Skip to main content

πŸ›‘οΈπŸͺŸπŸ’»β›“️Group - Devices - Virtual Machines

πŸ“„ What this group is about​

This dynamic group contains all Windows virtual machines in the tenant.
It’s used to separate VMs from physical devices so they don’t accidentally receive the same deployment profiles or policies that are meant for physical hardware.


πŸ› οΈ Configuration Table​

SettingValueAdditional Info
NameπŸ›‘οΈπŸͺŸπŸ’»β›“️Group - Devices - Virtual Machines
DescriptionAll Windows devices where the model indicates it’s a virtual machineHelps scope policies away from VMs when needed
Membership typeDynamicDevices are automatically added based on model
Dynamic rule syntax(see below)Matches all devices with β€œVirtual Machine” in their model
(device.deviceModel -contains "Virtual Machine")

πŸ’¬ Why this matters​

Virtual machines often require different management:

  • Testing environments
  • Lab or sandbox systems
  • Windows 365 Cloud PCs
  • AVD session hosts

By keeping them in a dedicated group, you can:

  • Prevent Autopilot deployment profiles from applying incorrectly
  • Assign separate baselines and security policies
  • Avoid clutter in reporting for physical hardware