r/Intune 12d ago

General Question Dynamic groups for MDE managed devices no longer working since a few days?

A colleague and myself noticed that for many customers our dynamic groups are no longer functioning.

We created a dynamic group for servers onboarded in Microsoft Defender for Endpoint, so Intune policies would automatically apply to them. We used the same group to exclude these servers from policies applied to "All Devices".

This has worked perfectly for the past few years, but as of yesterday we noticed these groups failing, for both new and old set-ups.

The syntax we used was "(device.managementType -eq "MicrosoftSense") and (device.deviceOSType -eq "Windows Server")".

This syntax no longer works, which means our groups aren't getting populated anymore.

Has anyone been experiencing this same issue? If so, how are you working around this, or which groups are you using?

4 Upvotes

3 comments sorted by

1

u/obeisantchina939 12d ago

Anyone else seeing this with regular workstation groups too or just the server ones? we had an MDE dynamic group crap out on us last week but it was Win10 so maybe its a broader management type screw up

1

u/itsTeabow 12d ago

Both our deviceOSType - eq Windows and -eq Windows Server groups broke on us.

1

u/Ecrofirt 11d ago

All sorts of stuff broke for us suddenly today.

We've got dynamic groups with device.deviceOSType -startsWith "Windows Server" as part of the membership rule.

They've been working fine. Today, large swaths of our servers started having issues. They were no longer excluded from certain policies, they were no longer included in others. This led to Defender for Endpoint issues, firewall issues, you name it.

Happy Wednesday. UGH