%20AD%20features%20that%20allow%20you%20assign%20a%20device%20categorie%20to%20an%20AzureAD%20group%20unfortunately.%3C%2FP%3E%3CP%3EThere%20is%20no%20way%20today%20to%20limit%20a%20device%20category%20usage%20to%20a%20specific%20users%20or%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20mentionned%20by%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F379977%22%20target%3D%22_blank%22%3E%40shehanjp%3C%2FA%3E%20you%20can%20create%20AzureAD%20group%20with%20devices%20categories%20as%20membership%20rules%20but%20this%20will%20not%20help%20you%20because%20the%20device%20will%20join%20the%20group%20after%20the%20user%20or%20an%20IT%20pro%20added%20the%20catagory%20set%20as%20the%20group%20membership%20criteria.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3296252%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3296252%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F934188%22%20target%3D%22_blank%22%3E%40MMelkersen_MVP%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDevice%20Categories%20was%20already%20in%20use%20in%20our%20intune%20for%20windows%20%2F%20MACs%20so%20need%20to%20setup%20device%20cats%20for%20iOS%2Fandroid%20devices.%20Its%20also%20easier%20for%20users%20to%20select%20the%20cat%20and%20then%20the%20apps%20and%20wallpaper%20etc%20is%20deployed%20to%20them.%20We%20can%20then%20also%20see%20the%20device%20in%20each%20cat%20easily%20via%20the%20filters.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3296244%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3296244%22%20slang%3D%22en-US%22%3EI%20would%20not%20recommend%20use%20device%20categories.%20If%20you%20need%20to%20find%20devices%20and%20add%20them%20to%20a%20dynamic%20AAD%20group%2C%20then%20find%20other%20attributes%20you%20can%20use%20to%20this.%3CBR%20%2F%3E%3CBR%20%2F%3ECan%20you%20tell%20more%20about%20what%20you%20want%20to%20achieve%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3295846%22%20slang%3D%22en-US%22%3ERe%3A%20Locking%20Intune%20Device%20Categories%20by%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3295846%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1373785%22%20target%3D%22_blank%22%3E%40NeilPD%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDevice%20categories%20are%20for%20devices%2C%20but%20not%20for%20the%20users%2C%20but%20admins%20can%20give%20the%20option%20to%20users%20to%20select%20the%20device%20category%20when%20enrolling%20the%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EIs%20there%20a%20way%20to%20assign%20an%20azure%20group%20to%20a%20device%20category%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EYes.%20You%20can%20create%20device%20categories%201st%20and%20then%20using%20Dynamic%20AAD%20Groups%20(Dynamic%20Device)%2C%20create%20a%20rule%20to%20assign%20devices%20with%20the%20specific%20category%20to%20the%20group.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ECheck%20this%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fdevice-group-mapping%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ECategorize%20devices%20into%20groups%20in%20Intune%20-%20Microsoft%20Intune%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20will%20work%20-%26nbsp%3B%3CSTRONG%3EOr%20so%20users%20can%20only%20see%20the%20device%20categories%20that%20they%20have%20been%20given%20access%20to%20by%20the%20azure%20group(s)%3F%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EThis%20can%20be%20achieved%20if%20you%20install%20Company%20Portal%20app.%20When%20they%201st%20open%20the%20app%2C%20they%20will%20be%20asked%20to%20select%20the%20Device%20Category.%20However%20in%20this%20case%20they%20can%20see%20all%20the%20device%20categories%20and%20have%20to%20select%20the%20proper%20one.%3C%2FP%3E%3CP%3EOnce%20selected%2C%20the%20device%20will%20be%20assigned%20to%20the%20previously%20created%20AAD%20Dynamic%20device%20group%20so%20you%20can%20set%20targeted%20policies%20for%20that%20category.%3CBR%20%2F%3ECheck%20this%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fjannikreinhard.com%2F2021%2F07%2F18%2Fconfigure-device-categories%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EConfigure%20device%20categories%20%E2%80%93%20Modern%20Device%20Management%20(jannikreinhard.com)%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps.%3C%2FP%3E%3CP%3EThanks%20you.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E**If%20you%20think%20my%20answer%20is%20valid%2C%20please%20Accept%20it%20as%20the%20solution.%20Thank%20you**%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Is there a way to assign an azure group to a device category.

 

So only users that are in that azure group are able to enrol their device into that device category.

 

Or so users can only see the device categories that they have been given access to by the azure group(s)?

 

This is to tighten up the enrollment process and just making it a cleaner/quicker approach for users.

8 Replies

@NeilPD 

 

Hi,

 

Device categories are for devices, but not for the users, but admins can give the option to users to select the device category when enrolling the device.

 

Is there a way to assign an azure group to a device category

Yes. You can create device categories 1st and then using Dynamic AAD Groups (Dynamic Device), create a rule to assign devices with the specific category to the group.

Check this - Categorize devices into groups in Intune - Microsoft Intune | Microsoft Docs

 

This will work - Or so users can only see the device categories that they have been given access to by the azure group(s)?

This can be achieved if you install Company Portal app. When they 1st open the app, they will be asked to select the Device Category. However in this case they can see all the device categories and have to select the proper one.

Once selected, the device will be assigned to the previously created AAD Dynamic device group so you can set targeted policies for that category.
Check this - Configure device categories – Modern Device Management (jannikreinhard.com)

 

Hope this helps.

Thanks you.

 

**If you think my answer is valid, please Accept it as the solution. Thank you**

 

I would not recommend use device categories. If you need to find devices and add them to a dynamic AAD group, then find other attributes you can use to this.

Can you tell more about what you want to achieve?

@MMelkersen_MVP 

Device Categories was already in use in our intune for windows / MACs so need to setup device cats for iOS/android devices. Its also easier for users to select the cat and then the apps and wallpaper etc is deployed to them. We can then also see the device in each cat easily via the filters.

Hi @NeilPD,

 

There is no Intune or Azure AD features that allow you assign a device categorie to an AzureAD group unfortunately.

There is no way today to limit a device category usage to a specific users or devices.

 

As mentionned by @shehanjp you can create AzureAD group with devices categories as membership rules but this will not help you because the device will join the group after the user or an IT pro added the catagory set as the group membership criteria.

 

Thanks

Hi,
Yeah that is what I was thinking, shame. Thanks for clearing it up.
ok, but what if they choose wrong category then?
Why not use different enrollment profiles and then filter your apps and policies on that in Intune? your deployments will be much faster and more reliable.

@NeilPD Another way to look at this without using device categories.. Group tags can be used to tag machines from the Device Registration page. You can use different enrollment profiles as @MMelkersen_MVP mentioned that's assigned to Group Rag based Dynamic AAD Device groups.
Also same AAD groups can be used to deploy Apps and device profiles if needed.

 

Cheers!

@shehanjp 

 

Yeah can see how that works. Just seems odd that this function isn't in Intune.

 

Migrating from AirWatch MDM to Intune seems like always finding things that you would expect as standard and it not being there. Not saying that Intune is bad, but just like changing to anything new and working my way through.