Baseline

Group Management

Security groups are the backbone of every CONFIG365 deployment. They are defined in JSON, deployed idempotently, and referenced throughout every other configuration via the {{GROUP:name}} placeholder system.

Security GroupsDynamic MembershipPlaceholdersIntune TargetingConditional Access

The {{GROUP:name}} Placeholder System

Rather than hardcoding Entra object IDs into every policy (which differ between tenants), CONFIG365 uses a placeholder system. When the pipeline runs, all {{GROUP:name}} tokens in your JSON configs are resolved to the correct Entra group ID for that tenant — enabling a truly portable baseline.

In a Conditional Access policy JSON
{
  "displayName": "Require Compliant Device – All Users",
  "conditions": {
    "users": {
      "includeGroups": ["{{GROUP:Baseline – Modern Workplace Users}}"]
    }
  },
  "grantControls": {
    "operator": "AND",
    "builtInControls": ["compliantDevice"]
  }
}

Resolution at Deploy Time

  1. 01 Groups are deployed first, before any dependent resources
  2. 02 A lookup table of group name → object ID is built
  3. 03 All JSON configs are scanned for {{GROUP:...}} tokens
  4. 04 Tokens are replaced with the resolved ID before API calls

Why Not Use IDs Directly?

Group object IDs differ between tenants. Using names means the same baseline JSON file deploys correctly to every tenant without modification.

Deployment Behavior

Idempotent

Running the pipeline multiple times is safe. If a group already exists, CONFIG365 verifies its properties and updates only what has changed.

Non-Destructive

Groups that exist in the tenant but not in the baseline JSON are not deleted. Only groups explicitly defined in the JSON are managed.

Order-Aware

Groups are always deployed before any resource that references them — ensuring placeholder resolution never fails on the first run.

Group JSON Structure
{
  "displayName": "Baseline – Modern Workplace Devices",
  "description": "All managed endpoints targeted with Intune policies.",
  "securityEnabled": true,
  "mailEnabled": false,
  "membershipRule": "(device.deviceOSType -eq \"Windows\")",
  "membershipRuleProcessingState": "On",
  "groupTypes": ["DynamicMembership"]
}

GUI Configuration Available

Group deploy and update behavior can be configured via the CONFIG365 web interface. The GUI lets you control per-group settings such as whether to allow property updates on existing groups, how to handle membership rule conflicts, and whether to skip groups already present in the tenant — without editing JSON or pipeline parameters directly.

Required Graph Permission

Group deployment requires Group.ReadWrite.All on the service principal. This is included in the standard CONFIG365 app registration.

Baseline Group Reference

Device Groups

Baseline – Modern Workplace Devices Primary

Primary device group. All managed endpoints are targeted with Intune policies and applications. Uses dynamic membership to include all devices after onboarding.

Baseline – Devices Bitlocker TPM Excluded

For legacy devices without TPM. Pre-boot BitLocker password is used. Avoid adding devices here — replacing non-TPM hardware is preferable.

Baseline – Devices Exclude Credential Provider

Disables legacy password sign-in. Should include all devices dynamically so only cloud / web sign-in with MFA is possible.

Baseline – Devices Unenrollment Block Excluded

Unenrolling from Entra is blocked by default. Add devices to this group to temporarily allow un-enrollment.

Baseline – Devices VDI

Session hosts and virtual machines. Used to exclude AVD and VDI hosts from policies that only apply to physical endpoints.

User Groups

Baseline – Modern Workplace Users Primary

Primary user group. All licensed users with a given name and surname are targeted with Conditional Access and user policies.

Dynamic Rule
(user.accountEnabled -eq true) and (user.givenName -ne $null) and (user.surname -ne $null) and (user.displayName -notContains "azavd")
Baseline – Users Azure AD Joined Device Local Administrator

Users in this group have local admin rights on all managed devices.

Baseline – Users Local Admin Strip Excluded

Users who should retain local admin rights and not be stripped.

Baseline – Users DeviceLock 15min / 30min

Increases the default 5-minute device lock timeout to 15 or 30 minutes for affected users.

AppLocker Groups

Baseline – Devices Applocker Script Excluded

Devices excluded from script execution restrictions.

Baseline – Devices Applocker MSI Excluded

Devices excluded from installer (MSI) execution restrictions.

Baseline – Devices Applocker EXE Excluded

Devices excluded from EXE execution restrictions.

Baseline – Devices Applocker APPX Excluded

Devices excluded from signed MSIX package restrictions.