Manage Dynamic Assignments

Applies to: Patch My PC Publisher Available at level: All Custom Products, All Products Available on tab: Intune Updates

Overview

Manage Dynamic Assignments allows you to automatically create Intune assignments for newly published updates based on predefined catalog criteria.

Manage Dynamic Assignments

Instead of assigning every update to the same Entra groups, Dynamic Assignments evaluates each update during a Publisher synchronization and applies assignments only when the update matches your configured rules. This enables targeted deployment based on update attributes rather than static grouping.

circle-info

Note

Dynamic Assignments are conceptually similar to Automatic Deployment Rules in ConfigMgr, but they apply to Intune Updates managed by the Publisher.

How Dynamic Assignments Work

During each sync, the Publisher evaluates newly published Intune Updates against your configured criteria. Criteria can include attributes such as the presence of a CVE, CVE severity, keywords in the update title, or the update classification.

If an update meets the defined conditions, the Publisher automatically creates assignments for the Entra groups you specify. If an update does not meet the criteria, no assignment is created.

This approach allows different updates to follow different deployment paths based on risk, urgency, or relevance, without requiring manual assignment for each update.

circle-exclamation

Evaluation Criteria

Dynamic Assignments evaluate newly published updates using one or more of the following criteria.

  • Has CVE A Boolean value that evaluates whether the update has one or more CVE IDs associated with it.

  • Severity A multi select list that includes Critical, Important, Moderate, and Low. Title Plain text or regular expression strings used to match update titles. Exclusions can be defined by prefixing a value with a minus sign.

  • Update Classification A multi select list that includes Updates, Critical Updates, and Security Updates.

circle-info

Note

Criteria options that allow multiple values use an OR operator. All different criteria types are joined together using an AND operator.

In practical terms, this means an update must meet all selected criteria types, but only one value within each type.

circle-exclamation

Configure Dynamic Assignments

To configure Dynamic Assignments, follow the steps below.

  1. Open the Intune Updates tab in the Publisher.

  2. Right click All Products or All Custom Products and select Manage Dynamic Assignments.

  3. Select Add to create a new Dynamic Assignment rule.

New Dynamic Assignment Rule
  1. Enter a Name and optional Description for the rule.

  2. Select one or more Property Filters to define the evaluation criteria.

  3. Configure the search criteria values for each selected filter.

New Dynamic Assignment Rule Settings
  1. Click Preview to see which updates currently match the rule.

Preview Updates
  1. Click Manage to configure assignments for the rule.

  2. Add the required Intune assignments using the standard Manage Assignments window.

Manage Assignments
  1. Click OK to save the rule.

Rule Configuration Complete

Last updated

Was this helpful?