Deploy to compliant devices only

stromnessian 46 Reputation points
2020-08-17T05:17:43.797+00:00

Hi

I'm probably missing something obvious, but I was wondering how I could deploy an app or configuration profile and limit it to compliant devices. Conditional access obviously isn't the solution as it's only for accessing cloud apps. I guess a dynamic group wouldn't work either as it'd require Intune enrollment to get the compliance data. Any ideas?

Regards

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
953 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,175 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AndyLiu-MSFT 586 Reputation points
    2020-08-18T02:48:20.55+00:00

    For configuration profile, there is applicability rules, which allows to deploy the profile based on the combined criteria in the rule. However, currently, there are only two properties: OS edition and OS version. There is no compliant status. For more details about applicability rules, please click this link. https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-create#applicability-rules

    I think the best way is to create a dynamic group, but again, there is no property for device compliance in the dynamic group rule. For the details about dynamic group rule, please click this link. https://learn.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership

    Thus, it's not supported for deploy configuration profiles and apps to the compliant devices only. I would recommend to submit a feature request on the Intune uservoice site by click the following link.

    https://microsoftintune.uservoice.com/forums/291681-ideas

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.