Microsoft Intune assignment

Abdullah 87 Reputation points
2023-03-29T09:22:01.9433333+00:00

We have configured for IOS, Android and Windows Compliance Policies and Configuration profiles. we have Hybrid infrastructure and we enabled automatic enrollment for hybrid Azure AD devices.

Not all the users in organization will have Intune license. in this case, should I assign the policies based on the users or the devices ?

Usually if all users have Intune license I configure dynamic group based on devices OS and apply it to the policies.

Please advise.

Thank you,

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
144 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,664 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,352 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-03-30T01:36:45.17+00:00

    @Abdullah Salem, Thanks for posting in Q&A.

    In General, to enroll device into Intune to be managed, Intune license is required. We can choose user related license like Microsoft Intune Plan 1 or device only license for some specific enrollment methods. Here is a link with more details for your reference:

    https://video2.skills-academy.com/en-us/mem/intune/fundamentals/licenses

    To assign policies, both licensed user group or device group are supported. In General, use device groups when you don't care who's signed in on the device, or if anyone signs in. You want your settings to always be on the device. use user groups when you want your settings and rules to always go with the user, whatever device they use. You can choose the group according to your requirement, Here is a link with more details:

    https://video2.skills-academy.com/en-us/mem/intune/configuration/device-profile-assign#user-groups-vs-device-groups

    For any useless device, like shared devices, co-management via device credential, you can assign the policy to these devices separately via device group.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.