Back

Device groups

Device groups organise devices so you can apply different MDM controls. Devices join or leave groups automatically based on defined filters.

Overview

Use device groups whenever a setting should apply to some devices but not all. Because the membership is driven by filters rather than a manual list, a device that changes team or office moves between groups on its own — nobody has to maintain the membership.


 

How to use

Create a group:

  1. Go to MDM > Device Groups.
  2. Click New group.
  3. Name the group, and add a description if it helps others understand the intent.
  4. Configure the filters that decide which devices belong.
  5. Click Save.

Assign a profile to the group:

  1. Open the device group.
  2. Go to the Profile tab.
  3. Select the MDM profile to apply.
  4. Save.

Devices in the group receive the controls within a few minutes.


 

What you can filter on

  • Team
  • Office
  • Legal entity
  • Tags
  • Assignee
  • Email provider groups — the groups synced from your email provider, such as a Google Workspace group

Filters combine, so you can target precisely. The same filters are available in an MDM control's custom target, which means you can choose between a reusable group and a one-off target.

Filtering on email provider groups requires Google Workspace or Microsoft Entra ID to be connected as your email provider.


 

Tips and Best Practices

  • Name groups after the rule, not the moment. "Engineering macOS" survives a reorganisation; "New laptops March" does not.
  • Filter on team or office rather than tags where you can. Those come from your HR system and stay current on their own; tags need somebody to maintain them.
  • Use a group when the target will be reused, and a control's custom target when it will not. A group that exists for one control is overhead.
  • Check group membership after connecting your email provider, since email provider groups only become available once it is connected.
 

 

Troubleshooting and FAQ

Troubleshooting

  • A device is not in the group I expected. Check the attribute the filter uses on that specific device. Team, office and legal entity come from your HR system, so a device attached to an employee with stale HR data will not match.
  • Email provider groups do not appear as a filter option. Google Workspace or Microsoft Entra ID is not connected as your email provider. Connect it first.
  • The profile has not applied. Allow a few minutes — devices receive controls on their next check-in, not instantly.

FAQ

  1. Do I have to add devices to a group by hand?
    No. Groups are dynamic: the filters decide membership and it updates automatically.
     
  2. Can a device be in more than one group?
    Yes, if it matches the filters of each one.
     
  3. What is the difference between a group and a control's custom target?
    They use the same filters. A group is reusable across controls; a custom target belongs to one control.

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice