Setting up and managing device configurations using Intune
For Intune wired 802.1x profiles, assignment can be to either user groups or device groups. The choice depends on whether the wired configuration is user‑scoped or device‑scoped, but both are supported:
- Create the wired network profile for Windows 10 and later using the Wired network template.
- In Assignments, select either Microsoft Entra user groups or device groups that should receive the profile. Intune will deliver the policy when those devices next check in.
- Intune recommends piloting to a small group first and being aware that some settings are user‑scope and some device‑scope. Behavior when a policy is removed or changed is controlled by the underlying CSP; if a different value is needed, create a new policy and assign it accordingly.
If a user‑assigned policy has not applied after a long time, verify:
- The profile is listed under Devices > Configuration and shows the group in Assignments.
- The targeted users sign in on Intune‑enrolled Windows devices and those devices have checked in with Intune.
- For certificate‑based EAP (such as EAP‑TLS), the wired profile, certificate profile, and trusted root profile are all assigned to the same groups so the device can build the certificate chain.
If necessary, switch to assigning the profile to a device group to ensure the configuration is applied at device scope and then test with a small pilot group.
References: