An enrolment policy setting that puts devices into a static Microsoft Entra security group as they enrol, not later on, so their apps and policies are there at first check-in. The Intune Provisioning Client service principal owns the group.
Also called enrolment time grouping.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Enrollment time grouping in context, with comparison tables and the common traps.
Terms in this definition
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Security group
Kind of Entra group used to grant resource access. Its members, added by assignment or by dynamic rules, may be users, devices or service principals.
- FIRST
A DAX function available only inside visual calculations. It fetches the value at the start of one axis of the visual's matrix, which makes it handy for comparing each point with the first; its opposite is LAST.
- Intune Provisioning Client
A Microsoft service principal, application ID f1346770-5b25-470b-88bd-d5744ab7952c and at times shown as Intune Autopilot ConfidentialClient, that has to be an owner of the device group used by Autopilot device preparation and enrolment time grouping.
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
Related terms
- Windows Autopilot device preparation
With this newer Autopilot approach, selected apps and scripts install during OOBE. It is targeted at user groups, and enrollment time grouping places each PC in a static group that the Intune Provisioning Client owns.