创建用于组织用户和设备的组Create groups to organize users and devices

适用于:经典门户中的 IntuneApplies to: Intune in the classic portal
在寻找有关 Azure 门户中 Intune 的文档吗?Looking for documentation about Intune in the Azure portal? 请转到此处Go here.

本主题指导管理员如何在 Intune 中创建用户组。This topic tells administrators how they can create groups of users in Intune.

Intune 中的组使你能非常灵活地管理设备和用户。Groups in Intune give you great flexibility for managing your devices and users. 你可以将组设置为适应组织需要(例如,按地理位置、部门或硬件特性)并将其用于执行各种管理任务,上至为一组用户部署策略,下至将应用程序部署到一组设备。You can set up groups to suit your organizational needs (for example, by geographic location, department, or hardware characteristics) and use them to perform a wide variety of administrative tasks, from deploying policies for a set of users to deploying applications to a set of devices.

组管理移动到 Azure ADGroup management moving to Azure AD

自 2016 年 11 月起,新帐户将在 Azure Active Directory (AD) 门户中管理用户和设备组。Starting in November 2016, new accounts will manage user and device groups in the Azure Active Directory (AD) portal. 2016 年 12 月,Intune 产品团队将开始将现有客户迁移到新的基于 Azure AD 的组管理体验。In December 2016, the Intune product team will begin to migrate existing customers to the new Azure AD-based group management experience. 所有用户和设备组都将迁移到 Azure AD 安全组。All user and device groups will be migrated to Azure AD security groups. 仅当能够将对用户日常工作的影响降到最低,且预计不会对用户造成影响时,我们才会开始迁移。We won’t start migrations until we can minimize any effect on your day-to-day work, and when we expect there will be no effect on your users. 还将在迁移帐户前通知用户。We also will give you notice before we migrate your account.

重要

在 Intune 门户中打开“组”工作区时,若显示 Intune 用户组现在在 Azure Active Directory 中作为组进行管理,且附带一个指向 Azure Active Directory 门户的链接,则表明你已在使用新的 Azure AD 安全组方法在 Intune 中进行组管理。If you open the Groups workspace in the Intune portal and see Intune user groups are now managed as groups in Azure Active Directory with a link to the Azure Active Directory portal, then you are already using the new Azure AD security groups approach to group management in Intune. 若要了解如何创建组,请参阅在 Azure Active Directory 中管理组To learn how to create groups, see Managing groups in Azure Active Directory.

如果没有看到 Azure AD 门户的链接,则表明你仍在使用 Intune 门户进行组管理。If you do not see the link to the Azure AD portal, you are still using the Intune portal for groups management.

Intune 门户中的组管理Group management in the Intune portal

设备和用户均在 Intune 管理控制台的“组”工作区中创建。Device and user groups are both created in the GROUPS workspace of the Intune administration console.

管理员控制台组工作区

提示

若要了解有关使用组的详细信息,请参阅通过 Microsoft Intune 使用组来管理用户和设备To learn more about using groups, see Use groups to manage users and devices with Microsoft Intune.

创建设备组Create a device group

使用设备组来部署应用和更新,并配置其他功能。Use device groups to deploy apps and updates, and configure other features. 例如,使用以下步骤设置“我的设备”组:For example, set up a "My Devices" group using the following steps:

  1. Intune 管理控制台中,依次选择“组” > “概述” > “创建组”。In the Intune administration console, choose Groups > Overview > Create Group.

  2. 对于“组名称”,键入“我的设备”,并从父组列表中选择“所有设备”,然后选择“下一步”。For the Group name, type “My Devices” and, from the parent group list, select All Devices, and then choose Next.

  3. 在“定义成员资格条件”页上,选择“所有设备”,以指示该组包括移动设备和计算机。On the Define Membership Criteria page, select All devices to indicate that the group includes both mobile devices and computers.

  4. 在“定义直属成员资格”页上,选择“下一步”。On the Define Direct Membership page, choose Next. 如果之前创建了未包括所有设备的组,并且希望向新组中添加特定设备,则可在此处执行该操作。If you previously created a group that did not include all devices, and you wanted to add specific devices to your new group, you can do that here.

  5. 在“摘要”页上,查看将采取的操作,然后选择“完成”。On the Summary page, review the actions that will be taken, and then choose Finish.

在“所有设备”下的“组”工作区中的“组”列表中,可找到新建的组。You can find the newly created group in the Groups list, in the Groups workspace, under All Devices. 你还可以从此处编辑或删除组。From here, you can also edit or delete the group.

创建用户组Create a user group

使用用户组来部署软件和设备策略。Use user groups to deploy software and device policies. 例如,使用以下步骤设置“Intune 用户”组:For example, set up an "Intune Users" group using the following steps:

  1. Intune 管理控制台中,依次选择“组” > “概述” > “创建组”。In the Intune administration console, choose Groups > Overview > Create Group.

  2. 对于“组名称”,键入“Intune 用户”,并从父组列表中选择“所有用户”,然后选择“下一步”。For the Group name, type “Intune Users” and, from the parent group list, select All Users, and then choose Next.

  3. 在“定义成员资格条件”页上,将“组成员资格开始为”设置为“父组中的所有用户”。On the Define Membership Criteria page, set Start group membership with to All users in the Parent group.

  4. 在“从这些安全组中排除成员”旁边,选择“浏览”,然后选择“公司管理员”。Beside Exclude members from these security groups, choose Browse and then select Company Administrator. 通过这种排除方式,可让你在不影响“公司管理员”帐户(也称为租户管理员)的情况下管理“Intune 用户”组。This exclusion lets you manage the Intune Users group without affecting the Company Administrator account (also known as the tenant administrator).

  5. 在“定义直属成员资格”页上,选择“下一步”。On the Define Direct Membership page, choose Next. 由于你希望“Intune 用户”组包括除“公司管理员”之外的所有用户,因此无需在此处执行任何操作。You don’t need to do anything here because you want the Intune Users group to include all users, except for the Company Administrator.

  6. 在“摘要”页上,查看将采取的操作,然后选择“完成”。On the Summary page, review the actions that will be taken, and then choose Finish.

在“所有用户”下的“组”工作区中的“组”列表中,可找到新建的组。You can find the newly created group in the Groups list, in the Groups workspace, under All Users. 你还可以从此处编辑或删除组。From here, you can also edit or delete the group.