# Check cross-service consumers before replacing an Intune targeting group

> Can a dynamic group safely become an Intune assignment filter?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-568-check-cross-service-consumers-before-replacing-an-intune-targeting-group/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:28+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can a dynamic group safely become an Intune assignment filter?

## Potentially affected

Consider this simplification only for a group used solely for Intune targeting. Confirm that the particular policy or app supports filters; Microsoft explicitly excludes unsupported workloads from this approach.

## DSE recommendation

List every consumer of the current group before proposing its removal.

## Article

## Source facts

Intune assignment filters refine a group assignment using device properties at check-in. Other services such as Conditional Access and SharePoint require Entra group membership and cannot consume those filters. Autopilot profile assignment also requires groups. Microsoft warns that a misconfigured or deleted filter on a broad assignment can affect every device in its scope. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/choose-targeting-method).

## Applicability

Consider this simplification only for a group used solely for Intune targeting. Confirm that the particular policy or app supports filters; Microsoft explicitly excludes unsupported workloads from this approach.

## DSE recommendation

List every consumer of the current group before proposing its removal. Separate its organizational identity role from the device-property condition needed by Intune. Translate the condition against the supported filter property names and values rather than copying a dynamic-membership expression literally. Preserve the original assignment until the proposed audience has been reviewed and a bounded pilot accepted.

## Verification

Compare expected included and excluded devices with actual assignment results in the pilot. Test an endpoint whose relevant property differs and confirm that it remains outside the intended payload. Ask each cross-service owner to confirm whether they still require the original group. Expand only with a documented audience comparison and an approved reversal plan. Do not delete a shared group merely because an Intune policy appears to work without it.

## Official references

[Microsoft Learn: Choose the right targeting method in Microsoft Intune](https://learn.microsoft.com/en-us/intune/fundamentals/choose-targeting-method).

## Primary reference

- Name: Choose the right targeting method in Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/fundamentals/choose-targeting-method
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check cross-service consumers before replacing an Intune targeting group,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-568-check-cross-service-consumers-before-replacing-an-intune-targeting-group/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
