Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Windows 11 25H2 does not require a special Entra group type. To identify these devices, create either a dynamic Microsoft Entra security group that evaluates the device’s reported operating-system build, an assigned group for a manually controlled pilot, or an Intune assignment filter when the targeting is only for Intune.
Before creating the rule, verify the 25H2 build reported by your devices. Microsoft Entra evaluates attributes such as device.deviceOSVersion, not the marketing label “25H2.” Do not insert an unverified build number into a production rule.
Choose the right targeting method
| Requirement | Best choice |
|---|---|
| A small, curated one-time pilot | Assigned security group |
| Automatic membership reusable across Microsoft services | Dynamic Entra device group |
| Intune-only targeting by OS version | Broad group or All devices plus an Intune assignment filter |
| Conditional Access, licensing, or other group-based access | Entra security group |
| Autopilot or pre-provisioning targeting | Autopilot attributes or a dedicated Autopilot group |
| Targeting at Intune check-in with minimal membership delay | Intune assignment filter |
Dynamic groups are reusable across workloads, but their membership is calculated asynchronously. Microsoft recommends considering assignment filters for simple Intune targeting because filters are evaluated at device check-in. See Microsoft’s targeting guidance and filter performance recommendations.
Prerequisites
- A Microsoft Entra tenant and permission to create security groups and dynamic membership rules.
- Device objects registered as Microsoft Entra joined, Microsoft Entra hybrid joined, or Microsoft Entra registered.
- Intune enrollment if the group will target Intune apps, policies, profiles, compliance, security, or Windows Update workloads.
- A verified OS build from actual device records.
- Appropriate licensing for the workload. Creating a device group does not automatically provide Intune management or Conditional Access entitlement.
Microsoft documents the device trust values as AzureAD for Microsoft Entra joined, ServerAD for hybrid joined, and Workplace for registered devices. Dynamic device-group syntax and supported attributes are documented in Microsoft’s dynamic membership rules reference.
#1 Best Overall
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
Verify the Windows 11 25H2 build
Do not identify 25H2 from the computer name, device ownership, or existing group membership. On a device, open Settings > System > About and inspect the Windows specifications, or run:
winver
For a command-line check:
Get-ComputerInfo | Select-Object WindowsProductName, WindowsDisplayVersion, OsBuildNumber
Then inspect the corresponding Entra device object. Microsoft Graph PowerShell can return the operating-system version:
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice `
-Search "displayName:ComputerName" `
-ConsistencyLevel eventual |
Select-Object DisplayName, OperatingSystem, OperatingSystemVersion, DeviceId
The feature-version label and build number are not interchangeable. Use the build prefix confirmed by Microsoft’s current Windows release-health documentation and by your tenant’s real device objects.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors<VERIFIED-25H2-BUILD>. Replace that placeholder only after confirming the applicable production build. A community example or preview-channel build is not sufficient evidence.Create a dynamic Entra device group
- Open the Microsoft Entra admin center.
- Go to Groups > All groups > New group. You can also create the group from the Intune admin center under Groups > All groups > New group.
- Set Group type to Security.
- Use a name such as
W11-25H2-Devices-Pilot. - Add a description, for example:
Windows 11 25H2 devices for pilot targeting. - Set Membership type to Dynamic Device.
- Add an owner or secondary owner where appropriate.
- Select Add dynamic query, then open Edit rule syntax.
Enter this rule after replacing the placeholder:
(device.deviceOSType -eq "Windows") -and
(device.deviceOSVersion -startsWith "10.0.<VERIFIED-25H2-BUILD>")
For example, if your verified production build prefix is 10.0.26200, the conditional rule would be:
(device.deviceOSType -eq "Windows") -and
(device.deviceOSVersion -startsWith "10.0.26200")
The 26200 value is an example, not a universal assertion about every Windows 11 25H2 release. Confirm it against the applicable release documentation and your tenant data before using it.
- Select Validate rules if the portal presents that option.
- Test representative devices.
- Select Save for the rule, then Create for the group.
Dynamic membership is automatic. You cannot manually add or remove individual devices from a dynamic group; membership changes when the evaluated attributes change.
Rank #2
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
Add narrower conditions when necessary
Use extra conditions only when they represent a genuine requirement. For example, to include Microsoft Entra joined devices only:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →(device.deviceOSType -eq "Windows") -and
(device.deviceOSVersion -startsWith "10.0.<VERIFIED-25H2-BUILD>") -and
(device.deviceTrustType -eq "AzureAD")
That condition excludes hybrid joined and registered devices. Do not add it merely because the devices are managed by Intune.
Other supported attributes can help narrow membership:
(device.deviceOwnership -eq "Company")
(device.deviceManagementAppId -eq "0000000a-0000-0000-c000-000000000000")
The latter is the documented Microsoft Intune management application ID. You can also use attributes such as manufacturer, model, device category, trust type, and ownership. Validate each attribute on actual device objects before using it in a production rule.
Create an assigned pilot group
An assigned group is usually safer for a small, deliberately selected rollout. Use it when the pilot list is curated, devices are already present in Entra, or automatic membership is not required.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Go to Groups > All groups > New group.
- Choose Security.
- Enter a name such as
W11-25H2-Pilot-Assigned. - Set Membership type to Assigned.
- Create the group.
- Open Members > Add members and select the device objects.
This approach gives administrators an explicit membership decision, but it will not automatically follow devices as they upgrade to or leave 25H2.
Rank #3
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Use an Intune assignment filter instead
If the group is needed only to target an Intune app, configuration profile, compliance policy, endpoint-security policy, or Windows Update policy, an assignment filter may be the better design.
- Assign the workload to All devices or a broad device group.
- Create an Intune device assignment filter.
- Choose the supported OS property and value from the filter editor.
- Validate the filter against a real managed device.
- Apply the filter to the assignment as an inclusion or exclusion.
Intune filter syntax is not the same as Entra dynamic-group syntax. Do not paste device.deviceOSVersion into the Intune filter editor unless the current editor explicitly exposes that property. Microsoft’s supported device-property reference uses Intune properties such as operatingSystemSKU; select the current OS-version property and value offered by your tenant.
Filters are evaluated at Intune check-in, which can make them more suitable for fast assignment changes. They are not directory groups and cannot replace an Entra group for Conditional Access, licensing, or other group-dependent services.
Use the group in Intune
- Open the relevant Intune workload, such as Apps, Devices > Configuration, Devices > Compliance, Endpoint security, or Windows updates.
- Create or open the policy, app assignment, or profile.
- Open Assignments.
- Add the 25H2 device group under Included groups.
- Configure exclusions carefully and review the assignment summary.
- Deploy to a pilot first.
- Monitor device and assignment status before expanding the rollout.
Group membership only scopes an assignment. It does not prove that a device is patched, encrypted, compliant, healthy, or safe to receive an update.
Verify membership and assignment
In Entra, open the group and inspect its members. Compare the result with the device’s operating-system version and trust state. You can query a specific object with Graph PowerShell:
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -Filter "displayName eq 'ComputerName'" |
Format-List DisplayName, OperatingSystem, OperatingSystemVersion, DeviceId, TrustType
If filtering is unavailable or does not return the expected object, use an eventually consistent search:
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Get-MgDevice `
-Search "displayName:ComputerName" `
-ConsistencyLevel eventual |
Select-Object DisplayName, OperatingSystem, OperatingSystemVersion, DeviceId
In Intune, review the workload’s device assignment status and the device’s check-in information. A local device may show the new feature version before its Entra object and dynamic-group membership have refreshed.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Troubleshooting
The group has no members
- Confirm that the device has an Entra device object.
- Check that
OperatingSystemis actuallyWindows. - Check the exact
OperatingSystemVersionvalue. - Confirm the rule includes the
10.0.prefix. - Check for duplicate or stale device records.
- Confirm that the device is registered or joined as expected.
- Allow for dynamic membership and directory synchronization processing.
The rule editor rejects the syntax
Use the raw rule editor and check that the device. prefixes are present, quotation marks are straight, operators use Entra syntax, and parentheses are balanced. Do not use an Intune filter expression in the Entra editor.
Devices appear too slowly
This is normal for asynchronous dynamic-group processing. For an assignment that must be evaluated at the next Intune check-in, use an assignment filter or an assigned pilot group instead.
The group includes the wrong Windows devices
Inspect the actual object attributes, then narrow the rule with trust type, ownership, management application, manufacturer, model, or device category. A broad build prefix can also include preview or unexpected builds. A prefix is useful because cumulative updates can change the revision portion, but it is not proof of edition, servicing channel, compliance, or management state.
The local device is on 25H2 but Entra is not
The directory record may not have refreshed, Graph results may be eventually consistent, or the query may be returning a duplicate or stale object. Use the Entra device object and Intune record as the targeting sources of truth while synchronization completes.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Important edge cases
Feature-version transitions
During a staged update, a device can leave an older-version group before it appears in the 25H2 group. It may temporarily receive neither assignment, or it may receive an old assignment before the new membership is calculated. Use separate pilot, validation, and broad-rollout controls instead of relying on one version group as the complete update strategy.
Best Value
- 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
- Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
- 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
- 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
- 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
Autopilot and pre-provisioning
OS-version attributes may not exist or may not be reliable early in Autopilot provisioning. For OOBE, pre-provisioning, or Enrollment Status Page scenarios, use Autopilot-specific attributes such as:
(device.devicePhysicalIds -any (_ -startsWith "[ZTDId]"))
See Microsoft’s guidance for Autopilot enrollment and Autopilot device groups.
Device groups cannot target owner attributes
A device dynamic rule evaluates device attributes. It cannot select devices by the owner’s department, country, or other user property. If targeting must follow users, use a user group and an appropriate Intune assignment design.
Exclusion timing
A device can receive an included Intune assignment before Entra calculates that it belongs to an exclusion group. Avoid dynamic-group exclusions for latency-sensitive assignments; use an assignment filter when the exclusion must be evaluated at check-in.
Operational best practices
- Use names that identify Windows version, scope, and purpose, such as
W11-25H2-Devices-Pilot. - Document the verified build prefix, rule owner, creation date, and intended workloads.
- Add a secondary owner where operationally appropriate.
- Keep pilot and production groups separate.
- Test rules with representative joined, hybrid joined, registered, managed, and unmanaged devices.
- Use dynamic groups for reusable cross-service identity decisions and filters for Intune-only property targeting.
- Review membership after feature updates and during rollback or servicing changes.
- Do not treat membership as evidence of security compliance.
Licensing note
You do not need to purchase a separate product merely to create a Windows device group. The required entitlement depends on what the group will do. Intune is relevant for endpoint-management workloads; Entra capabilities are relevant for identity and access workloads. Existing Microsoft 365 Business Premium, Microsoft 365 E3, or Microsoft 365 E5 licensing may already include applicable services, but confirm the tenant’s current entitlements and regional terms on Microsoft’s Intune pricing page and Entra ID pricing page. No current dollar price is quoted because pricing varies by region, agreement, currency, billing term, and bundle.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

