Scope Groups and Naming Conventions
Audience: Platform Engineering, distributed unit administrators
Purpose: Standardize scope group naming for consistent policy management
Quick Reference
| Group Type | Prefix | Purpose |
|---|---|---|
| Device Scope Group | DSG | Device object collections |
| User Scope Group | USG | User account groupings |
| Experience Scope Group | ESG | Combined policy bundles |
| Policy Scope Group | PSG | Policy/app assignments |
| Role Scope Group | RSG | PIM role access |
| File Scope Group | FSG | File permissions |
| Cloud Scope Group | CSG | Cloud resource access |
Prerequisites: Administrative Units
All scope groups (Entra security groups) must be created within the respective unit's designated Administrative Unit.
| Requirement | Details |
|---|---|
| AU Naming | AU-[FAMIS CODE] (e.g., AU-VPOP, AU-CLED) |
| Required Role | Groups Administrator role for the specific AU |
| Elevation | Often requires PIM elevation for the AU-scoped role |
This ensures scope group management is controlled by authorized personnel within each unit while maintaining a unified system.
Scope Group Types
Device Scope Group (DSG)
Purpose: Manages all devices enrolled in Intune specific to a unit.
| Attribute | Description |
|---|---|
| Members | Device objects (e.g., Windows desktops, Android devices) |
| Use Case | Direct device targeting; commonly nested into ESGs |
| Example | DSG - CLED - Faculty Laptops |
User Scope Group (USG)
Purpose: Organizes user accounts by roles or departments within a unit.
| Attribute | Description |
|---|---|
| Members | User and service accounts |
| Use Case | Role-based access; nested into ESGs for policy targeting |
| Example | USG - CLED - Faculty Users |
Experience Scope Group (ESG)
Purpose: Defines a user or device "experience" by grouping USGs and/or DSGs from the same unit.
| Attribute | Description |
|---|---|
| Members | One or more USGs and/or DSGs from the same FAMIS code |
| Use Case | Simplified assignment of consistent policy bundles |
| Example | ESG - CLED - Faculty Standard Experience |
ESGs act as the target for policy collections delivered via PSGs. Instead of adding many USGs/DSGs to many PSGs, add them to one ESG, then add that ESG to multiple PSGs.
Policy Scope Group (PSG)
Purpose: Manages specific policy and application assignments within Intune.
| Attribute | Description |
|---|---|
| Members | Experience Scope Groups (ESGs) |
| Use Case | Controls deployment of individual policies and applications |
| Example | PSG - Required - User - CLED - Microsoft Office 365 |
PSG Naming Format
PSG - [Assignment Type] - [Target] - [FAMIS Code] - [Policy/App Name]
For Applications:
PSG - Required - User - [FAMIS] - [App Name]PSG - Required - Device - [FAMIS] - [App Name]PSG - Available - User - [FAMIS] - [App Name]PSG - Available - Device - [FAMIS] - [App Name]PSG - Uninstall - User - [FAMIS] - [App Name]PSG - Uninstall - Device - [FAMIS] - [App Name]
For Policies:
PSG - Included - User - [FAMIS] - [Policy Name]PSG - Included - Device - [FAMIS] - [Policy Name]PSG - Excluded - User - [FAMIS] - [Policy Name]PSG - Excluded - Device - [FAMIS] - [Policy Name]
Shared Device Exclusion Filter
All User PSGs must have an Exclude filter to prevent user-assigned policies from deploying to shared devices.
| Filter | Details |
|---|---|
| Filter Name | Shared Device - Filter |
| Rule Syntax | (device.enrollmentProfileName -ne "_TAMU User Driven with Pre Provision") |
Role Scope Group (RSG)
Purpose: Provides custom role-based access, often linked to PIM for temporary elevation.
| Attribute | Description |
|---|---|
| Members | Specific users or USGs requiring elevated access |
| Use Case | Permissions for sensitive or administrative roles |
| Example | RSG - CLED - BitLocker Recovery |
File Scope Group (FSG)
Purpose: Manages file permissions for cloud-based storage like SharePoint.
| Attribute | Description |
|---|---|
| Members | User accounts or roles needing file/folder access |
| Use Case | Fine-grained access control for SharePoint content |
| Example | FSG - CLED - HR Documents - Edit |
Cloud Scope Group (CSG)
Purpose: Grants access to cloud-based resources (SharePoint sites, Loop, Planner).
| Attribute | Description |
|---|---|
| Members | User accounts needing specific cloud resource access |
| Naming | CSG - [FAMIS Code] - [Site Name] - [Access Level] |
| Description Field | Include full URL of the resource |
Examples:
CSG - VPOP - Research Hub - EditCSG - CLED - Marketing Planner - OwnerCSG - ENGR - Project Loop Site - Contributor
For hub sites, include "Hub" in the name: CSG - VPOP - Research Hub - Read
Implementation Example
Consider the "College of Education Faculty" (FAMIS Code: CLED):
1. Foundation Groups
USG - CLED - Faculty Users (all faculty user accounts)
DSG - CLED - Faculty Laptops (all faculty-assigned laptops)
2. Experience Group
ESG - CLED - Standard Faculty Experience
├── USG - CLED - Faculty Users
└── DSG - CLED - Faculty Laptops
3. Policy Groups Targeting the ESG
| Assignment Type | Target | Group Name | Members | Filter Mode |
|---|---|---|---|---|
| Required | User | PSG - Required - User - CLED - Microsoft Office 365 | ESG | Exclude |
| Included | User | PSG - Included - User - CLED - OneDrive Compliance | ESG | Exclude |
| Available | User | PSG - Available - User - CLED - Adobe Acrobat Pro | ESG | Exclude |
| Included | Device | PSG - Included - Device - CLED - Laptop Config | ESG | None |
Workflow Benefits
- Add new faculty member → Add to
USG - CLED - Faculty Users - They automatically receive → All policies/apps via ESG membership
- Change experience → Adjust ESG membership in PSGs
- Onboarding is simple → Single group membership grants full experience
Standard Naming Format
PSG Format
PSG - [Assignment Type] - [Target] - [FAMIS Code] - [Policy/App Name]
| Element | Description |
|---|---|
| PSG | Identifies as Policy Scope Group |
| Assignment Type | Required, Available, Uninstall (apps) or Included, Excluded (policies) |
| Target | User or Device |
| FAMIS Code | Department code (e.g., CLED, VPOP) |
| Name | Policy or application name |
Other Scope Groups Format
[Scope Group Type] - [FAMIS Code] - [Descriptive Name]
| Element | Description |
|---|---|
| Scope Group Type | DSG, USG, ESG, FSG, RSG, CSG |
| FAMIS Code | Department tracking code |
| Descriptive Name | Clear description of purpose or members |
Related Resources
- Endpoint Custom Roles — RBAC role definitions
- Deployment Profiles & ESP — Autopilot configuration
- Entra ID PIM Guide — Role elevation procedures
- Administrative Units — Microsoft documentation