Applying configuration policy - scope tag vs AAD group

Djordje Novakovic 311 Reputation points
2023-02-03T09:02:08.5833333+00:00

Hello,

When I create configuration policy or any other task in Intune and want to assign it I have option to define scope tags and groups.

I want to apply my policy to Azure AD group only. In Scope tags section there is "Default" tag by design.

Will that policy be applied to Azure AD group and all devices with "Default" tag?

Or it will apply only to Azure AD group?

User's image

User's image

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,549 questions
0 comments No comments
{count} votes

Accepted answer
  1. Ruud Gijsbers Rademakers 551 Reputation points
    2023-02-03T13:10:11.27+00:00

    Hi Djordje,

    The scope tags are not used for assigning the policies. Scope tags are used to configure RBAC Roles as described here: https://learn.microsoft.com/en-us/mem/intune/fundamentals/scope-tags

    So your policy will only apply to the users that are member of the Azure AD Group.

    Regards,

    Ruud

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Djordje Novakovic 311 Reputation points
    2023-02-03T13:12:26.3033333+00:00

    Clear, thanks!

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.