Reconfiguring Microsoft Entra Conditional Access in Hexnode with a dynamic groupSolved

Participant
Discussion
3 weeks ago Sep 16, 2026

We’re updating our Microsoft Entra Conditional Access integration in Hexnode after the Microsoft API change around the “All users” sync scope. We created a dynamic Entra security group with this rule: “user.objectId -ne null”

The goal is to keep the same coverage as the previous “All users and groups” scope, but avoid any sync issues caused by the Microsoft API limitation.

Before saving the change, I want to confirm a few things:

  1. Does this dynamic group actually replicate the existing All Users scope?
  2. Does saving the group Object ID make any changes to Intune Partner Compliance Management or macOS onboarding?

Replies (7)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 16, 2026
Marked SolutionPending Review

Hello @marien ,

The dynamic group rule “user.objectId -ne null” is intended to include all user objects in Microsoft Entra ID. It functions as an equivalent replacement for the previous “All users” sync scope in this workflow.

This change is highly recommended because Microsoft has deprecated the legacy workflow that relied directly on the “All users” scope. While existing configurations may continue to work temporarily, future syncs could fail depending on Microsoft-side API behavior, so it is best to complete this reconfiguration as soon as possible.

When you save the dynamic group in Hexnode UEM, it only updates the sync target used by the Microsoft Entra Conditional Access integration. This action does not separately onboard the tenant under Intune Partner Compliance Management, nor does it assign the supplied group specifically to macOS.

As long as your selected dynamic group contains the users that should remain in scope, no interruption is expected for existing compliance reporting, device registration, user access, or enrollment.

Regards,
Simon Scott
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Sep 16, 2026
Marked SolutionPending Review

I ran into a UI difference here too. The instructions I had mentioned “Verify & Continue,” but in my portal the Conditional Access page shows the configured domain, platform options, a Next button, and then Sync Target. I wasn’t sure if macOS had to be selected before adding the group. Also should any filters be added for this workaround?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 16, 2026
Marked SolutionPending Review

In the current portal workflow, you can complete the reconfiguration using these steps:

  1. Navigate to Admin > Microsoft Entra ID.

  2. Click on your configured domain name and go to the Conditional Access page.

  3. Click Next. You do not need to select macOS specifically for this step; you can proceed with any OS selected.

  4. On the Sync Target screen, change the scope from All users and groups to Selected groups.

  5. Click Add groups.

  6. Enter the group Object ID of your dynamic Microsoft Entra security group.

  7. Click Add, review the configuration, and click Save.

No filters are required for this workaround. The Filters section can be left empty unless you have a separate, specific requirement to narrow the sync scope.

Marked SolutionPending Review
Participant
3 weeks ago Sep 17, 2026
Marked SolutionPending Review

When I clicked Save after switching to Selected groups, Hexnode showed a “Users from unselected groups will be deleted” prompt with options to “Disenroll device(s)” or “Assign to a new user.” The selected dynamic group appeared to contain the same valid users already synced in Hexnode. Does this prompt mean devices will actually be removed?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 17, 2026
Marked SolutionPending Review

The “Users from unselected groups will be deleted” prompt appears whenever the sync scope is changed, as Hexnode UEM detects that users outside the newly selected scope may need to be removed from the directory sync.

If a removed directory user is currently assigned to an enrolled device, the option you select determines what happens to that device:

  • Disenroll device(s): Devices assigned to the removed users will be disenrolled.

  • Assign to a new user: Devices can be reassigned to a different user instead of being disenrolled.

For a cautious approach, we recommend selecting Assign to a new user to prevent any accidental device disenrollments.

Before saving, you can safely review any potentially affected users and devices:

  1. Go to Manage > Directory Services. Select the Microsoft Entra domain and review the synced users and total devices.

  2. Go to Manage > Users.

  3. Set the Enrollment Status filter to Enrolled and select your relevant Domain. This displays all domain users currently associated with enrolled devices.

  4. For any device you want to keep under a local or default owner, click the user, go to Devices, select the device, and use Actions > Edit > Change Owner to assign it to the appropriate local/default user.

Devices that are already assigned to a local or default user will not be affected by the directory user removal prompt.

If you ever need to roll back this change, switching the sync target back from Selected groups to All users and groups is the expected rollback path. However, because the legacy Microsoft workflow is deprecated, the dynamic group configuration is the recommended setup for long-term.

Marked SolutionPending Review
Participant
3 weeks ago Sep 17, 2026
Marked SolutionPending Review

After adding the group, Microsoft Entra showed more members in the dynamic group than Hexnode showed for the same group. Hexnode’s count did match the users already visible under Directory Services, though. Is that difference normal, or should the two counts be identical before saving?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 17, 2026
Marked SolutionPending Review

A difference between the Microsoft Entra group member count and the Hexnode synced user count is completely normal.

Hexnode applies validation checks while syncing users from directory services. Accounts that cannot be assigned or managed in the Hexnode UEM portal are automatically excluded from the Hexnode count. Common examples include:

  • Guest or B2B users

  • Disabled users

  • Entries missing a valid email address

  • Entries missing a valid UPN

If the dynamic group in Microsoft Entra includes these types of accounts, Entra will naturally show a higher total. Once the configuration is saved, Hexnode will successfully sync and process the valid members from the selected group.

Save