Microsoft Defender for Endpoint
Endpoint protection

Create and manage device groups in Microsoft Defender for Endpoint

In brief

The guidance now specifies that assigned Microsoft Entra groups must already have RBAC roles. It also clarifies matching conditions and notes that configuration changes may take several hours to propagate.

What Defender admins need to know

Configure the required RBAC roles before creating device groups, and allow for propagation delays.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create and manage device groups in Microsoft Defender for Endpoint

Overview

In Microsoft Defender for Endpoint, you can create device groups and use them to:

  • Limit access to related alerts and data to specific Microsoft Entra user groups that have assigned RBAC roles

  • Configure different auto-remediation settings for different sets of devices

  • Assign specific remediation levels to apply during automated investigations

  • In an investigation, filter the Devices list to specific device groups by using the Group filter. As part of the process of creating a device group, you'll:

  • Set the automated remediation level for that group. For more information on remediation levels, see Use Automated investigation to investigate and remediate threats.

  • Specify the matching rule that determines which device group belongsdevices belong to the device group based on the device name, domain, tags, and OS platform. If a device is also matched to other groups, it's added only to the highest ranked device group.

  • Select the Microsoft Entra user group that should have access to the device group.

  • Rank the device group relative to other groups after it's created.

  1. In the Microsoft Defender portal at https://security.microsoft.com, go to Settings > Endpoints > Permissions section > Device groups. Or, to go directly to the device groups tab, use https://security.microsoft.com/securitysettings/endpoints/machine_groups.

  2. On the device groups tab, select Add device group.

    Select Next

  3. On the Devices page, configure the matching rule that determines which devices belong to the group. You can define conditions based on device name, domain, tags, and OS platform. Devices that match all specified conditions are added to the group. For instructions,information about how matching rules and automated investigations work together, see How the automated investigation starts.

Select Next.

  1. On the Preview devices page, select Show preview to show up to 10 devices that match the device rule you configured on the previous page. If you're satisfied with the results,previewed devices, select Next.

  2. On the User access page, assign the user groups that can access the device group you created.

Devices that aren't matched to any groups are added to Ungrouped devices (default) group. You cannot change the rank of this group or delete it. However, you can change the remediation level of this group, and define the Microsoft Entra user groups that can access this group.

Add device group definitions