Skip to content
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups

How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups

Written By Anoop C Nair
Last Updated June 15, 2026
Posted In Entra
SHARE

Key Takeaways

  • Automatically organize devices during enrollment.
  • Reduce manual device group assignments.
  • Improve consistency and scalability in device management.
  • Deploy applications and policies based on department or device role.

In this post let’s Learn How to Setup Dynamic Device Groups in Intune. Managing devices efficiently is a part of endpoint administration. Microsoft Intune provides several methods to organize and manage devices, and Device Categories remain a simple and effective option for assigning devices to the correct groups during enrollment.

How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups

By combining Device Categories with Dynamic Device Groups in Microsoft Entra ID, administrators can reduce manual effort and ensure devices receive the correct policies, applications, and configurations. This approach helps device management and improve deployment consistency across the organization.

How Do You Add Devices Automatically to Intune Groups using Microsoft Entra Dynamic Device Groups?

To automatically add devices to Intune groups, you first need to create a Dynamic Device Group in the Microsoft Entra admin center. Sign in to the Microsoft Entra portal, navigate to Groups > All Groups, and select New Group. Dynamic groups automatically manage membership based on rules, eliminating the need to manually add or remove devices.

In this example, we will create a security group that uses dynamic membership rules. Once the group is created, Microsoft Entra automatically evaluates devices against the configured rule and adds matching devices to the group. This makes device management more efficient and ensures devices are always assigned to the correct group.

Patch My PC
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups - Fig.1
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups – Fig.1

On the New Group page, select Security as the Group Type and provide a Group Name and Description. Under Membership Type, select Dynamic Device instead of Assigned. This enables Microsoft Entra to automatically manage group membership based on the rules you define.

  • After selecting Dynamic Device, create a membership rule that identifies the devices you want to include in the group.
  • Once the rule is validated and saved, select Create.
  • Microsoft Entra will begin processing the rule and automatically add devices that meet the specified criteria.
  • Whenever a new user joins the IT department, that user is automatically added to the Intune MDM group. Provisioning and de-provisioning groups is made easy with this.

Microsoft Entra ID provides 2 methods for creating dynamic membership rules: the Rule Builder and the Rule Syntax editor. The Rule Builder offers an easy-to-use graphical interface, while the Rule Syntax editor allows advanced administrators to create more complex queries. To automatically add Hybrid Microsoft Entra joined devices to a dynamic device group, select Add Dynamic Query, choose deviceTrustType as the property, set the operator to Equals, enter ServerAD as the value, and then save the rule.

More Details -> Create AAD Dynamic Groups Based On Domain Join Type Hybrid Azure AD And Azure AD

Learn How to Setup Dynamic Device Groups in Intune
Login to Microsoft Entra portal
Navigate to the Groups > All Groups >select New Group.
Group Type -> Security
Group Name ->HTMD Hybrid Device Group
Group Description -> To add all devices or users from a dept
Membership Type -> Dynamic User
LeHow to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups – Table 1
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups - Fig.2
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups – Fig.2

Access the Dynamic Device Group

Navigate to Groups > All Groups in the Microsoft Entra admin center and locate the Dynamic Device Group you want to manage. Select the group to review its settings and configure dynamic membership rules. Once selected, the group can automatically add devices that meet the specified criteria, reducing administrative effort and ensuring devices are organized.

How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups - Fig.3
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups – Fig.3

Automatically Assign Devices to Intune Groups with Device Categories

Microsoft Intune Device Categories help administrators organize devices and automatically assign them to the appropriate groups during enrollment. To create a device category, sign in to the Intune admin center and navigate to Devices > Manage Devices > Device Categories. Select Create, provide a category name and description, and then save the category.

Device Categories can represent departments, locations, or device purposes such as IT, HR, Finance, or Sales. When users enroll their devices through the Microsoft Intune Company Portal app, they can select the appropriate category. This category can then be used with Microsoft Entra dynamic device groups to automatically group devices and simplify policy and application assignments.

  • I have created only one category, “ADMIN,” for users. You are free to make an Intune device category for each department!!

More details on AAD Groups Based On Intune Device Categories.

How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups - Fig.4
How to Automatically Add Devices to Intune Groups using Microsoft Entra Dynamic Device Groups – Fig.4

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community and WhatsApp Channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows,   Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read