Intune Scope Tags
Posted by Nervous-Equivalent@reddit | sysadmin | View on Reddit | 4 comments
For some reason I'm struggling to get my head around Intune scopes. I've been Intune admin for quite a while with a large Intune environment, but now I've been tasked with enrolling a large number of devices from another site which another team will manage. Is this correct:
- I will create two scopes, Scope A and Scope B.
- I will create a dynamic group that contains all of my devices (Scope A), and a dynamic group that contains all of their devices (Scope B).
- My admin role will have the Scope (Groups) set to the Scope A dynamic group, the role for the other team will be set for Scope B dynamic group.
If they were to create a config profile with Scope B tag and accidentally assigned it to "All Devices" (or another group that contained some of my Scope A devices), would my Scope A devices still get the profile?
I spoke to Intune support about this and it sounded like Scope B admins could still impact my Scope A devices.
7ep3s@reddit
Scope tags don't have anything to do with assignments.
If you want to implement segregation you should remove the ability of the different admin teams to interact with All Devices and All Users, so there cannot be such accidents.
satchentaters696@reddit
Scope tag is for filtering and control. Group b can edit and assign scope b items to anything they have access to assign i.e. if they can assign to all devices then it can, they just cant touch group a scoped items. Create a dynamic Entra group for there machines so they can only touch that group and put change management policies in place that go before you and other stakeholders to approve before deployment.
Goodabye@reddit
Not even sure if scopes cover this. It might be simpler to create a new 365 tenant, link both, and limit their access to the new one—while you keep control of both. That is if the devices don't use the same domain.
TheMangyMoose82@reddit
Scope tags are just for controlling visibility and access for admin roles and not for managing how things apply, is my understanding.