Dynamic device groups drive most Intune targeting, so a small mistake in a rule quietly decides which devices get your apps and policies. When a device doesn't land where you expect, the cause is usually the rule syntax, the attribute value, or processing time. Here are rules built on documented attribute values, how to test them before you save, and when an Intune assignment filter is the better tool.
Prerequisites#
- Licensing: dynamic membership needs Microsoft Entra ID P1 (or Intune for Education) for each unique user who is a member of dynamic groups. Devices in device-based dynamic groups don't need a license. Bundles such as Microsoft 365 E3 and Business Premium include Entra ID P1.
- Role: at least Groups Administrator to create rules and use rule validation.
- Limits: up to 15,000 dynamic groups per tenant. A rule can't mix users and devices, and device rules can only reference device attributes, never the owner's department or other user attributes.
Step 1: Create the group#
In the Microsoft Intune admin center, go to Groups › New group. Choose Security, set Membership type to Dynamic Device and select Add dynamic query. For anything beyond a simple expression, select Edit in the Rule syntax section and paste the rule. The group is a Microsoft Entra group, so it also appears under Entra ID › Groups › All groups.
Step 2: Write rules against real attribute values#
| Goal | Rule |
|---|---|
| All Windows Autopilot devices | (device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]")) |
| Autopilot devices with a group tag | (device.devicePhysicalIds -any (_ -eq "[OrderID]:CAI-Kiosk")) |
| Autopilot devices from a purchase order | (device.devicePhysicalIds -any (_ -eq "[PurchaseOrderId]:76222342342")) |
| Corporate-owned Windows devices | (device.deviceOSType -eq "Windows") -and (device.deviceOwnership -eq "Company") |
| Windows 11 devices | (device.deviceOSType -eq "Windows") -and (device.deviceOSVersion -startsWith "10.0.2") |
| Devices from one enrollment profile | (device.enrollmentProfileName -eq "ADE - Shared iPads") |
| Microsoft Entra hybrid joined devices | (device.deviceTrustType -eq "ServerAD") |
The details that trip people up:
- Group tag = OrderID. The Autopilot group tag you set in Intune is stored as the
[OrderID]physical ID on the Entra device. - Ownership is
Companyin Entra rules, even though Intune shows Corporate. The other values arePersonalandUnknown. - OS version is a string. Windows 10 builds report as
10.0.1…and Windows 11 builds as10.0.2…, so prefix matching with-startsWithseparates them. - Trust type values are
AzureAD(Entra joined),ServerAD(hybrid joined) andWorkplace(registered). - enrollmentProfileName holds the Apple ADE profile, Android Enterprise corporate-owned dedicated device profile, or Windows Autopilot profile name.
Tip: for groups that receive Autopilot deployment profiles or OOBE configuration, stick to Autopilot attributes ([ZTDid], [OrderID], [PurchaseOrderId]). Microsoft notes that other attributes aren't guaranteed to be populated before provisioning, which can lead to unexpected configuration during setup.
Step 3: Validate before you save#
Open the group's Dynamic membership rules and use the Validate Rules tab to test up to 20 devices at a time. Each result shows whether the device would be a member, and View details breaks the rule into its expressions so you can see which one failed. A result of Unknown means the rule is invalid or there was a network problem.
If a value doesn't match what you expect, check what Entra ID actually stores:
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -Search "displayName:PC-0042" -ConsistencyLevel eventual |
Select-Object DisplayName, OperatingSystem, OperatingSystemVersion, TrustType, PhysicalIdsStep 4: Allow for processing time#
- Membership changes are usually processed within a few hours, but can take more than 24 hours depending on the number of groups, the volume of changes and rule complexity.
- Any attribute change triggers evaluation of every dynamic rule in the tenant, and stale devices are evaluated too. Cleaning them up keeps processing faster.
- Check the membership processing status on the group's Overview page before deciding the rule is wrong.
- Once membership changes in Entra ID, Intune typically picks it up within about five minutes; the device still has to check in to receive the policy.
Verify#
- The group's Members list contains the devices you expect, and Validate Rules agrees for edge cases, such as an Autopilot device without a group tag.
- In Intune, the policy or app's device status lists the targeted devices.
Tips & gotchas: when a filter beats a dynamic group#
Intune assignment filters refine an assignment when the device checks in, without precomputing group membership, so there's no group processing delay. Microsoft recommends assigning to the built-in All devices and All users virtual groups instead of recreating them as dynamic groups, and applying the same thinking to other large, fast-changing groups such as "all Windows devices".
| Need | Better fit |
|---|---|
| Assign Autopilot deployment profiles | Dynamic device group using ZTDid or OrderID |
| A group other Entra features or teams will use | Dynamic or assigned group |
| Slice an Intune policy or app by OS version, model, ownership or enrollment profile | Assignment filter on an existing group |
| Very large or fast-changing populations | All devices plus a filter |
- Filters only apply to Intune-managed devices and apps, on supported workloads.
- Filter values can differ from Entra rules: ownership is
Corporatein filters,Companyin dynamic rules. - To see why a filter matched, open Devices › All devices, select the device and choose Filter evaluation. Results can take up to 30 minutes to appear.