Entra IDHow-to

Dynamic device groups for Intune: membership rules that actually work

Working dynamic device rules for Autopilot, group tags, OS version, ownership and enrollment profiles, plus licensing, processing time, rule validation and when filters fit better.

Dynamic device groups drive most Intune targeting, so a small mistake in a rule quietly decides which devices get your apps and policies. When a device doesn't land where you expect, the cause is usually the rule syntax, the attribute value, or processing time. Here are rules built on documented attribute values, how to test them before you save, and when an Intune assignment filter is the better tool.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Create the group; Write rules against real attribute values; Validate before you save; Allow for processing time). 3. Verify. 4. Tips & gotchas. Toolbox: Groups › New group, Groups › All groups, [OrderID], AzureAD, ServerAD.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Create the group2Write rules against realattribute values3Validate before you save4Allow for processing timeTOOLBOXGroups › New groupGroups › All groups[OrderID]AzureADServerADHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Create the group; Write rules against real attribute values; Validate before you save; Allow for processing time). 3. Verify. 4. Tips & gotchas. Toolbox: Groups › New group, Groups › All groups, [OrderID], AzureAD, ServerAD.1Prerequisites2Step-by-step1Create the group2Write rules against real attribute values3Validate before you save4Allow for processing time3Verify4Tips & gotchasTOOLBOXGroups › New groupGroups › All groups[OrderID]AzureADServerAD
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

Prerequisites#

  • Licensing: dynamic membership needs Microsoft Entra ID P1 (or Intune for Education) for each unique user who is a member of dynamic groups. Devices in device-based dynamic groups don't need a license. Bundles such as Microsoft 365 E3 and Business Premium include Entra ID P1.
  • Role: at least Groups Administrator to create rules and use rule validation.
  • Limits: up to 15,000 dynamic groups per tenant. A rule can't mix users and devices, and device rules can only reference device attributes, never the owner's department or other user attributes.

Step 1: Create the group#

In the Microsoft Intune admin center, go to Groups › New group. Choose Security, set Membership type to Dynamic Device and select Add dynamic query. For anything beyond a simple expression, select Edit in the Rule syntax section and paste the rule. The group is a Microsoft Entra group, so it also appears under Entra ID › Groups › All groups.

Step 2: Write rules against real attribute values#

GoalRule
All Windows Autopilot devices(device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]"))
Autopilot devices with a group tag(device.devicePhysicalIds -any (_ -eq "[OrderID]:CAI-Kiosk"))
Autopilot devices from a purchase order(device.devicePhysicalIds -any (_ -eq "[PurchaseOrderId]:76222342342"))
Corporate-owned Windows devices(device.deviceOSType -eq "Windows") -and (device.deviceOwnership -eq "Company")
Windows 11 devices(device.deviceOSType -eq "Windows") -and (device.deviceOSVersion -startsWith "10.0.2")
Devices from one enrollment profile(device.enrollmentProfileName -eq "ADE - Shared iPads")
Microsoft Entra hybrid joined devices(device.deviceTrustType -eq "ServerAD")

The details that trip people up:

  • Group tag = OrderID. The Autopilot group tag you set in Intune is stored as the [OrderID] physical ID on the Entra device.
  • Ownership is Company in Entra rules, even though Intune shows Corporate. The other values are Personal and Unknown.
  • OS version is a string. Windows 10 builds report as 10.0.1… and Windows 11 builds as 10.0.2…, so prefix matching with -startsWith separates them.
  • Trust type values are AzureAD (Entra joined), ServerAD (hybrid joined) and Workplace (registered).
  • enrollmentProfileName holds the Apple ADE profile, Android Enterprise corporate-owned dedicated device profile, or Windows Autopilot profile name.

Tip: for groups that receive Autopilot deployment profiles or OOBE configuration, stick to Autopilot attributes ([ZTDid], [OrderID], [PurchaseOrderId]). Microsoft notes that other attributes aren't guaranteed to be populated before provisioning, which can lead to unexpected configuration during setup.

Step 3: Validate before you save#

Open the group's Dynamic membership rules and use the Validate Rules tab to test up to 20 devices at a time. Each result shows whether the device would be a member, and View details breaks the rule into its expressions so you can see which one failed. A result of Unknown means the rule is invalid or there was a network problem.

If a value doesn't match what you expect, check what Entra ID actually stores:

PowerShell
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -Search "displayName:PC-0042" -ConsistencyLevel eventual |
    Select-Object DisplayName, OperatingSystem, OperatingSystemVersion, TrustType, PhysicalIds

Step 4: Allow for processing time#

  • Membership changes are usually processed within a few hours, but can take more than 24 hours depending on the number of groups, the volume of changes and rule complexity.
  • Any attribute change triggers evaluation of every dynamic rule in the tenant, and stale devices are evaluated too. Cleaning them up keeps processing faster.
  • Check the membership processing status on the group's Overview page before deciding the rule is wrong.
  • Once membership changes in Entra ID, Intune typically picks it up within about five minutes; the device still has to check in to receive the policy.

Verify#

  • The group's Members list contains the devices you expect, and Validate Rules agrees for edge cases, such as an Autopilot device without a group tag.
  • In Intune, the policy or app's device status lists the targeted devices.

Tips & gotchas: when a filter beats a dynamic group#

Intune assignment filters refine an assignment when the device checks in, without precomputing group membership, so there's no group processing delay. Microsoft recommends assigning to the built-in All devices and All users virtual groups instead of recreating them as dynamic groups, and applying the same thinking to other large, fast-changing groups such as "all Windows devices".

NeedBetter fit
Assign Autopilot deployment profilesDynamic device group using ZTDid or OrderID
A group other Entra features or teams will useDynamic or assigned group
Slice an Intune policy or app by OS version, model, ownership or enrollment profileAssignment filter on an existing group
Very large or fast-changing populationsAll devices plus a filter
  • Filters only apply to Intune-managed devices and apps, on supported workloads.
  • Filter values can differ from Entra rules: ownership is Corporate in filters, Company in dynamic rules.
  • To see why a filter matched, open Devices › All devices, select the device and choose Filter evaluation. Results can take up to 30 minutes to appear.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)