We’re updating our Microsoft Entra Conditional Access integration in Hexnode after the Microsoft API change around the “All users” sync scope. We created a dynamic Entra security group with this rule: “user.objectId -ne null”
The goal is to keep the same coverage as the previous “All users and groups” scope, but avoid any sync issues caused by the Microsoft API limitation.
Before saving the change, I want to confirm a few things:
- Does this dynamic group actually replicate the existing All Users scope?
- Does saving the group Object ID make any changes to Intune Partner Compliance Management or macOS onboarding?