logo
search
Security Policy Errors

How to Fix Devices Randomly Added to Intune Groups by a Service Principal

Rana GarciaRana Garcia Sep 25, 2026 869 views

Question details

The user needs to identify and resolve why devices are unexpectedly being added to Microsoft Intune policy groups by an automated service principal.

How to Fix Devices Randomly Added to Intune Groups by a Service Principal
Product
Microsoft Intune
Device & OS
not provided
Scenario
Investigating unexpected BitLocker recovery prompts and automated group membership changes in enterprise device management.
Observed behavior
Devices are randomly added to Intune groups, such as disk-encryption policy groups, by an Intune service principal instead of a user, causing duplicate encryption and BitLocker recovery prompts.
Before you start

Ensure you have Intune Administrator or Global Administrator privileges in Microsoft Entra ID to access the required audit logs and group membership rules.

Solution 1Recommended

Review Entra ID Audit Logs and Dynamic Rules

Investigate Microsoft Entra ID logs and dynamic group configurations to identify the automation responsible for the membership changes.

When devices are added to groups by a service principal, it typically indicates that an automated process, dynamic rule, or Graph API application is executing the changes. Tracing the exact timestamp and service principal ID in the logs will reveal the source.

1
Access Entra ID Audit Logs

Log in to the Microsoft Entra admin center, navigate to 'Audit Logs', and filter the activity by 'Group Management' to find recent membership changes.

2
Identify the Service Principal

Click on the specific audit log entry where a device was added. Check the 'Initiated by (actor)' section to identify the exact service principal, Graph API app, or automated script executing the change.

3
Review Dynamic Group Rules

Navigate to the specific Intune group in question. If it is a Dynamic Device group, review the membership syntax to ensure overly broad queries are not capturing unintended devices.

4
Escalate to Microsoft Support

If the audit logs point to internal Microsoft Intune backend services and no misconfigured scripts or rules are found, compile your findings and post the full details in the dedicated Microsoft Intune community on Microsoft Q&A for specialist investigation.

Review Entra ID Audit Logs and Dynamic Rules
Resolving Duplicate BitLocker Prompts: Once the unintended group memberships are corrected and devices receive only one encryption policy, the duplicate BitLocker recovery prompts should cease after the next device sync.
Free Microsoft Office alternative

Equip Your Managed Devices with WPS Office

While you are streamlining your Microsoft Intune policies and device management, consider deploying WPS Office. It provides a lightweight, highly compatible, and free alternative to Microsoft Office, perfect for enterprise environments looking to reduce licensing costs without sacrificing functionality.

  1. 1. Download the Installer: Visit the official WPS Office website to download the enterprise-ready installation package.
  2. 2. Deploy via MDM: Package the installer and deploy it to your managed devices using Microsoft Intune or your preferred endpoint management tool.
  3. 3. Seamlessly Edit Files: Open and edit existing Microsoft Office documents immediately with full layout and formatting retention.
High compatibility with Microsoft Office formats, including docx, xlsx, and pptx.Lightweight installation package suitable for rapid deployment via enterprise MDM solutions like Intune.Familiar user interface requiring zero learning curve, ensuring seamless workforce migration.Cost-effective solution offering powerful document creation and editing tools for free.
microsoft office alternative - wps office

Frequently Asked Questions

Why does a service principal appear in Intune audit logs instead of a user?

A service principal appears in audit logs when an automated system, dynamic group rule, PowerShell script, or Graph API application makes a change, rather than a human administrator performing the action manually.

Can overly broad dynamic group rules cause encryption policy conflicts?

Yes. If dynamic group rules are not strictly defined, devices may be unintentionally pulled into multiple groups with conflicting disk-encryption policies, resulting in duplicate BitLocker prompts.

Where should I escalate unresolved Microsoft Intune group membership issues?

If you cannot find the source of the automation in Entra ID or Intune, you should post your audit log findings in the dedicated Microsoft Intune community on Microsoft Q&A, where Microsoft engineers can investigate backend service principal activity.