CHiLL Posted April 16, 2024 Posted April 16, 2024 We have a mix of on-site (managed by SCCM but also synced in AAD) and off-site student/DFE laptops (managed by Intune only). The restrictions for the laptops were created in a rush during the pandemic and were basically machine only restrictions. I've taken the time to basically re-create our on-site GP settings in Intune, with the settings spread across both computer and user settings. While I'm testing the policies I am noticing that in the reporting of Intune, it shows the user policies as being evaluated and not applied for our users on our on-site devices. While I'm glad they're not being applied (since presumably ConfigMgr is preventing it), it would be nice for Intune to know not to even bother checking on this devices. I have looked at the filter options, where I have deployed the Intune policy to my user group and set the filter option to only our Intune/DFE devices...but they stopped being applied on all devices (no longer appearing in the Device Configuration tab in the device info in Intune). When I removed the filter, they eventually re-applied to the device and re-appeared in Device Configuration. I presume this was an issue because the filter was for devices whereas the policies are applied to users. Ideally, I'd just like to have a user policies that is only evaluated on specific devices. Is this possible?
mjhardisty Posted April 16, 2024 Posted April 16, 2024 Are the on-site devices appearing in Intune too?
CHiLL Posted April 16, 2024 Author Posted April 16, 2024 Are the on-site devices appearing in Intune too? Yeah, they show in the list of devices. For those on-site devices, "Managed by" is set as "Co-Managed" and "Compliance" is set to "See ConfigMgr".
mjhardisty Posted April 16, 2024 Posted April 16, 2024 https://www.tbone.se/2023/01/27/filter-out-devices-based-on-join-type-in-intune/ Would that work to exclude devices in policies that are Hybrid Joined?
CHiLL Posted April 16, 2024 Author Posted April 16, 2024 https://www.tbone.se/2023/01/27/filter-out-devices-based-on-join-type-in-intune/ Would that work to exclude devices in policies that are Hybrid Joined? I think it would do if I was deploying the policy to a device group, but I don't think the filter works if it filters devices but the assignment is targeting a user group.
mjhardisty Posted April 16, 2024 Posted April 16, 2024 I would presume the User policies would apply to all devices by default, so maybe adding this exclusion might work. Worth a try to understand the behaviour.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now