Profile Assignments Confusion

%3CLINGO-SUB%20id%3D%22lingo-sub-2336824%22%20slang%3D%22en-US%22%3EProfile%20Assignments%20Confusion%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2336824%22%20slang%3D%22en-US%22%3E%3CP%3EReading%20Microsoft's%20documentation%20located%20here%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fdevice-profile-assign%23exclude-groups-from-a-profile-assignment%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAssign%20device%20profiles%20in%20Microsoft%20Intune%20-%20Azure%20%7C%20Microsoft%20Docs%3C%2FA%3E%26nbsp%3Bit%20seems%20pretty%20clear%20to%20me%20that%20you%20assign%20profiles%20to%20devices%20when%20the%20settings%20in%20the%20profile%20should%20always%20follow%20a%20device%20and%20to%20users%20when%20the%20settings%20should%20always%20follow%20a%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20in%20the%20case%20of%20an%20iOS%20device%20configuration%20profile%20for%20device%20restrictions%20for%20example%2C%20I%20want%20the%20settings%20to%20follow%20the%20device%2C%20not%20the%20user.%20The%20device%20should%20always%20adhere%20to%20the%20settings%20in%20the%20device%20restrictions.%20Simple%20enough%2C%20pretty%20much%20like%20computer%20based%20GPO's%20and%20windows%20on-premise.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGiven%20the%20example%20above%2C%20it%20would%20seem%20to%20be%20that%20targeting%20the%20assignment%20to%20%22All%20Devices%22%20would%20make%20more%20sense%20than%20a%20device%20based%20group%20or%20even%20a%20dynamically%20built%20device%20based%20group%20considering%20the%20latency%20and%20delay%20they%20have%20when%20adding%20members.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20understanding%20is%20that%20profiles%20in%20Intune%20are%20platform%20specific%2C%20so%20if%20I%20create%20a%20device%20restrictions%20profile%20for%20iOS%20and%20assign%20it%20to%20%22All%20Devices%22%2C%20it%20only%20targets%20iOS%2FiPadOS%20devices.%20Is%20this%20correct%3F%20Leaving%20me%20free%20to%20apply%20profiles%20that%20I%20want%20on%20all%20devices%20from%20a%20given%20platform%20simply%20by%20targeting%20%22All%20devices%22%20instead%20of%20a%20dynamic%20device%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20my%20thinking%20correct%20here%3F%20If%20not%2C%20why%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2336824%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2337544%22%20slang%3D%22en-US%22%3ERe%3A%20Profile%20Assignments%20Confusion%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2337544%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EYou%20could%20microsoft%20docs%20about%20this%20topic%20but%20you%20are%20indeed%20correct.%20If%20you%20create%20a%20ios%20device%20configuration%20policy%20and%20you%20assign%20it%20to%20all%20devices%2C%20it%20only%20will%20be%20applied%20at%20all%20IOS%20devices%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fdevice-profile-assign%23user-groups-vs-device-groups%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fdevice-profile-assign%23user-groups-vs-device-groups%3C%2FA%3E%3C%2FLINGO-BODY%3E
New Contributor

Reading Microsoft's documentation located here Assign device profiles in Microsoft Intune - Azure | Microsoft Docs it seems pretty clear to me that you assign profiles to devices when the settings in the profile should always follow a device and to users when the settings should always follow a user.

 

So in the case of an iOS device configuration profile for device restrictions for example, I want the settings to follow the device, not the user. The device should always adhere to the settings in the device restrictions. Simple enough, pretty much like computer based GPO's and windows on-premise.

 

Given the example above, it would seem to be that targeting the assignment to "All Devices" would make more sense than a device based group or even a dynamically built device based group considering the latency and delay they have when adding members.

 

My understanding is that profiles in Intune are platform specific, so if I create a device restrictions profile for iOS and assign it to "All Devices", it only targets iOS/iPadOS devices. Is this correct? Leaving me free to apply profiles that I want on all devices from a given platform simply by targeting "All devices" instead of a dynamic device group.

 

Is my thinking correct here? If not, why? 

1 Reply
Hi,
You could microsoft docs about this topic but you are indeed correct. If you create a ios device configuration policy and you assign it to all devices, it only will be applied at all IOS devices

https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-assign#user-groups-vs-devic...