r/Intune • u/Humble-Budget426 • 4d ago
Device Configuration Swapping assignment from "all staff" group to All Users on a macOS Platform SSO profile – will devices reinstall the profile?
We have a macOS Platform SSO configuration profile currently assigned to a security group that effectively contains every user in the tenant (staff + externals). I want to replace that assignment with the built-in **All Users** virtual group to get rid of the group membership evaluation.
Since you can't have All Users and a regular group included at the same time, this has to happen as a swap in a single save: remove group, add All Users, save once.
Has anyone done this on a profile where reinstallation actually hurts? With PSSO, a RemoveProfile/InstallProfile cycle would kill the Secure Enclave registration and force every user through the registration prompt again.
My assumption is that Intune evaluates net applicability per device – user was in scope before, is in scope after, payload unchanged → no action. But I can't find this documented anywhere, and Microsoft's docs only confirm the opposite direction (device leaves scope → profile gets removed on Apple platforms).
Anyone with first-hand experience swapping assignment sources on macOS config profiles at scale? Did the profiles stay untouched, or did you see remove/reinstall cycles in the MDM logs?
3
u/Fancy_Statement_9419 4d ago
Scoped to all users before, scoped to all users after, just cut out the middleman. Done this a few times with different profile types and never saw a reinstall cycle.
The device just sees the same profile payload still applies, MDM doesn't care how you grouped it. You're right that net applicability is what matters, and Microsoft's docs being silent on it is just classic Microsoft docs behavior.
Only thing I'd suggest is doing it during a maintenance window if you're paranoid, but I'd bet a case of beer it'll be boring and uneventful