Hybrid AD security computer groups in Intune - Exceptions not working

StephanG 811 Reputation points
2022-07-15T13:37:54.01+00:00

Hi everyone,

we are using rings to test out settings. These are defined by computer groups in the local AD that is synced with AD Connect.
We came across an issue when applying ASRs on some notebooks show an error.
ASRs can only applied in one policy.

So we have a Test, Ring1, Ring2, All computers group

The NB is in
Test
Ring1
Group

Ring1 Policy has
Ring 1 Group assigned. Test Group excepted.
Assignment overruled by exception you would think but no.

It is statet like this here:
https://learn.microsoft.com/en-us/mem/intune/apps/apps-inc-exl-assignments

Ring1 AND Test Policy are getting assigned and throw an error.

Anyone else having these problems? In the group there are only computers it is not mixed.

BR
Stephan

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,498 questions
{count} votes

2 answers

Sort by: Most helpful
  1. StephanG 811 Reputation points
    2022-07-18T07:11:57.097+00:00

    1 not to the same group
    2 yes we have - our test client
    3
    221792-2022-07-18-08h47-02.png

    221793-2022-07-18-09h05-09.png

    This shows our testclient which is in Ring0 and Test_ATP.
    In the 2nd screenshot you see that Ring0 is included but Test_ATP is excluded - so why does it says "succeeded" while the TEST Baseline which has only the Test_ATP group - is in Error.


  2. StephanG 811 Reputation points
    2022-07-18T08:03:33.343+00:00

    Ring1 has CompGRP_Ring1 assigned where this client is not a member.
    They are static device groups - synced from our AD (if this makes a difference).

    To make sure: A device group gets a device group if there are not users in it? :)