Close Menu
    Facebook X (Twitter) Instagram
    Sunday, October 12
    X (Twitter) LinkedIn Reddit RSS
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»Office 365»Azure Active Directory»Get a list of devices based on iOS enrolment type – dynamic groups in Azure Active Directory

    Get a list of devices based on iOS enrolment type – dynamic groups in Azure Active Directory

    Eswar KonetiBy Eswar KonetiNovember 28, 10:17 pm2 Mins Read Azure Active Directory 8,696 Views
    Share
    Facebook Twitter LinkedIn Reddit

    A year ago, Apple announced a new method of iOS/iPad device enrolment which is called User Enrollment. This enrolment method is available in iOS 13 and macOS 10.15 Catalina and later OS.

    with user enrollment, we can use federated authentication to link Apple Business Manager to your instance of Microsoft Azure Active Directory (Azure AD). As a result, your users can leverage their Azure AD usernames (User Principal Name) and passwords as Managed Apple IDs. They can then use their Azure AD credentials to sign in to their assigned iPad or Mac and even to iCloud on the web. Users can also use it to sign in on Shared iPad.

    For more information, please refer https://support.apple.com/en-gb/guide/apple-business-manager/apdb19317543/web

    With the availability of user enrolment from Apple, we can use Intune to enroll iOS and iPadOS devices using Apple's User Enrolment process.

    Following are the 3 device enrolment types available.

    image

    For more information about user enrollment in Intune, please refer to https://docs.microsoft.com/en-us/mem/intune/enrollment/ios-user-enrollment?

    After you create an enrolment profile, assign to a user group and enroll the devices, you may need to identify the list of devices that use a specific enrolment profile for reporting purpose.

    In my tenant, I have created 3 different enrollment types and assigned them to various user groups based on the requirement.

    image

    Now how do we know devices that are are enrolled using particular enrollment type?

    We can use Azure Active Directory dynamic membership group with an enrollment profile name.

    Azure Active Directory (Azure AD) helps you to create complex attribute-based rules to enable dynamic memberships for groups.

    To create dynamic Azure AD group for specific enrollment profile, follow the steps below.

    1. Login to https://aad.portal.azure.com/ or https://endpoint.microsoft.com/
    2. Click on Azure Active Directory, click on Groups
    3. Click on create a new group, give it a name, description and for membership rule, choose Dynamic Device, click on add dynamic query

    image

    4. Configure the values as per below.

    Value should be the enrollment type name that you created above.

    image

    5. Click on save and create

    The group will now start processing the changes and fetch the devices that match the specific enrollment type.

    Like wise, you can create several azure AD dynamic groups based on the attributes available and used in intune.

    For a list of pre-defined rules and device attributes that can be used in dynamic groups, please refer

    https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-dynamic-membership#rules-for-devices

    Azure AD dynamic group EMS enrollment profie intune iOS User enrollment MEM user enrollment
    Share. Twitter LinkedIn Email Facebook Reddit

    Related Posts

    Export Microsoft Entra ID User Authentication Methods to CSV using PowerShell & Microsoft Graph API

    August 13, 2:08 pm

    Automating Intune Deployment Rings Using Entra ID Dynamic Groups and Regex

    July 01, 10:31 pm

    Exporting Intune Win32 Apps with All Properties Using PowerShell and Microsoft Graph

    June 30, 7:01 pm

    3 Comments

    1. Lori Reive on May 12, 2025 9:57 PM

      I believe i am hacked with the hacker using a Microsoft cloud based MDM program. This is my personal device. I’m retired and do not work. But my device is telling me that my email is enrolled in this program. it was also telling me my computer is enrolled in Windows hello for business. Can you please check my email address on these programs. I have already check with apple. Please help i have been hacked for 3 years. Have 5 police reports have lost thousands. Every file i find on phone relates to azure and on computer relates to windows hello for business. I been through hell. I know who is targeting me.

      Reply
    2. DT on April 13, 2022 1:29 PM

      Hello Easwar,

      This is a generic query on group creation

      Would it be possible to create dynamic device group in Intune based on iOS serial numbers ?

      Reply
      • Eswar Koneti on May 4, 2022 10:47 PM

        Hi,
        Serial number is not listed as an attribute in the dynamic group creation. You will have to use powershell to query the data to create the group based on the devices.

        Thanks,
        Eswar

        Reply

    Leave a ReplyCancel reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Sign Up

    Get email notifications for new posts.

    Author

    I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

    Support

    Awards

    Archives

    © Copyright 2009-2025 Eswar Koneti, All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.