# Capture the actual Zebra LifeGuard deployment population at creation

> Will later changes to an Intune group alter an already-created Zebra LifeGuard deployment?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-112-capture-the-actual-zebra-lifeguard-deployment-population-at-creation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:04+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Will later changes to an Intune group alter an already-created Zebra LifeGuard deployment?

## Potentially affected

Use this check when scheduling or auditing an Intune-integrated Zebra LG OTA deployment. Confirm service enrollment and device eligibility before treating current group membership as the target list.

## DSE recommendation

Retain the eligible device population at creation alongside the deployment identifier.

## Article

## Source facts

Intune sends eligible Zebra devices to LifeGuard OTA when the deployment is created. Devices added to the assigned group afterward are not included. Removing a device from the group afterward may not prevent its update. These deployments cannot be edited after creation. A deployment for later additions must be created separately. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/android/setup-zebra-lifeguard).

## Applicability

Use this check when scheduling or auditing an Intune-integrated Zebra LG OTA deployment. Confirm service enrollment and device eligibility before treating current group membership as the target list.

## DSE recommendation

Retain the eligible device population at creation alongside the deployment identifier. Plan a separate reconciliation for devices enrolled later, and handle removal requests as a deployment-control issue rather than a group-edit shortcut. Have the operations owner approve the captured population before a future-dated deployment is submitted.

## Verification

Compare the submitted population, present group members, and device-level deployment results. In an authorized pilot, distinguish a later-added device from one included at creation, without relying on a production firmware downgrade for testing. Resolve any removal request against the actual deployment state. Preserve device identifiers and observed firmware outcomes so a later auditor can explain why current membership differs from the machines processed.

## Official references

[Microsoft Learn: Zebra LifeGuard Over-the-Air Integration with Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-updates/android/setup-zebra-lifeguard).

## Primary reference

- Name: Zebra LifeGuard Over-the-Air Integration with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-updates/android/setup-zebra-lifeguard
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Capture the actual Zebra LifeGuard deployment population at creation,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-112-capture-the-actual-zebra-lifeguard-deployment-population-at-creation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
