Intune - Comprehensive Properties of Security Groups

Ignacio Ortiz 20 Reputation points
2024-06-05T12:44:20.9033333+00:00

Good morning,

For security groups created in the tenant, various custom or default policies can be added from the Intune, Entra ID, and Defender portals. In my case, I have configured several security groups, each with different associated policies and settings. However, I cannot find a way to determine exactly which policies or configurations are associated with each security group.

Inside the properties of these groups, we can see different parameters such as members, owners, roles, licenses… but there is no information about other aspects linked to the group. Currently, to find this out, I have to individually check each of the different policies to see which groups they are associated with... and this becomes very complicated when dealing with many policies.

Therefore, my question is: Is there a quick and comprehensive way to find out which policies and configurations are associated with a security group? This would greatly help me to make a proper administration and maintenance.

Thank you in advance!

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
428 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,173 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,064 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 49,191 Reputation points Microsoft Vendor
    2024-06-06T01:31:43.12+00:00

    @Ignacio Ortiz, Thanks for posting in Q&A. Based as I know, currently in Intune, there's no report to show policies assigned to group. But we can check the policies assigned to a device. if one user is only in this group, you can check the policies on this device as a workaround. Here is a link guide us how to get it.

    https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-monitor?tabs=policy%2Cdevices#view-existing-policies

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-06-05T12:59:47.4266667+00:00

    My advice, use virtual All devices\All Users groups in Intune and control assignments using filters wherever possible. Filters can also address your requirement of knowing which all assignments are assigned.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.