Intune Assign a Dynamic group as members of local administrators on devices


Hi All

Following Microsofts article it states you can get a group assigned to be a member of local administrators on devices which are in intune. I’d like to be able to assign a Dynamic group to be assigned to local administrators groups on machines.

As per microsoft

<groupmembership> <accessgroup desc = “Group1”> <member name = “S-1-15-6666767-76767676767-666666777″/> <member name = “contosoAlice”/> </accessgroup> <accessgroup desc = “Group2”> <member name = “S-1-15-1233433-23423432423-234234324″/> <member name = “contosoGroup3“/> </accessgroup> </groupmembership>

in my scenario Group3 = [email protected]

I have attempted with object id also, as it is a azure group there is no sid.

However when attempting I’m always receiving remediation failed. Error code 0x87d1fde8

Has anyone had any luck to assign a group within the administrators group of a machine?


ConfigureGroupMembership [./Device/Vendor/MSFT/Policy/Config/RestrictedGroups/ConfigureGroupMembership]

solved 0
M7HRU TV 8 months 2020-08-14T22:26:49+05:30 5 Answers 203 views Beginner 0

Answers ( 5 )


    Hi just want to feedback on this if anyone else faces the issue. Groups is only managed from 2004 onwards.


    No response hence closing the thread


    Thanks but is the request I have mentioned possible? or can you only assign individual users only?


    The best option is to check the event logs and registry to understand more details about errors

    I have explained how to troubleshoot in free intune training videos

Leave an answer

Sorry, you do not have a permission to answer to this question .