Add Entra ID Devices to a Security Group from CSV with PowerShell

Adding devices to an Entra ID or Intune security group is straightforward when only a few devices are involved. However, manually managing larger device lists or repeating the same task regularly can quickly become inefficient.

I frequently need to populate Entra ID groups with specific devices. The built-in bulk import feature can be useful for simple, one-time operations, but it is not always practical for recurring administrative tasks. Existing members, missing devices, and individual errors can make the process difficult to track.

The PowerShell script described in this article provides a repeatable alternative. It reads device names from a CSV file, searches for the corresponding device objects in Microsoft Entra ID, and adds them to an assigned security group through Microsoft Graph.

The script also handles situations in which more than one Entra ID object has the same device name. This can occur in environments with Microsoft Entra hybrid joined devices after reinstallations, resets, re-joins, or repeated registrations.


What the script does

The script performs the following tasks:

  • Connects to Microsoft Graph.
  • Searches for the target Entra ID group.
  • Verifies that the group exists only once.
  • Reads device names from a CSV file.
  • Searches for matching Entra ID device objects.
  • Detects multiple objectIDs with the same display name.
  • Skips devices that are already group members.
  • Adds missing devices to the assigned security group.
  • Reports devices that were not found.
  • Continues processing if an individual operation fails.
  • Displays a final summary of the operation.

The device is added by its unique Object ID rather than only by its display name. This is important because display names are not guaranteed to be unique.


Requirements and permissions

The solution requires the Microsoft Graph PowerShell SDK. The relevant modules are:

  • Microsoft.Graph.Authentication
  • Microsoft.Graph.Groups
  • Microsoft.Graph.Identity.DirectoryManagement

The script connects to Microsoft Graph using the following permissions:

Group.ReadWrite.All
Device.Read.All

For a more narrowly scoped implementation, GroupMember.ReadWrite.All may be used for adding members to groups, together with Device.Read.All for reading device objects. Microsoft Graph documents these permissions for group membership operations involving devices.

Depending on the tenant configuration, administrator consent may be required. The signed-in account must also have an appropriate Microsoft Entra role and permission to modify the selected group.

Before using the solution in production, verify:

  • The Microsoft Graph PowerShell SDK is installed.
  • The required permissions have been approved.
  • Consent has been granted where necessary.
  • The target is an assigned security group.
  • The CSV file contains the expected column.
  • Device names match the Entra ID displayName property.
  • Duplicate device objects are handled according to the organization’s policy.

CSV input and configuration variables

The script uses three configuration variables:

$groupName  = "Intune_Policy_Renew Secure Boot Certificate"
$csvPath = "C:\Temp\SecBootDevices.csv"
$csvColumn = "DeviceName"

The variables have the following purposes:

  • $groupName contains the display name of the target Entra ID security group.
  • $csvPath specifies the location of the CSV file.
  • $csvColumn defines the column containing the device names.

The CSV file should use the following format:

DeviceName
PC-001
PC-002
LAPTOP-ABC

The device names should match the displayName property of the corresponding Entra ID device objects. The search uses an exact match rather than a partial search.

A different CSV column can be used by changing $csvColumn:

powershell$csvColumn = "ComputerName"

The CSV would then look like this:

ComputerName
PC-001
PC-002
LAPTOP-ABC

Hybrid joined devices and duplicate objects

Microsoft Entra hybrid joined devices are connected to an on-premises Active Directory environment and registered with Microsoft Entra ID. Their lifecycle can result in more than one device objectID for the same computer name.

Possible causes include:

  • Reinstalling or reimaging a computer.
  • Resetting a Windows device.
  • Removing and rejoining a device.
  • Re-registering the device.
  • Repeated synchronization or registration attempts.
  • Old device objects that were not removed.

The duplicate objects may have the same display name but different Object IDs. For example:

PC-001 - Object ID: 11111111-1111-1111-1111-111111111111
PC-001 - Object ID: 22222222-2222-2222-2222-222222222222

These are separate directory objects even though their names are identical.

The script processes all matching objects and uses each Object ID when adding the device to the group. This prevents matching objects from being silently ignored.

However, duplicate device objects should be reviewed carefully. Some may represent valid current registrations, while others may be stale records that should be cleaned up. Microsoft provides documentation for managing device identities and hybrid join configurations.learn.microsoft+1


Why use PowerShell instead of bulk import?

The built-in bulk import functionality is useful for occasional manual operations. It becomes less convenient when the same process must be performed regularly or when device lists are larger.

The PowerShell approach provides several advantages:

  • The device list is maintained in a reusable CSV file.
  • Existing group members are detected automatically.
  • Multiple objects with the same device name are reported.
  • Missing devices are clearly identified.
  • Individual errors do not stop the complete process.
  • The operation can be repeated whenever necessary.
  • The final summary makes verification easier.
  • The workflow is easier to document and audit.

This is especially useful when a group is used to assign an Intune policy to a controlled set of devices.


Result summary

After processing the CSV file, the script displays a summary similar to this:

textCompleted. Added: 18 | Skipped: 7 | Not found: 2 | Failed: 1

The counters have the following meanings:

CounterMeaning
AddedDevice objects were successfully added
SkippedThe device object was already a group member
Not foundNo matching device object was found
FailedAn error occurred while adding the device

This makes it easy to identify devices that require further investigation.

For example:

  • A high Skipped count usually means the script was safely re-run.
  • A high Not found count may indicate incorrect device names in the CSV.
  • A high Failed count may indicate permission, throttling, or group-related problems.
  • Multiple matches should trigger a review of duplicate device objects.

Important considerations

Display names are not unique identifiers

The script searches for devices by their display name. This is convenient, but the display name is not guaranteed to be unique.

When several objects have the same name, the script processes all matching Object IDs. This behavior should be tested carefully before using the script for a large production import.

For a more selective process, the search could be extended to include additional properties such as:

  • Device ID.
  • Trust type.
  • Account enabled state.
  • Operating system.
  • Approximate last sign-in date.
  • Management type.

Review stale devices

Not every duplicate device object is necessarily valid. Old objects may remain after a device was reinstalled, reset, or re-registered.

Before deleting or using duplicate objects, check their current status and relationship to Intune and Microsoft Entra ID. The script intentionally does not delete objects; it only adds matching devices to the selected group.


Conclusion

The built-in Entra ID bulk import feature is useful for simple, one-time operations, but it is not always practical for recurring device assignments. A PowerShell and Microsoft Graph-based workflow provides better repeatability, error handling, and visibility.

The solution described in this article reads device names from a CSV file, searches Microsoft Entra ID for matching objects, skips existing group members, and adds the required devices to an assigned security group.

It is particularly useful in Intune environments with Microsoft Entra hybrid joined devices, where more than one device object can sometimes exist for the same computer name. Because duplicate objects may be either valid registrations or stale records, they should be reviewed regularly as part of normal device lifecycle management.

Download

The script can be downloaded here from my Github Repositroy: Add-EntraDevicesFromCsvToGroup.ps1

Schreibe einen Kommentar