How to Create Azure AD Dynamic Groups for Managing Devices via Intune

In this post, we will see how to create Dynamic device groups and User Groups in Azure Active Directory. Azure AD groups are similar to collections (in SCCM world) for Intune device management solution. These AAD groups can be intern used to target different policies to specific group of devices. So this is very important in the world of modern management of devices using Microsoft Intune. If you are a SCCM admin, AAD dynamic group are similar to creating dynamic collection using WQL query rules. AAD groups don’t have that granularity in creating dynamic query rules if you compare it with WQL query rules. However, new Azure portal has loads of options to create dynamic query rules. The video tutorial will help you get more insides of AAD Dynamic groups.

AAD Dynamic membership advanced rules are based on binary expressions. One Azure AD dynamic query can have more than one binary expression. Each binary expression in AAD dynamic membership rule query must have 3 parts Left parameter, Binary operator and Right constant. Left parameter in query rule is one of the attribute of AAD object (either user or device). In case, you want to query users in a particular department then user is object and department is attribute (user.department). Binary operator is nothing other than conditional operator like “-ne,-eq, -contains -match”. Right constant is constant value specific to your requirement for example if you want to create a group for all IT users, then right constant value is “IT”.

(user.department -startsWith "IT")
(user.department -match "IT")
(user.department -eq "IT")

I did a test to understand what is the maximum supported words/characters in Azure AD dynamic advanced membership rule and I found that we could save a query with maximum of 311 words and 3045 characters. When I increased the numbers to 315 words and 3085 characters, it started giving an error “Failed to create Group_Maxi. Undefined” where MAXI is the group name.

How to Create Azure AD Dynamic Groups for Managing Devices via Intune 2

Now back to Intune and device management. I will create 3 basic groups for device management and these AAD dynamic device groups (All Windows Devices, All iOS Device and All Android Devices) will be used to deploy different configuration policies.

First I wanted to group for all windows devices in my Intune environment.  There are two ways to create AAD group with dynamic membership query rules 1. Simple rule and 2. Advanced Rule. To group windows devices based on operating system it’s better to use simple query via Azure portal GUI. In case you want to use advance membership, then following is the query “(device.deviceOSType -contains “Windows”)“. When you create a Azure AD dynamic device group, it’s going to take time 1 or 2 minutes (depending upon the complexity of the query and the size of the database) to populate the devices into the group.

How to Create Azure AD Dynamic Groups for Managing Devices via Intune 3

It’s time to find out iOS devices (iPhone or iPad) in my environment via AAD Dynamic query and group those devices into a AAD dynamic group. Unlike Windows device group, iOS device AAD dynamic Device group can’t be created using simple membership rule rather we should use Advanced membership rule. This is because we need to have two constant values like iPhone and iPad.  Following is the query which I used to fetch iOS devices (device.deviceOSType -contains “iPhone”) -or (device.deviceOSType -contains “iPad”).

How to Create Azure AD Dynamic Groups for Managing Devices via Intune 4

OK, here we go with grouping of Android devices. In this scenario, I want to create AAD dynamic device group using simple membership rule. Because I don’t have more than one constant value in AAD group binary expression. Following is the dynamic query for Android device group “(device.deviceOSType -contains “Android”)“.

How to Create Azure AD Dynamic Groups for Managing Devices via Intune 5

Reference TechNet document about Azure AD dynamic group here

New Azure portal – This will directly take you to all Groups blade

Sharing is caring!

13 thoughts on “How to Create Azure AD Dynamic Groups for Managing Devices via Intune”

  1. Anoop -this post is really helpful, thanks very much for taking the time to write it up.

    I wondered however if you could let me know how you found that you should use ‘deviceOSType’ – when I created dynamic groups for users it it is easy to get a list of attributes…not sure how to do the same for devices.

    Many thanks!


  2. Awesome thanks – I managed to create a dynamic group that contained devices whilst waiting for your update, from this group I could get an object in this group and | fl to get full details. I will read your post now also as Graph is another area of interest to me.

    Thanks again

  3. Hi Anoop,
    Any way we can create AAD Device groups based on AD OU, Programs Installed, basically like more granular queries like we can with SCCM collections?


  4. Is there any option to create a user Group based on the Device Type they are using? For e.g. create a user group for all MacOS users.

    • I think you are trying to replicate the sccm collection logic to azure ad dynamic groups. If so, I don’t think that is possible …. you might need to use requirements rules or custom script for that … I suppose


Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.