Group Management
Security groups are the backbone of every CONFIG365 deployment. They are defined in JSON, deployed idempotently,
and referenced throughout every other configuration via the {{GROUP:name}} placeholder system.
The {{GROUP:name}} Placeholder System
Rather than hardcoding Entra object IDs into every policy (which differ between tenants), CONFIG365 uses a placeholder
system. When the pipeline runs, all {{GROUP:name}} tokens in your JSON configs
are resolved to the correct Entra group ID for that tenant — enabling a truly portable baseline.
{
"displayName": "Require Compliant Device – All Users",
"conditions": {
"users": {
"includeGroups": ["{{GROUP:Baseline – Modern Workplace Users}}"]
}
},
"grantControls": {
"operator": "AND",
"builtInControls": ["compliantDevice"]
}
} Resolution at Deploy Time
- 01 Groups are deployed first, before any dependent resources
- 02 A lookup table of group name → object ID is built
- 03 All JSON configs are scanned for
{{GROUP:...}}tokens - 04 Tokens are replaced with the resolved ID before API calls
Why Not Use IDs Directly?
Group object IDs differ between tenants. Using names means the same baseline JSON file deploys correctly to every tenant without modification.
Deployment Behavior
Running the pipeline multiple times is safe. If a group already exists, CONFIG365 verifies its properties and updates only what has changed.
Groups that exist in the tenant but not in the baseline JSON are not deleted. Only groups explicitly defined in the JSON are managed.
Groups are always deployed before any resource that references them — ensuring placeholder resolution never fails on the first run.
{
"displayName": "Baseline – Modern Workplace Devices",
"description": "All managed endpoints targeted with Intune policies.",
"securityEnabled": true,
"mailEnabled": false,
"membershipRule": "(device.deviceOSType -eq \"Windows\")",
"membershipRuleProcessingState": "On",
"groupTypes": ["DynamicMembership"]
} GUI Configuration Available
Group deploy and update behavior can be configured via the CONFIG365 web interface. The GUI lets you control per-group settings such as whether to allow property updates on existing groups, how to handle membership rule conflicts, and whether to skip groups already present in the tenant — without editing JSON or pipeline parameters directly.
Required Graph Permission
Group deployment requires Group.ReadWrite.All on the service principal. This is included in the standard CONFIG365 app registration.
Baseline Group Reference
Device Groups
Baseline – Modern Workplace Devices Primary Primary device group. All managed endpoints are targeted with Intune policies and applications. Uses dynamic membership to include all devices after onboarding.
Baseline – Devices Bitlocker TPM Excluded For legacy devices without TPM. Pre-boot BitLocker password is used. Avoid adding devices here — replacing non-TPM hardware is preferable.
Baseline – Devices Exclude Credential Provider Disables legacy password sign-in. Should include all devices dynamically so only cloud / web sign-in with MFA is possible.
Baseline – Devices Unenrollment Block Excluded Unenrolling from Entra is blocked by default. Add devices to this group to temporarily allow un-enrollment.
Baseline – Devices VDI Session hosts and virtual machines. Used to exclude AVD and VDI hosts from policies that only apply to physical endpoints.
User Groups
Baseline – Modern Workplace Users Primary Primary user group. All licensed users with a given name and surname are targeted with Conditional Access and user policies.
(user.accountEnabled -eq true) and (user.givenName -ne $null) and (user.surname -ne $null) and (user.displayName -notContains "azavd") Baseline – Users Azure AD Joined Device Local Administrator Users in this group have local admin rights on all managed devices.
Baseline – Users Local Admin Strip Excluded Users who should retain local admin rights and not be stripped.
Baseline – Users DeviceLock 15min / 30min Increases the default 5-minute device lock timeout to 15 or 30 minutes for affected users.
AppLocker Groups
Baseline – Devices Applocker Script Excluded Devices excluded from script execution restrictions.
Baseline – Devices Applocker MSI Excluded Devices excluded from installer (MSI) execution restrictions.
Baseline – Devices Applocker EXE Excluded Devices excluded from EXE execution restrictions.
Baseline – Devices Applocker APPX Excluded Devices excluded from signed MSIX package restrictions.