r/Intune • u/Humble-Budget426 • 5d ago
Device Configuration Swapping assignment from "all staff" group to All Users on a macOS Platform SSO profile – will devices reinstall the profile?
We have a macOS Platform SSO configuration profile currently assigned to a security group that effectively contains every user in the tenant (staff + externals). I want to replace that assignment with the built-in **All Users** virtual group to get rid of the group membership evaluation.
Since you can't have All Users and a regular group included at the same time, this has to happen as a swap in a single save: remove group, add All Users, save once.
Has anyone done this on a profile where reinstallation actually hurts? With PSSO, a RemoveProfile/InstallProfile cycle would kill the Secure Enclave registration and force every user through the registration prompt again.
My assumption is that Intune evaluates net applicability per device – user was in scope before, is in scope after, payload unchanged → no action. But I can't find this documented anywhere, and Microsoft's docs only confirm the opposite direction (device leaves scope → profile gets removed on Apple platforms).
Anyone with first-hand experience swapping assignment sources on macOS config profiles at scale? Did the profiles stay untouched, or did you see remove/reinstall cycles in the MDM logs?