@Abdullah Salem, Thanks for posting in Q&A.
In General, to enroll device into Intune to be managed, Intune license is required. We can choose user related license like Microsoft Intune Plan 1 or device only license for some specific enrollment methods. Here is a link with more details for your reference:
https://learn.microsoft.com/en-us/mem/intune/fundamentals/licenses
To assign policies, both licensed user group or device group are supported. In General, use device groups when you don't care who's signed in on the device, or if anyone signs in. You want your settings to always be on the device. use user groups when you want your settings and rules to always go with the user, whatever device they use. You can choose the group according to your requirement, Here is a link with more details:
For any useless device, like shared devices, co-management via device credential, you can assign the policy to these devices separately via device group.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.