Adding newly enrolled devices while blocking existing enrolled device to a security group

Gokul R Dev 351 Reputation points
2023-05-12T04:40:57.1466667+00:00

Hello everyone,

I just want to know whether it's possible to create a dynamic group which adds devices that are going to be enrolled to intune in future while blocking the existing enrolled devices to join the group. If it's possible could someone help me on the dynamic query rule syntax.

Microsoft Security | Intune | Security
Microsoft Security | Intune | Enrollment
{count} votes

Accepted answer
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2023-05-12T05:34:47.1+00:00

    @Gokul R Dev, Thanks for posting in Q&A. After going through the properties of Dynamic membership rules, I didn't find a property can filter the newly enrolled device. But only filter the enrolled devices by using enrollmentProfileName. Here is a link with more details:

    https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-dynamic-membership

    If you want to filter the newly enrolled device, I think the device attribute like enrolled time needs to be added into the dynamic membership rule. You can feedback to AAD uservoice to see if it can be added in the future.

    https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.