MDM Profiles, Policies, and Groups
Jeremy Moskowitz · 2019
This chapter describes four goals: 1. Create your first MDM policies. 2. Get to know some of the inner workings of how the guts of MDM policies are constructed. 3. Utilize third-party ADMX files. 4. Learn how to create and leverage MDM groups to target policies. An MDM service also enables you to create specific Assigned groups and also Dynamic groups. Assigned groups are where you directly dictate that specific users or computers are put inside. Dynamic groups are where you set criteria, such that when the condition applies, then the user or computer automatically gets evaluated to be contained within the group. Assigned groups, again, simply means you're directing which users or computers are inside. These are akin to on-prem AD Security Groups, but they're used mostly for targeting where Intune profiles will used. To create an Assigned group, simply pull down the group type as Security, provide a group name and optional description, and then specify the membership type as Assigned. Dynamic groups are a nice touch, and a good idea. That being said, the actual fields that you can use query upon and then make Dynamic groups is a little paltry.