Intune / Entra dynamic group membership filter assistance

Jon Resele 60 Reputation points
2025-02-11T05:11:11.9833333+00:00

Hey all,

I work for an IT dept at a University. On my campus we have a space for College Faculty as well as Adjuncts. For that particular College, there is a department printer. Through Intune, I have a .ps1 that adds the department printer to any PC that is domain-named for that space.

The space is [loc]36#-D##

Any desktop located in the 36# area.

I'm having issues with locations that are in the 36* space that are in offices that contain a letter in the location, so like [loc]36#A-D## or [loc]36#F-D##

Desktops that are named "-D##" that do not have a letter involved are added to the dynamic group, but locations that have a letter after [loc]36. are not included.

Example: [loc]362-D01 is included in the group, [loc]360-D01 is included in the group, but [loc]360A-D01 is not.
This is my filter: (device.deviceOwnership -eq "Company") and (device.displayName -match "LOC36.-D.)
The wildcards on -match should be ".
" but in the validation the PCs I'm looking to add (in Entra) are not getting into the group.

I'm looking to include any endpoint that is named: LOC36.-D. but it doesn't seem to translate

Are there any filter tips to get me where I'm going?

I've already tried:
(device.deviceOwnership -eq "Company") and ((device.displayName -startsWith "LOC36") and (device.displayName -contains "-D")) but that didn't validate...

Microsoft Intune Grouping
Microsoft Intune Grouping
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Grouping: The arrangement or formation of people or things in a group or groups.
68 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,569 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,437 questions
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 16,280 Reputation points Microsoft Vendor
    2025-02-11T07:38:51.21+00:00

    @Jon Resele, Thanks for posting in Q&A.

    For your issue, please ensure the dynamic rule syntax is correct, and you can validate it follow the link below.

    https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-rule-validation

    The official documentation also points out that you should reduce the use of Contain and Match as much as possible to achieve better results.

    https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-rule-more-efficient

    Also, you can consider change the displayName and ownership to an easy one or consider the Consider other device attributes for filtering

    Here is a link containing the device attributes that you can refer to.

    https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership#rules-for-devices

    Hope above information can help you, if there is any update, feel free to let me know.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.