+The All users and All devices are Intune virtual groups and not AAD security groups. As a result, for Scope group assignment purposes you cannot use them as parents of AAD security groups. If you need both All users/All devices and specific AAD security groups for scope group assignments, you must add them separately with separate assignments. Otherwise, even if you have All users for the role's scope group assignment the admin in this role won't have access to specific AAD user groups. For AAD security groups, nesting is supported.
0 commit comments