Assign applications using groups, filters, and targeting
After you've added an app to Microsoft Intune, you can assign the app to users and devices. It's important to note that you can deploy an app to a device whether or not the device is managed by Intune.
The following table lists the various options for assigning apps to users and devices:
| Option | Devices enrolled with Intune | Devices not enrolled with Intune |
|---|---|---|
| Assign to users | Yes | Yes |
| Assign to devices | Yes | No |
| Assign wrapped apps or apps that incorporate the Intune SDK (for app protection policies) | Yes | Yes |
| Assign apps as Available | Yes | Yes |
| Assign apps as Required | Yes | No |
| Uninstall apps | Yes | No |
| Receive app updates from Intune | Yes | No |
| End users install available apps from the Company Portal app | Yes | No |
| End users install available apps from the web-based Company Portal | Yes | Yes |
Assign apps to groups
- In the Microsoft Intune Admin Center, select Apps > All apps.
- In the Apps pane, select the app you want to assign.
- In the Manage section of the menu, select Properties.
- Scroll down and select Edit next to Assignments.
- For the specific app, select an assignment type:
- Required: The app is installed on devices in the selected groups. Some platforms may have other prompts for the end user to acknowledge before app installation begins.
- Available for enrolled devices: Assign the app to groups of users who can install the app from the Company Portal app or website.
- Available with or without enrollment: Assign this app to groups of users whose devices aren't enrolled with Intune. Users must be assigned an Intune license, see Intune Licenses.
- Uninstall: The app is uninstalled from devices in the selected groups if Intune has previously installed the application onto the device via an "Available for enrolled devices" or "Required" assignment using the same deployment.
- Select + Add group to open the Select groups pane.
- After you've selected one or more groups to include, select Select.
- Under Group mode verify the app assignment mode. You can exclude or include groups from the app assignment by changing this setting.
- In the app Assignments pane, select Review + Save.
Use filters to refine targeting
Groups define the broad target, but assignment filters let you refine that target using device properties or managed app properties. Filters are useful when a group is still too broad and you need to target only a subset, such as devices with a certain operating system version, manufacturer, enrollment profile, or ownership-related characteristic.
Intune supports filters for two scopes: managed devices and managed apps. Managed devices are devices enrolled in Intune. Managed apps are apps managed by Intune on devices that typically aren’t enrolled, such as in MAM scenarios.
For managed-device filters, you can build rules by using properties such as manufacturer, OS version, device category, or enrollment profile. For managed-app filters, Intune supports filtering for app-management scenarios, but those filters apply to app protection policies and app configuration policies, not to every workload in Intune.
Use assignment filters in the following scenarios:
- Deploy a Windows device restriction policy to only the corporate devices in the Marketing department, while excluding personal devices.
- Deploy an iOS/iPadOS app to only the iPad devices in the Finance users group.
- Deploy an Android mobile phone compliance policy to all users in the company, and exclude Android meeting room devices that don't support the mobile phone compliance policy settings.
- On personally owned devices, deploy an app configuration policy for a specific app manufacturer or an app protection policy that runs a specific OS version.
Assignment filters include the following features and benefits:
- Improve flexibility and granularity when assigning Intune policies and apps.
- Are used when assigning apps, policies, and profiles. They dynamically target managed devices based on device properties and target managed apps based on app properties you enter.
- Can include or exclude devices or apps in a specific group based on criteria you enter.
- Can create a query of device or app properties based on different properties, like device platform or application version.
- Can be used and reused in multiple scenarios in "Include" or "Exclude" mode.
This feature applies to:
Managed devices on the following platforms:
- Android device administrator
- Android Enterprise
- Android (AOSP)
- iOS/iPadOS
- macOS
- Windows
Managed apps on the following platforms:
- Android
- iOS/iPadOS
- Windows
Create a filter for managed devices
In the Intune admin center, select Tenant administration > Assignment filters > + Create > Managed devices.
In Basics, enter a name (e.g., Windows OS version filter) and a description, select your platform and select Next.
In the Rules pane, there are two ways to create a rule: Use the rule builder, or use the rule syntax.
Create a rule using the rule builder:
- Property: osVersion (OS Version)
- Operator: Equals
- Value: 10.0.26200
Select Add expression and enter following information:
- And/Or: And
- Property: manufacturer (Manufacturer)
- Operator: Equals
- Value: Microsoft
Select Next.
In the Scope tags pane, select a scope tag (optional) and select Next.
In the Review + create pane, select Create to create the filter.
Use a filter
In the intune admin center, select the app you want to assign and edit the assignment.
Assign the app to users group or a devices group.
In the column Filter mode select None to edit the filter.
In the Assignment filter pane, select one of the following options:
Do not apply a filter: All targeted users or devices receive the app or policy without filtering.
Include filtered devices in assignment: Devices that match the assignment filter conditions receive the app or policy. Devices that don't match the assignment filter conditions don't receive the app or policy.
A list of assignment filters that match the policy platform is shown.
Exclude filtered devices in assignment: Devices that match the assignment filter conditions don't receive the app or policy. Devices that don't match the assignment filter conditions receive the app or policy.
Select your existing assignment filter, then select Select.
Select Review + save, then in the Review + save pane select Save to finish the assignment.