Hi Djordje,
The scope tags are not used for assigning the policies. Scope tags are used to configure RBAC Roles as described here: https://learn.microsoft.com/en-us/mem/intune/fundamentals/scope-tags
So your policy will only apply to the users that are member of the Azure AD Group.
Regards,
Ruud