Intune AutoPilot user group based on new autopilot device

Sanjeev Kumar 20 Reputation points
2024-11-11T20:55:39.3966667+00:00

Automatic User Group Assignment in Intune for Autopilot Deployments

The deployment of 3,000 Windows devices in Intune has been completed, with Office apps assigned to device groups. However, there are occasional failures occurring at the Enrollment Status Page (ESP). The current plan is to deploy Office apps to user groups instead and to skip the ESP's "Account Setup" stage.

Is there a way to automatically add users to a new group if they initiate a new Autopilot deployment?

Microsoft Intune Grouping
Microsoft Intune Grouping
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Grouping: The arrangement or formation of people or things in a group or groups.
61 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
963 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,249 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-11-11T21:48:00.2266667+00:00

    I would start by addressing the failures during the Autopilot provisioning process first. Skipping ESP is not the solution for failures. As for the question around office assignment is concerned, you cannot create a group the way you want dynamically using native functionality in Entra. Although I don’t really understand the approach here. If you want office to install after a user logs in then just assign to a user based group. If you are concerned about devices other than autopilot provisioned receiving the policy then just use a device filter and scope the to autopilot enrolled profile assigned devices.

    0 comments No comments

  2. Crystal-MSFT 49,846 Reputation points Microsoft Vendor
    2024-11-12T01:33:01.63+00:00

    @Sanjeev Kumar, Thanks for posting in Q&A. Based on checking the rule property, I find there's no attribute to create user group who initiate an Autopilot enrollment.

    https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership

    Agree with Rahul Jindal [MVP], you can use Intune filter to do it. You can create a filter with enrollmentProfileName set as the Autopilot enrollment profile. When deploy office to user group add this filter to only apply to these devices.

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/filters-device-properties

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.