![]() ![]() Unfortunately, this can lead to errors when it reports on the overall compliance of the device. The user who signs into the device will also receive a compliance status.The “system account” will receive a compliance status.If you assign these policies to devices, you will find that there are two compliance results for every device (well, actually three if you include the built-in policy). Is it possible to assign a compliance policy to a security group comprised of devices? Yes. When it comes to Compliance policies, I always target users. The type of policy or profile you are working with may answer the question for you. Let’s start with the second question first. What type of policy or profile are we working with?.Are you trying to control an experience based on who the user is, or what device they are using?.Unfortunately, there is no one size fits all here so we have to give the classic consultant answer: “It depends.” On what does it depend? A couple of factors: Eliminating that option right off the bat, let’s narrow it down further by determining when it would be best to recommend targeting Users vs. Dynamic Security groups comprised of Devicesįirst, just know that you should use Security groups to assign policies and profiles within Intune (I would not use Microsoft 365 Groups).Dynamic Security groups comprised of Users.Static Security groups comprised of Devices.Static Security groups comprised of Users. ![]() The question is: When working in Microsoft Endpoint Manager (Intune), how do I determine whether to assign policies to devices or users?īefore we describe the best practices here I think it is important to review a little bit of information about security groups. In truth, it is not the first time I have answered this question, but I realized that I could probably repeat myself less if I simply write an article and publish it. ![]() A new reader question came across my desk the other day. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |