October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk7 min

Create an SCCM (Configuration Manager) Collection for Co-Managed Devices

Learn how to create and safely scope a dynamic Configuration Manager collection for devices actively co-managed by Configuration Manager and Microsoft Intune.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A dynamic Configuration Manager device collection can identify Windows devices that are actively co-managed by Configuration Manager and Microsoft Intune. Use the query below, then scope it with a deliberate limiting collection before deploying applications, policies, updates, or workload pilots.

“Co-management eligible” is not the same as “co-managed.” Eligibility indicates that a device can be onboarded; the collection in this guide requires current co-management policy and MDM state data.

What counts as a co-managed device?

Co-management means Configuration Manager (often still called SCCM) and Microsoft Intune manage the same Windows device concurrently. A Configuration Manager client, an Intune-enrolled device, or a member of the built-in Co-management Eligible Devices collection is not automatically a completed co-management state.

Microsoft documents a device as co-managed when ComgmtPolicyPresent and MDMEnrolled are both 1. The stricter query used here also requires MDMProvisioned = 1, so it can return fewer devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

See Microsoft’s state definitions in co-management monitoring documentation and the eligibility collection details in Microsoft’s enablement documentation.

Eligibility versus current state

State or collection Meaning
Co-management Eligible Devices Devices identified as eligible for onboarding; not proof that enrollment completed.
ComgmtPolicyPresent = 1 The Configuration Manager co-management policy exists on the client.
MDMEnrolled = 1 The device is enrolled in MDM/Intune.
MDMProvisioned = 1 An additional MDM provisioning-state check.
All three query conditions A strict, practical target for currently co-managed devices.

Before you create the collection

  • A working Configuration Manager hierarchy and console.
  • Devices discovered by Configuration Manager, with usable client and co-management state data.
  • Co-management configured or being deployed, with Intune/MDM enrollment data returning to Configuration Manager.
  • Permissions to create device collections and query rules.
  • A limiting collection that defines the devices this collection is allowed to contain.

Starting with Configuration Manager version 2111, co-management onboarding uses the Cloud Attach Configuration Wizard; the query itself still relies on the co-management state class.

Recommended WQL query

select SMS_R_SYSTEM.ResourceID,
       SMS_R_SYSTEM.ResourceType,
       SMS_R_SYSTEM.Name,
       SMS_R_SYSTEM.SMSUniqueIdentifier,
       SMS_R_SYSTEM.ResourceDomainORWorkgroup,
       SMS_R_SYSTEM.Client
from SMS_R_System
inner join SMS_Client_ComanagementState
    on SMS_Client_ComanagementState.ResourceId = SMS_R_System.ResourceId
where SMS_Client_ComanagementState.ComgmtPolicyPresent = 1
  and SMS_Client_ComanagementState.MDMEnrolled = 1
  and SMS_Client_ComanagementState.MDMProvisioned = 1

Microsoft publishes this join pattern in its Configuration Manager query examples.

How the query works

  • SMS_R_System supplies the resource ID and device identity returned to the collection.
  • SMS_Client_ComanagementState supplies co-management status.
  • ResourceId joins the system record to its state record.
  • ComgmtPolicyPresent = 1 confirms that co-management policy is present.
  • MDMEnrolled = 1 confirms MDM enrollment.
  • MDMProvisioned = 1 applies the additional provisioning filter used by Microsoft’s sample.

Create the dynamic device collection in the console

  1. Open the Configuration Manager console.
  2. Go to Assets and Compliance and select Device Collections.
  3. Select Create Device Collection.
  4. On General, enter a name such as All Co-Managed Devices and describe the three state conditions.
  5. Choose a carefully scoped Limiting collection. This is a hard boundary: query results outside it cannot become members.
  6. On Membership Rules, select Add Rule, then Query Rule.
  7. Name the rule, for example Co-Managed Devices Query, and set Resource class to System Resource.
  8. Select Edit Query Statement, open the Criteria tab, choose Show Query Language, and paste the WQL.
  9. Use the query-preview control when available to check returned resources. Preview does not bypass the limiting collection or collection evaluation.
  10. Finish the wizard. To request an immediate evaluation, right-click the collection and select Update Membership.

Query rules are dynamically evaluated, so devices can enter or leave as discovery and co-management state data changes. Microsoft describes collection creation and evaluation in Create collections. Incremental updates may be enabled where supported, but do not assume a fixed five-minute result for every environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a safe limiting collection

Do not use All Systems casually for production deployments. It is broad enough that a later query change could expose unexpected devices. Prefer a boundary such as:

  • Managed Windows workstations only.
  • Active Configuration Manager clients.
  • A business-unit or pilot boundary.
  • A collection that excludes servers and special-purpose devices.

Validate the member count in a staging collection before attaching deployments. If the count is unexpectedly large, stop or disable related deployments and correct the limiting or query rule before proceeding.

Verify membership

  1. Preview the query and note known test devices.
  2. Select Update Membership on the collection.
  3. Refresh the console after evaluation completes.
  4. Confirm that the devices are also inside the limiting collection.
  5. Check at least one known device against co-management monitoring data and its client state.

If the collection is empty

Check discovery and client data

Confirm that the device is discovered, has an active Configuration Manager client, and has returned current inventory and co-management state data. The query cannot return a device that Configuration Manager has never discovered.

Check enrollment and policy

An Intune-enrolled device still needs the Configuration Manager co-management policy. Conversely, a policy-present device without MDM enrollment does not satisfy the documented co-managed state. Microsoft recommends examining the SMS_Client_ComanagementState WMI class on the site server when investigating these fields; see How to monitor co-management.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Lenovo V15 Gen 4 Business Laptop, 15.6" FHD Display, Intel Core i5-13420H (Beat i7-1355U), HDMI, RJ45, Webcam, Numeric Keypad, Wi-Fi, Windows 11 Pro, Black (16GB RAM | 512GB SSD)
  • [High Speed RAM And Enormous Space] 4GB high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once; 128GB PCIe NVMe M.2 Solid State Drive allows to fast bootup and data transfer
  • [Processor] Intel Core i5-13420H Processor (8 Cores, 12 Threads, 12MB Intel Smart Cache, Base at 1.5 GHz, Up to 4.6 GHz Max Turbo Frequency), with Intel UHD Graphics
  • [Display] 15.6" FHD (1920 x 1080) Display
  • [Tech Specs] 1 x USB 3.0 Type-A, 1 x USB 2.0 Type-A, 1 x USB Type-C, 1 x HDMI, 1 x RJ45, 1 x headphone/microphone combo, Webcam, Numeric Keypad, Wi-Fi and Bluetooth
  • [Operating System] Windows 11 Pro - Organize open apps with pre-configured layouts to optimize productivity, Navigate with more intuitive experience to get things done, Collaborate with teams with more features

Check the collection itself

  • Verify that the rule uses System Resource.
  • Paste the query without changing field names or the join.
  • Confirm the limiting collection contains the expected devices.
  • Run Update Membership, wait for evaluation, and reload the console.
  • Allow for site-data replication and refresh delays.

Eligible but not co-managed

Membership in Co-management Eligible Devices can precede policy application or MDM enrollment. Treat it as an onboarding or targeting aid, not as proof of completed co-management.

Duplicate Microsoft Entra objects

Duplicate Microsoft Entra device objects can produce inconsistent auto-enrollment and join state. Microsoft recommends detecting and cleaning them up before relying on co-management auto-enrollment; see the enablement guidance.

Two-condition alternative for troubleshooting

If the strict query is unexpectedly narrow, test the state definition Microsoft uses for co-management monitoring:

select SMS_R_SYSTEM.ResourceID,
       SMS_R_SYSTEM.ResourceType,
       SMS_R_SYSTEM.Name,
       SMS_R_SYSTEM.SMSUniqueIdentifier,
       SMS_R_SYSTEM.ResourceDomainORWorkgroup,
       SMS_R_SYSTEM.Client
from SMS_R_System
inner join SMS_Client_ComanagementState
    on SMS_Client_ComanagementState.ResourceId = SMS_R_System.ResourceId
where SMS_Client_ComanagementState.ComgmtPolicyPresent = 1
  and SMS_Client_ComanagementState.MDMEnrolled = 1

Use this two-condition version for state reporting or diagnosis when provisioning data is delayed or unavailable. It is less restrictive, so do not treat it as universally interchangeable with the production three-condition collection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Design pilot and workload collections

Pilot targeting

Build the base collection first, then create a smaller pilot using a direct membership rule or an include rule from an approved pilot collection. Direct rules are explicit and manually maintained; query rules change automatically. Microsoft documents both models in collection management guidance.

Operating-system and join-state subsets

Add operating-system filters only when the required inventory class and property are present and current in your environment. Do not infer Microsoft Entra join type from a guessed domain or workgroup value; use validated inventory, tenant, or join-state properties.

Workload-specific targeting

Co-management state and workload authority are separate. A co-managed device may still have some workloads controlled by Configuration Manager. Create separate collections or reports for compliance, Windows Update, endpoint protection, applications, resource access, and device configuration.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

PowerShell automation pattern

The following is an automation pattern; cmdlet parameters and provider behavior vary by installed Configuration Manager console/module version. Test it in a lab first and ensure the site drive is connected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Lenovo V-Series V15 Business Laptop, 15.6" FHD Display, AMD Ryzen 7 Processor, 24GB RAM, 1TB SSD, Numeric Keypad, HDMI, RJ45, Webcam, Wi-Fi, Windows 11 Pro, Black
  • [High Speed RAM And Enormous Space] 24GB high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once; 1TB PCIe NVMe M.2 Solid State Drive allows to fast bootup and data transfer
  • [Processor] AMD Ryzen 7 5825U Processor (8 Cores, 16 Threads, 16MB Cache, Base at 2.0 GHz, Up to 4.5 GHz Max Turbo Frequency), with AMD Radeon Graphics
  • [Display] 15.6" FHD (1920 x 1080) Display
  • [Tech Specs] 1 x USB 3.2 Type-C, 1 x USB 3.2 Type-A, 1 x USB 2.0 Type-A, 1 x HDMI, 1 x RJ45, 1 x headphone/microphone combo, Webcam, Numeric Keypad, Wi-Fi and Bluetooth
  • [Operating System] Windows 11 Pro - Organize open apps with pre-configured layouts to optimize productivity, Navigate with more intuitive experience to get things done, Collaborate with teams with more features
$SiteCode = "ABC"
$CollectionName = "All Co-Managed Devices"
$LimitingCollectionName = "All Managed Windows Workstations"

Import-Module "$($ENV:SMS_ADMIN_UI_PATH)..ConfigurationManager.psd1"
Set-Location "$SiteCode`:"

$wql = @"
select SMS_R_SYSTEM.ResourceID,
       SMS_R_SYSTEM.ResourceType,
       SMS_R_SYSTEM.Name,
       SMS_R_SYSTEM.SMSUniqueIdentifier,
       SMS_R_SYSTEM.ResourceDomainORWorkgroup,
       SMS_R_SYSTEM.Client
from SMS_R_System
inner join SMS_Client_ComanagementState
    on SMS_Client_ComanagementState.ResourceId = SMS_R_System.ResourceId
where SMS_Client_ComanagementState.ComgmtPolicyPresent = 1
  and SMS_Client_ComanagementState.MDMEnrolled = 1
  and SMS_Client_ComanagementState.MDMProvisioned = 1
"@

New-CMDeviceCollection `
    -Name $CollectionName `
    -LimitingCollectionName $LimitingCollectionName `
    -RefreshType Both

Add-CMDeviceCollectionQueryMembershipRule `
    -CollectionName $CollectionName `
    -RuleName "Co-Managed Devices Query" `
    -QueryExpression $wql

Invoke-CMCollectionUpdate -Name $CollectionName

See Microsoft’s references for New-CMDeviceCollection, Add-CMDeviceCollectionQueryMembershipRule, and Invoke-CMCollectionUpdate. Assigning a provider-machine variable alone does not establish a provider connection; use the connection method appropriate to your console version.

Operational guidance

  • Keep one well-maintained base collection and derive narrower collections with include or exclude rules where practical.
  • Avoid many overlapping, expensive query collections in large hierarchies.
  • Use incremental updates where appropriate, while retaining sensible full-evaluation schedules.
  • Never assume that a co-managed collection proves every workload has moved to Intune.

Frequently Asked Questions

Is Co-management Eligible Devices the same as a co-managed collection?

No. The built-in collection identifies devices eligible for onboarding. A current co-managed state requires co-management policy and MDM enrollment; the strict collection also checks MDM provisioning.

Why is an Intune-enrolled device missing?

Intune enrollment alone is insufficient. Check that the Configuration Manager co-management policy is present, state data is current, the device is in the limiting collection, and the collection has evaluated.

How do I refresh membership immediately?

Right-click the collection in Device Collections and select Update Membership. PowerShell administrators can use Invoke-CMCollectionUpdate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can this collection identify workloads already moved to Intune?

No. Co-management state and workload authority are separate. Use workload-specific collections or reports.

Should I always require MDMProvisioned = 1?

Use it for a strict production targeting collection. Omit it in the troubleshooting or reporting variant when provisioning data is delayed or makes the result unexpectedly narrow.

The Bottom Line

Use the three-condition query for a conservative, dynamic collection of currently co-managed devices, constrain it with a purposeful limiting collection, and validate membership before targeting production workloads.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.