Azure AD Membership Group changing group from assigned to dynamic

Mr Burns 1 Reputation point
2021-11-02T09:44:43.293+00:00

Hi,

I'm pretty new to AD management and am handling the migration of around 100 macOS devices to a new policy. Instead of editing the original device policy (to avoid disruption), I created a new device policy and manually moved over all existing devices to the new policy. This made each user change their password and was implemented this way to cause the least amount of disruption as possible. I now have an issue however, I need to make this policy a dynamic device policy and am wondering whether changing this policy type will in any way cause each user to have to reset their password for example / cause any other disruption. I am unable to find any information on this online but may have missed something, so apologies in advance if this question has been asked previously.

Thanks so much in advance for any help provided.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,729 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,365 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,568 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Simon Ren-MSFT 30,496 Reputation points Microsoft Vendor
    2021-11-03T09:12:40.063+00:00

    Hi,

    Thanks for posting in Microsoft Q&A forum.

    1,==>I need to make this policy a dynamic device policy and am wondering whether changing this policy type will in any way cause each user to have to reset their password for example / cause any other disruption.
    Do you mean to change your assigned group that contains around 100 macOS devices to dynamic group? If yes, after changing the group type, the existing membership may change based on dynamic membership rule we provide. However, per my experience. if one macOS device is already existed in the assigned group before change and continues to exist in the dynamic group afther change, the reset password policy will not re-run on the device and will not cause any other disruption.

    2,May we know which device policy you are using to reset the password for macOS device? Is it device compliance policy for macOS\System security\Password policy?

    If I have misunderstood anything, please feel free to let me know. Thanks for your time.

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.