- Go to Azure Ad https://portal.azure.com/#view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/Overview
- Groups
- New Group
Make sure the Group Type is Security (if you choose 365 group a Teams, Sharepoint, Distribution group will be created. )
- Under Group name use the following naming convention SG-*Service*-*Description* (for general use leave service blank)
- SG-Ross (General use group for all users in Ross office)
- SG-Intune-WallpaperExemption (Group for users to be exempt from an Intune policy)
- Under Group name use the following naming convention SG-*Service*-*Description* (for general use leave service blank)
- Change Membership type to Dynamic User
- Click Add Dynamic Query
- Fill in the criteria wanted for the group
The first line should always be AccountEnabled Equals True so that no disabled or blocked users are in it
- Once you think your rules are correct click “Validate Rules”
Click Add users then add a couple of users that should be in the group and a couple that should not.
- Once you are happy that it is working as should be click save
- Click create wait for 5-10 mins the check the group has the correct people inside it.