SOLVED

Users with Multiple Devices - Groups Best Practice

%3CLINGO-SUB%20id%3D%22lingo-sub-1155385%22%20slang%3D%22en-US%22%3EUsers%20with%20Multiple%20Devices%20-%20Groups%20Best%20Practice%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1155385%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESay%20a%20user%20has%20multiple%20devices%20like%20so%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWindows%2010%20laptop%3C%2FP%3E%3CP%3EiOS%20Personal%20phone%3C%2FP%3E%3CP%3EiOS%20DEP%20%2F%20Corp%20phone%3C%2FP%3E%3CP%3EAndroid%20Enterprise%20Work%20Profile%3C%2FP%3E%3CP%3EAndroid%20Enterprise%20COFM%3C%2FP%3E%3CP%3EMacOS%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20best%20to%20create%20ONE%20group%20for%20policies%2C%20apps%20etc%20or%20create%20a%20group%20per%20OS%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EInfo%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1155385%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1157762%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20with%20Multiple%20Devices%20-%20Groups%20Best%20Practice%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1157762%22%20slang%3D%22en-US%22%3EThis%20is%20really%20dependent%20on%20the%20settings%20you%20specify%20per%20device.%3CBR%20%2F%3E%3CBR%20%2F%3EDo%20you%20push%20different%20settings%20to%20personal%2Fcoorporate%20devices%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1161505%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20with%20Multiple%20Devices%20-%20Groups%20Best%20Practice%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1161505%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20the%20same%20scenario%20for%20one%20of%20our%20customers%2C%20in%20that%20case%2C%20what%20I%20would%20suggest%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20create%20a%20Dynamic%20Groups.%3C%2FP%3E%3CP%3E%3CSTRONG%3EExample%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWindows%2010%20laptop%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.deviceOSVersion%20-startsWith%20%2210.0%22)%20and%20(device.deviceOwnership%20-eq%20%22Company%22)%3C%2FFONT%3E%3C%2FLI%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.deviceOSVersion%20-startsWith%20%2210.0%22)%20and%20(device.deviceOwnership%20-eq%20%22Personal%22)%3C%2FFONT%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EiOS%20Personal%20phone%3C%2FP%3E%3CUL%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.%3CSPAN%3EdeviceOwnership%3C%2FSPAN%3E-eq%20%22Personal%22)%26nbsp%3B%3C%2FFONT%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EiOS%20DEP%20%2F%20Corp%20phone%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.enrollmentProfileName%20-eq%20%22DEP%20iPhones%22)%26nbsp%3B%3C%2FFONT%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAndroid%20Enterprise%20Work%20Profile%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.deviceOSType%20-contains%20%22AndroidEnterprise%22)%20%3C%2FFONT%3E%3C%2FLI%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.deviceOSType%20-eq%20%22AndroidForWork%22)%3C%2FFONT%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EMacOS%3C%2FP%3E%3CUL%3E%3CLI%3E%3CFONT%20color%3D%22%23800000%22%3E(device.deviceModel%20-eq%20%22iPad%20Air%22)%3C%2FFONT%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20then%20simply%20create%20your%20Intune%20Management%20Profiles%20and%20Categories%20based%20on%20those%20created%20groups.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20don't%20forget%20to%20benefit%20of%20using%20device%20categories.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1161923%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20with%20Multiple%20Devices%20-%20Groups%20Best%20Practice%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1161923%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F194333%22%20target%3D%22_blank%22%3E%40Mahmoud%20A.%20Atallah%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Buddy%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20very%20much%20for%20the%20device%20queries%20per%20OS%2C%20very%20useful.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20you%20please%20recheck%20the%20queries%20on%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAE%20Corp%20Owned%20Fully%20Managed%3C%2FP%3E%3CP%3EiOS%20Personal%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStuart%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1162561%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20with%20Multiple%20Devices%20-%20Groups%20Best%20Practice%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1162561%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20the%20best%20approach%20is%20to%20create%20%3CSTRONG%3Edevice%20categories%2C%26nbsp%3B%3C%2FSTRONG%3E%20by%20using%20the%20deviceCategory%20attribute.%20For%20example%3A%20%3CSTRONG%3Edevice.deviceCategory%20-eq%20%E2%80%9CPersonal%20Device%E2%80%9C.%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EWhen%20users%20of%20iOS%20and%20Android%20devices%20enroll%20their%20device%2C%20they%20must%20choose%20a%20category%20from%20the%20list%20of%20categories%20you%20configured.%20After%20they%20choose%20a%20category%20and%20finish%20enrollment%2C%20their%20device%20is%20added%20to%20the%20Intune%20device%20group%2C%20or%20the%20Active%20Directory%20security%20group%20that%20corresponds%20with%20the%20category%20they%20chose.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1163719%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20with%20Multiple%20Devices%20-%20Groups%20Best%20Practice%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1163719%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F194333%22%20target%3D%22_blank%22%3E%40Mahmoud%20A.%20Atallah%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20thanks%20for%20your%20very%20informative%20reply.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDevice%20Categories%2C%20I%20find%2C%20can%20be%20prone%20to%20error%20from%20end%20users%2C%20ie%20selecting%20the%20wrong%20category.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20have%20a%20reference%20that%20this%20is%20the%20best%20practice%20here%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUser%20Groups%20vs%20Device%20Groups%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fconfiguration%2Fdevice-profile-assign%23user-groups-vs-device-groups%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fconfiguration%2Fdevice-profile-assign%23user-groups-vs-device-groups%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E
Regular Contributor

Hi All

 

Say a user has multiple devices like so:

 

Windows 10 laptop

iOS Personal phone

iOS DEP / Corp phone

Android Enterprise Work Profile

Android Enterprise COFM

MacOS

 

Is it best to create ONE group for policies, apps etc or create a group per OS?

 

Info appreciated

5 Replies
This is really dependent on the settings you specify per device.

Do you push different settings to personal/coorporate devices?
Best Response confirmed by Stuart King (Regular Contributor)
Solution

Hi @Stuart King , 

 

I had the same scenario for one of our customers, in that case, what I would suggest,

 

Just create a Dynamic Groups.

Example:

 

Windows 10 laptop 

  • (device.deviceOSVersion -startsWith "10.0") and (device.deviceOwnership -eq "Company")
  • (device.deviceOSVersion -startsWith "10.0") and (device.deviceOwnership -eq "Personal")

iOS Personal phone

  • (device.deviceOwnership-eq "Personal") 

iOS DEP / Corp phone 

  • (device.enrollmentProfileName -eq "DEP iPhones") 

Android Enterprise Work Profile 

  • (device.deviceOSType -contains "AndroidEnterprise")
  • (device.deviceOSType -eq "AndroidForWork")

MacOS

  • (device.deviceModel -eq "iPad Air")

 

And then simply create your Intune Management Profiles and Categories based on those created groups. 

 

And don't forget to benefit of using device categories.  

 

 

 

@Mahmoud A. Atallah 

 

Hi Buddy

 

Thanks very much for the device queries per OS, very useful.

 

Can you please recheck the queries on:

 

AE Corp Owned Fully Managed

iOS Personal

 

Stuart

@Stuart King 

 

As the best approach is to create device categories,  by using the deviceCategory attribute. For example: device.deviceCategory -eq “Personal Device“.

When users of iOS and Android devices enroll their device, they must choose a category from the list of categories you configured. After they choose a category and finish enrollment, their device is added to the Intune device group, or the Active Directory security group that corresponds with the category they chose.

@Mahmoud A. Atallah 

 

Many thanks for your very informative reply.

 

Device Categories, I find, can be prone to error from end users, ie selecting the wrong category.

 

Do you have a reference that this is the best practice here?

 

User Groups vs Device Groups:

 

https://docs.microsoft.com/en-us/intune/configuration/device-profile-assign#user-groups-vs-device-gr...

 

Regards