• Home
  • IT
maciejrebisz.com

How to create a Dynamic Device Group in AzureAD for Personal and Corporate devices – Cloud First

When we are using Intune in the new Azureportal (Ibiza) then we what to take advanced of dynamic device groups.

In many cases we what to make Device Configuration and deploy to either to personal or corporate devices, the easy way is to create 2 dynamic devices groups.

One for personal devices:

Powershell:

New-AzureADMSGroup -Description “All Personal Devices” -DisplayName “All Personal Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOwnership -eq “Personal”)” -MembershipRuleProcessingState “On”

One for Company devices:

Powershell:

New-AzureADMSGroup -Description “All Company Devices” -DisplayName “All Company Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOwnership -eq “Company”)” -MembershipRuleProcessingState “On”

As a request I have updated this post to also include combined Dynamic groups for Personal or Corporate device groups – the following examples are combined with OS type.

All Personal Ipad devices

 New-AzureADMSGroup -Description “All Personal Ipad Devices” -DisplayName “All Personal Ipad Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOSType -eq “Ipad“) -And (device.deviceOwnership -eq “Personal”)” -MembershipRuleProcessingState “On”

All Personal Android devices

New-AzureADMSGroup -Description “All Personal Android Devices” -DisplayName “All Personal Android Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOSType -eq “Android”) -And (device.deviceOwnership -eq “Personal”)” -MembershipRuleProcessingState “On”

All Corporate Ipad devices

New-AzureADMSGroup -Description “All Company Ipad Devices” -DisplayName “All Company Ipad Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOSType -eq “Ipad”) -And (device.deviceOwnership -eq “Company”)” -MembershipRuleProcessingState “On”

All Corporate Ipone devices

New-AzureADMSGroup -Description “All Company Iphone Devices” -DisplayName “All Company Iphone Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOSType -eq “Iphone”) -And (device.deviceOwnership -eq “Company”)” -MembershipRuleProcessingState “On”

All Corporate Android devices

New-AzureADMSGroup -Description “All Company Android Devices” -DisplayName “All Company Android Devices” -MailEnabled $false -SecurityEnabled $true -MailNickname “Win” -GroupTypes “DynamicMembership” -MembershipRule “(device.deviceOSType -eq “Android”) -And (device.deviceOwnership -eq “Company”)” -MembershipRuleProcessingState “On”

Related Posts

Windows-Hello-For-Business-Active-Directory[1]

IT /

How to setup Windows Hello for Business in the new Intune portal

B-Intune-Graphic[1]

IT /

How to deploy Shared Devices with Intune for Education and Autopilot in the future

wp-1593849019379[1]

IT /

Managed browser extensions on Edge with Intune

‹ SCCM – Page 2 – Cloud First › How to configure Windows 10 Storage Sense – Cloud First

YouTube

Ad

banner

Ad

banner

Back to Top