How to Create Groups and Manage Users in Microsoft Intune

From Notes_Wiki

Home > Microsoft Intune > How to Create Groups and Manage Users in Microsoft Intune

How to Create Groups and Manage Users in Microsoft Intune

Description

Groups in Microsoft Intune (via Microsoft Entra ID / Azure AD) are used to organize users and devices. These groups help assign apps, policies, and configurations to specific users or devices.

Purpose

Creating user and device groups allows admins to:

  • Deploy apps and policies to specific departments or users.
  • Target compliance and configuration policies.
  • Simplify large-scale management.

Steps

A. Create a Group

  1. Go to Microsoft Entra Admin Center.
  2. In the left panel, click on Groups > All groups.
  3. Click + New group.

B. Configure Group Settings

  1. Under Group type, select:
    1. Security – used for Intune policies, app deployment, etc.
    2. Microsoft 365 – for email collaboration groups (not common for Intune).
  2. Enter a group name (e.g., HR Users or IT Devices).
  3. (Optional) Add a description.

C. Membership Type

  • Assigned – You manually add users/devices to the group.
  • Dynamic User – Members are added based on user attributes (e.g., department).
  • Dynamic Device – Devices are auto-added based on rules (e.g., OS type).
  • Mail-enabled Security – Rarely used with Intune.
  1. Select the Membership type.
  2. If using **Assigned**, click on + Members and add users/devices.
  3. Click Create.

D. Manage Group Members (For Assigned Groups)

  1. Go to the group > Members > + Add members.
  2. Search and select users or devices.
  3. Click Select > Add.

Real-world Example

An organization creates a group named “Sales Team – Laptops” with assigned membership. They later use this group to deploy a VPN configuration profile and an antivirus app via Intune.

Notes

  • Groups are essential for applying most Intune policies.
  • Dynamic groups are powerful for automation but may take a few minutes to populate.
  • Use naming conventions (like `Dept-Devices-Windows`) to keep groups organized.
  • Groups created here will reflect in Intune under Endpoint Manager.





Home > Microsoft Intune > How to Create Groups and Manage Users in Microsoft Intune