Intune Scope Groups prevent Assignment of Firewall Policy

ComputerHabit 861 Reputation points
2023-03-13T14:56:18.4933333+00:00

I am trying to use scope groups. When I assign a scope group to my EndPoint Secuirty Manager policy it will not allow an admin to assign a group to the policy.

I'm trying to setup profiles for Endpoint Security area. In this case a Firewall policy needing assignment.

I know that scope groups are to limit what you can manage. I'm not really understanding the relationship to this group and why it can't be assigned to the policy.

If I remove the scope group and make it all users\devices it works.

How do I maintain a scope group assignment and allow assignment of a group to a policy?

Does the group need to contain at least on System\User from the scope group?

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,665 questions
{count} votes

1 answer

Sort by: Most helpful
  1. ComputerHabit 861 Reputation points
    2023-03-27T15:22:12.9133333+00:00

    Hello,

    For anyone misunderstanding Scoped GROUPS.

    There is a bullet point at the bottom of the KB article that mentions how it is used.

    The Scoped Groups are used to Define the GROUPS the Admin is allowed to use. This means that to use a Group in a Policy it must be in the Admins Groups Scope. If it isn't it needs to be added.

    0 comments No comments