Webinar: Managing Macs with Intune: security, scale, & the modern enterprise fleet
Register to attend
Reference

MDM Device Group sync

Petros Amoiridis

ProEnterprise

Workbrew can sync Device Groups from a connected MDM provider. Synced groups mirror the groupings defined in your MDM, updating their membership automatically on a recurring schedule. This feature is available on Pro and Enterprise plans.

Supported providers

Each provider maps a different concept to Workbrew Device Groups. See MDM integration for provider setup and credential requirements.

ProviderSynced as Device Groups
JamfComputer groups
Iru (formerly Kandji)Tags
SimpleMDMAssignment groups
FleetLabels
JumpCloudSystem groups
Microsoft IntuneSecurity groups

What gets synced

Device Groups

Each sync pulls the full list of groups from the MDM and reconciles them with existing synced groups in Workbrew. Groups that no longer exist in the MDM are detached (their MDM link is removed) and become editable like any manually created group.

Device membership

Devices are matched to their MDM counterparts using an MDM-assigned device identifier. On each sync, Workbrew adds Devices that appeared in the MDM group and removes Devices that are no longer in it, so the group's membership stays in sync with the MDM.

Sync schedule

TriggerInterval
Automatic (scheduled)Every 6 hours
Manual (from the Workbrew Console)On demand, with a 15-minute cooldown between syncs
MDM provider changeImmediately when the Workspace's MDM type is set or changed

Only one sync runs per Workspace at a time.

Synced group behavior

Synced groups are marked as Managed by the MDM provider in the Workbrew Console. They differ from manually created groups in the following ways:

Synced groupsManual groups
NameSet by the MDM, updated on each syncEditable
Device membershipControlled by the MDM, updated on each syncEditable
Policies and settingsEditableEditable
Deletable from WorkbrewYesYes

If a synced group's name conflicts with an existing group, Workbrew appends the provider name (e.g. Engineering (Jamf)).

Sync errors

When a sync fails, the error is recorded against the Workspace and displayed in the Workbrew Console. Errors are categorized by type:

Error typeMeaning
UnauthorizedThe API token or credentials are invalid or expired
ForbiddenThe credentials lack the required permissions
Not foundThe MDM host or API endpoint could not be reached
Connection failedA network or DNS error prevented the connection
SSL errorTLS certificate validation failed
Server errorThe MDM provider returned a server-side error

A failed sync does not modify existing synced groups. Previous group data is preserved until the next successful sync.