How to Fix Devices Randomly Added to Intune Groups by a Service Principal
Question details
The user needs to identify and resolve why devices are unexpectedly being added to Microsoft Intune policy groups by an automated service principal.

- Product
- Microsoft Intune
- Device & OS
- not provided
- Scenario
- Investigating unexpected BitLocker recovery prompts and automated group membership changes in enterprise device management.
- Observed behavior
- Devices are randomly added to Intune groups, such as disk-encryption policy groups, by an Intune service principal instead of a user, causing duplicate encryption and BitLocker recovery prompts.
Ensure you have Intune Administrator or Global Administrator privileges in Microsoft Entra ID to access the required audit logs and group membership rules.
Review Entra ID Audit Logs and Dynamic Rules
Investigate Microsoft Entra ID logs and dynamic group configurations to identify the automation responsible for the membership changes.
When devices are added to groups by a service principal, it typically indicates that an automated process, dynamic rule, or Graph API application is executing the changes. Tracing the exact timestamp and service principal ID in the logs will reveal the source.
Log in to the Microsoft Entra admin center, navigate to 'Audit Logs', and filter the activity by 'Group Management' to find recent membership changes.
Click on the specific audit log entry where a device was added. Check the 'Initiated by (actor)' section to identify the exact service principal, Graph API app, or automated script executing the change.
Navigate to the specific Intune group in question. If it is a Dynamic Device group, review the membership syntax to ensure overly broad queries are not capturing unintended devices.
If the audit logs point to internal Microsoft Intune backend services and no misconfigured scripts or rules are found, compile your findings and post the full details in the dedicated Microsoft Intune community on Microsoft Q&A for specialist investigation.

Equip Your Managed Devices with WPS Office
While you are streamlining your Microsoft Intune policies and device management, consider deploying WPS Office. It provides a lightweight, highly compatible, and free alternative to Microsoft Office, perfect for enterprise environments looking to reduce licensing costs without sacrificing functionality.
- 1. Download the Installer: Visit the official WPS Office website to download the enterprise-ready installation package.
- 2. Deploy via MDM: Package the installer and deploy it to your managed devices using Microsoft Intune or your preferred endpoint management tool.
- 3. Seamlessly Edit Files: Open and edit existing Microsoft Office documents immediately with full layout and formatting retention.

Frequently Asked Questions
Why does a service principal appear in Intune audit logs instead of a user?
A service principal appears in audit logs when an automated system, dynamic group rule, PowerShell script, or Graph API application makes a change, rather than a human administrator performing the action manually.
Can overly broad dynamic group rules cause encryption policy conflicts?
Yes. If dynamic group rules are not strictly defined, devices may be unintentionally pulled into multiple groups with conflicting disk-encryption policies, resulting in duplicate BitLocker prompts.
Where should I escalate unresolved Microsoft Intune group membership issues?
If you cannot find the source of the automation in Entra ID or Intune, you should post your audit log findings in the dedicated Microsoft Intune community on Microsoft Q&A, where Microsoft engineers can investigate backend service principal activity.




