Overview
Use device groups whenever a setting should apply to some devices but not all. Because the membership is driven by filters rather than a manual list, a device that changes team or office moves between groups on its own — nobody has to maintain the membership.
How to use
Create a group:
- Go to MDM > Device Groups.
- Click New group.
- Name the group, and add a description if it helps others understand the intent.
- Configure the filters that decide which devices belong.
- Click Save.
Assign a profile to the group:
- Open the device group.
- Go to the Profile tab.
- Select the MDM profile to apply.
- Save.
Devices in the group receive the controls within a few minutes.
What you can filter on
- Team
- Office
- Legal entity
- Tags
- Assignee
- Email provider groups — the groups synced from your email provider, such as a Google Workspace group
Filters combine, so you can target precisely. The same filters are available in an MDM control's custom target, which means you can choose between a reusable group and a one-off target.
Filtering on email provider groups requires Google Workspace or Microsoft Entra ID to be connected as your email provider.
Tips and Best Practices
- Name groups after the rule, not the moment. "Engineering macOS" survives a reorganisation; "New laptops March" does not.
- Filter on team or office rather than tags where you can. Those come from your HR system and stay current on their own; tags need somebody to maintain them.
- Use a group when the target will be reused, and a control's custom target when it will not. A group that exists for one control is overhead.
- Check group membership after connecting your email provider, since email provider groups only become available once it is connected.
Troubleshooting and FAQ
Troubleshooting
- A device is not in the group I expected. Check the attribute the filter uses on that specific device. Team, office and legal entity come from your HR system, so a device attached to an employee with stale HR data will not match.
- Email provider groups do not appear as a filter option. Google Workspace or Microsoft Entra ID is not connected as your email provider. Connect it first.
- The profile has not applied. Allow a few minutes — devices receive controls on their next check-in, not instantly.
FAQ
-
Do I have to add devices to a group by hand?
No. Groups are dynamic: the filters decide membership and it updates automatically.
-
Can a device be in more than one group?
Yes, if it matches the filters of each one.
-
What is the difference between a group and a control's custom target?
They use the same filters. A group is reusable across controls; a custom target belongs to one control.