Microsoft recently introduced Filters in Microsoft Endpoint Manager / Intune which allow more granular targeting of applications and policies to specific devices. In this blog post, we will see how we can deploy a Microsoft Store app to a group of devices using Azure AD group and MEM Filters.
We will deploy Microsoft Whiteboard to all Windows 10 Devices whose Device Category is ‘Training Devices’. For this example, we already approved the Microsoft Whiteboard application in Microsoft Store for Business (MSfB) and it’s synced with Microsoft Endpoint Manager.
data:image/s3,"s3://crabby-images/6b52c/6b52cb2395d1ef8721240f7a61fcb71b829a57a9" alt="Intune Filters"
Create AD Group for Windows 10 Devices
The next step is to create a dynamic AAD group for all Windows 10 devices. If you already have a group for Windows 10 devices then you can skip this step.
From Azure Active Directory > Group, create a dynamic group. Use the below query expression to include all Windows 10 devices.
data:image/s3,"s3://crabby-images/92a79/92a799fb26ddd424f83254bf77bfa1555846d101" alt="Dynamic membership rule"
Azure AD Group – Dynamic Rule
(device.deviceOSVersion -startsWith "10.0") -and (device.DeviceOSType -startsWith "Windows") -and (device.managementType -eq "MDM")
Create Filter for Training Devices
In Microsoft Endpoint Manager admin center, Select Devices | Filters (preview) and click on Create.
data:image/s3,"s3://crabby-images/0b867/0b86737d85a24f9cb80eca0795f5d19c4847a155" alt="Create Intune Filter"
Enter Filter Name, Description, and Platform, and then clock on Next. Add the expression to include devices whose Device Category is ‘Training Devices’. Click on Next.
data:image/s3,"s3://crabby-images/916b8/916b817ec2df1d06f67d0e736ec18a8ec6ce6c29" alt="Create intune filter"
Review the details and then click on Create.
data:image/s3,"s3://crabby-images/4f373/4f373988070721f9cbc2dd05025eed8c5aaeab82" alt="Intune filter Review + create"
You can now see the newly created filter in Devices | Filters (preview)
data:image/s3,"s3://crabby-images/ebb89/ebb895bef62ecd54c4632bb8a9c9255f97602980" alt="Devices | Check existing filters"
Deploy Microsoft Whiteboard on Devices using AAD group & Intune Filters
Now we have both AAD group and MEM Filter in place for the granular deployment of applications on Windows 10 devices whose device category is ‘Training Devices’.
To deploy the application, Go to Apps, click on Microsoft Whiteboard, and select Properties. Click on the Edit link under the Assignments section.
data:image/s3,"s3://crabby-images/e30db/e30dbc18c66c10cc1e751ff1eaa3e4743bc7089d" alt="App properties"
In the Edit application page, click on Add group under Required and select Windows 10 devices group. Click on Select.
data:image/s3,"s3://crabby-images/cd5bc/cd5bcf1b0ff0ada440e75d8af75f776df1217ce5" alt="Intune Apps assign group"
Now you can see the Windows 10 Devices group added under Required. The Filter option is now available.
data:image/s3,"s3://crabby-images/db3ed/db3edc98c8c4d2c91fd62db881063ed7ee1f58db" alt="Intune Apps assign group"
Click on the None link below Filter mode.
Select the “Include filtered devices in assignment” radio button.
From available filters, select the filter which you want to use and click on Select.
data:image/s3,"s3://crabby-images/679b9/679b9f6404358ead8d44821c8b220302e36a8930" alt="Intune Apps assign group"
You can now see that Filter mode and Filter is now visible under Required. Filter mode is set to Include and Filter set to ‘Training Devices’.
Click on Review & Save.
data:image/s3,"s3://crabby-images/58fbd/58fbd6d1ae7240b9c37fec2a4733b1b940149905" alt="Intune Apps assign group"
Review the details and click on Save to complete the deployment setup.
data:image/s3,"s3://crabby-images/9ee64/9ee6414742896f9efbf965ba9f72c46b472efd1c" alt="Intune Apps assign group"
Deployment Status & Filters Evaluation
We will now check the deployment on one of our test Windows 10 laptops. The device category has not yet been set on this laptop. Before proceeding further, let’s understand how the include and exclude filters are evaluated. Here is the excerpt from Microsoft documentation.
data:image/s3,"s3://crabby-images/1405f/1405f6fce6d19b94e219c2733b9d9b71baef22c2" alt="Intune Filters | filter mode"
Microsoft Endpoint Manager Filters – Include and Exclude evaluation rule
To check the application deployment status, Go to Apps > Microsoft Whiteboard > Device install status. The following details are shown.
Status: Not applicable
Status Details: Filters criteria are not met
Filters (Preview): Filters evaluated
data:image/s3,"s3://crabby-images/2e40a/2e40a520ab5c10190950e72ef1906bcfad5e5707" alt="Apps"
Application install status
Click on the Filters evaluated link. You can see that the Evaluation result is “Not match” hence the application was not offered to the device. You can also see that the Device Category property was empty hence Filter criteria were not matched.
data:image/s3,"s3://crabby-images/dd2ea/dd2ea6ebdb89a05d7ec0ba3170609d2ba2418063" alt="Filters evaluation status"
We will now set the Device category for this device, force client policy sync, and check the filter evaluation and deployment status again.
To change the Device category, go to Devices > Select Device and select Properties. Update the Device category. We changed this to “Training Devices”.
data:image/s3,"s3://crabby-images/a2ec6/a2ec691461e8ba65c66bb25158704e60a62bf769" alt="Device properties"
Device category
Force sync on Windows 10 devices to quickly update the policy.
Windows Settings > Accounts > Access Work or School > Select Account and then click on Sync.
data:image/s3,"s3://crabby-images/01679/0167998126406ffe783372b5480e97306a6d36e8" alt="School or work account | Device sync status"
Wait for some time for Filter re-evaluation. I have waited for an hour and the application was installed after the filter evaluation succeeded.
data:image/s3,"s3://crabby-images/67a0e/67a0e3dc554782b0fa79fe8b9c0f6107978601b4" alt="Intune filter evaluation"
See the Filter evaluation now. The included criteria were matched and the application was offered to the device.
data:image/s3,"s3://crabby-images/95fa2/95fa26651ca968155eb96fb7eb6690ca8f83b58b" alt="Intune filter evaluation"
Filter evaluation
You can also find the application added in the Start menu on Windows 10 devices.
data:image/s3,"s3://crabby-images/cfe1e/cfe1e726b7051f521bcdde191332202cda9989bb" alt="Windows 10 Start menu"
Related Posts
- Deploy Win32 App Using Intune Enterprise App Catalog
- Understanding Win32 App Detection Rules
- Understanding Win32 App Requirements Rule
- Upgrade / Replace Win32 Apps with Supersedence Relationship
- Win32 App Deployment with Dependencies
- Win32 Apps vs LOB Apps
- Win32 App Deployment failed with error code 0x80070643
- Win32 App Deployment Failed with Error 0x87D1041C
- Win32 App Deployment failed with error 0x87D300C9
- Win32 App failed with error code 0x80070653
- Deploy Google Chrome for Enterprise with Intune Win32 App
- How to Prepare Win32 App Installation source for Microsoft Intune
- SCCM Device Collection Equivalents in Microsoft Intune for App Deployment
- Deploy Microsoft SQL Server Management Studio 19.02 through Intune
- Organizing Laptop and Desktop in Intune Using Filters
Subscribe to Techuisitive Newsletter
Be the first to know about our new blog posts. Get our newsletters directly in your inbox and stay up to date about Modern Desktop Management technologies & news.